Back to skill

Security audit

Docker Essentials

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Docker command reference, but users should be careful with cleanup commands, registry pushes, exposed ports, and example credentials.

Install only if you want a Docker command cheat sheet. Before running examples, review cleanup commands because volumes and images may contain important data, avoid pushing images that might include secrets or private code, pin production images, and replace the sample database password and port binding with secure local settings.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:281
Finding

Weak Hardcoded Database Credential with Broad Host Port Exposure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 281–289
Vulnerability Type: Hardcoded weak credential and insecure network exposure
Risk Level: Medium

bash
**Database container:**
```bash
docker run -d \
  --name postgres \
  -e POSTGRES_PASSWORD=secret \
  -e POSTGRES_DB=mydb \
  -v postgres-data:/var/lib/postgresql/data \
  -p 5432:5432 \
  postgres:15
text

### Technical Analysis

The documented Docker workflow configures PostgreSQL with the predictable plaintext password `secret`. Supplying the password through `-e` also places it in the container configuration, where users with sufficient Docker access can retrieve it through container inspection.

The mapping `-p 5432:5432` publishes the database port on all host interfaces by default. If network firewalls or host access controls do not block the port, the database can become reachable from untrusted networks. Combining a predictable credential with broad network publication creates a directly exploitable authentication weakness for users who copy the example without hardening it.

### Attack Path

1. A user copies the documented command and starts the PostgreSQL container.
2. Docker publishes TCP port 5432 on all host interfaces.
3. An attacker identifies the exposed PostgreSQL service from a reachable network.
4. The attacker attempts authentication using the documented password `secret` and an applicable database role, such as the image's default administrative role.
5. If authentication succeeds, the attacker accesses the configured database with that role's privileges.

Exploitation requires network reachability and knowledge or discovery of a valid database username.

### Impact Assessment

A successful attacker could obtain the privileges granted to the compromised PostgreSQL role. If the default administrative role is compromised, this may permit reading, modifying, or deleting databases and database objects managed 
...[truncated 174 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the fixed password with a strong, randomly generated secret.
  • Avoid placing production credentials directly in reusable commands or committed documentation. Supply them through a protected secret file or an orchestrator-supported secrets mechanism.
  • Restrict publication to the loopback interface when only local access is required:
    bash
    -p 127.0.0.1:5432:5432
    
  • Omit the published port entirely when only containers on a private Docker network need database access.
  • Add explicit guidance concerning firewall rules, trusted-source allowlists, TLS, least-privilege database roles, and credential rotation.
  • Clearly label demonstration values as placeholders that must not be used in production.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (18)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

docker-compose down -v removes attached volumes and therefore can permanently delete application or database data. In a concise command cheat sheet, presenting this command without a deletion warning is dangerous because users may assume it is just a normal stop operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Volume prune commands can irreversibly delete stored container data, and system prune variants can remove a wide range of Docker resources. Because this skill is aimed at practical command usage, missing warnings materially increases the risk of accidental data loss by less experienced users.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

System-wide prune commands can remove unused containers, images, networks, and optionally volumes across the host, which may break development or test environments. Without an explicit warning, the skill normalizes high-impact cleanup commands in a way that can cause broad accidental destruction.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill shows docker container prune without warning that it deletes stopped containers, which can remove useful state and disrupt local workflows. In an educational command reference, omission of destructive-operation warnings increases the chance that users will run cleanup commands without understanding the consequences.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The push example omits any warning that locally built images may include proprietary code, embedded credentials, or sensitive files if the build context is unsafe. In a Docker skill, encouraging registry pushes without privacy guidance can lead to accidental public disclosure of source code or secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example includes an inline database password, which can be captured in shell history, process listings, shared screenshots, or copied documentation. In a broadly reusable Docker skill, this can normalize insecure credential handling and lead users to expose real secrets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.