Back to skill

Security audit

Docker Plus

Security checks for vulnerabilities and agentic risk

Overview

This Docker guidance skill is only a Markdown template, but some production and security examples could lead users to leak credentials or run broad destructive cleanup commands.

Review this skill carefully before installing or using it as production guidance. Do not copy its secret-handling or Compose credential examples into real systems; use Docker or platform secrets, runtime injection, and unique credentials instead. Treat docker system prune -af as destructive and verify the Docker context and disposable resources before running it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:151
Finding

Database Secret Persisted in Docker Image Metadata

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:178
Finding

Hard-Coded Plaintext Database Credentials in Production Compose Template

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:30
Finding

Destructive Docker Cleanup Command Presented Without Safety Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

docker system prune -af is a destructive cleanup command that removes unused containers, networks, images, and build cache; documenting it without caution can lead to accidental data or environment loss. In an agent skill meant to be reused as operational guidance, terse unsafe commands increase the chance of harmful copy-paste execution.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill says not to store secrets in images, then demonstrates ARG DB_PASSWORD followed by ENV DB_PASSWORD=$DB_PASSWORD, which bakes secret material into image metadata/layers and can expose it via image inspection, build history, or registry access. In a Docker guidance skill, this is especially dangerous because users may copy the pattern verbatim into production builds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example secret-handling pattern and credentials guidance normalizes embedding a database password in image configuration, contradicting secure practice and potentially leading users to leak credentials into images, CI logs, and registries. Because this skill presents itself as security-hardening guidance, the misleading example is more dangerous than a neutral code snippet.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

Production stage

FROM debian:bookworm-slim RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates && rm -rf /var/lib/apt/lists/* COPY --from=builder /app/target/release/myapp /usr/local/bin/ CMD ["myapp"]

text

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

Production stage

FROM debian:bookworm-slim RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates && rm -rf /var/lib/apt/lists/* COPY --from=builder /app/target/release/myapp /usr/local/bin/ CMD ["myapp"]

text

Chaining Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

Production stage

FROM debian:bookworm-slim RUN apt-get update && apt-get install -y --no-install-recommends ca-certificates && rm -rf /var/lib/apt/lists/* COPY --from=builder /app/target/release/myapp /usr/local/bin/ CMD ["myapp"]

text

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The heading/comment claims 'Read-only filesystem', but RUN chmod -R 555 /app only changes file permissions inside the image and does not enable Docker's read-only root filesystem behavior at runtime. The documentation overstates what the code achieves, creating an intent-code divergence.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.