Back to skill

Security audit

Portainer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Portainer control tool, but it can immediately stop, restart, redeploy, and read logs from Docker infrastructure without built-in confirmation or tight scoping.

Review before installing. Use a least-privilege Portainer token, restrict it to intended environments where possible, protect ~/.clawdbot/.env, and require explicit human confirmation before stop, restart, redeploy, or log commands. Treat container logs as sensitive because they can contain secrets or personal data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
|------|---------|
| **Portainer** | Version 2.x with API access |
| **Tools** | `curl`, `jq` |
| **Auth** | API Access Token |

### Setup

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
1. **Get API Token from Portainer:**
   - Log into Portainer web UI
   - Click username → My Account
   - Scroll to "Access tokens" → Add access token
   - Copy the token (you won't see it again!)

2. **Configure credentials:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
1. **Get API Token from Portainer:**
   - Log into Portainer web UI
   - Click username → My Account
   - Scroll to "Access tokens" → Add access token
   - Copy the token (you won't see it again!)

2. **Configure credentials:**

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · portainer.sh (reported line 183)May include surrounding context.

sh
1. **Get API Token from Portainer:**
   - Log into Portainer web UI
   - Click username → My Account
   - Scroll to "Access tokens" → Add access token
   - Copy the token (you won't see it again!)

2. **Configure credentials:**

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
set -e

# Load config from environment or .env
PORTAINER_URL="${PORTAINER_URL:-}"
PORTAINER_API_KEY="${PORTAINER_API_KEY:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

md
set -e

# Load config from environment or .env
PORTAINER_URL="${PORTAINER_URL:-}"
PORTAINER_API_KEY="${PORTAINER_API_KEY:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

md
set -e

# Load config from environment or .env
PORTAINER_URL="${PORTAINER_URL:-}"
PORTAINER_API_KEY="${PORTAINER_API_KEY:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 256)May include surrounding context.

md
set -e

# Load config from environment or .env
PORTAINER_URL="${PORTAINER_URL:-}"
PORTAINER_API_KEY="${PORTAINER_API_KEY:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · portainer.sh (reported line 7)May include surrounding context.

sh
set -e

# Load config from environment or .env
PORTAINER_URL="${PORTAINER_URL:-}"
PORTAINER_API_KEY="${PORTAINER_API_KEY:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · portainer.sh (reported line 11)May include surrounding context.

sh
set -e

# Load config from environment or .env
PORTAINER_URL="${PORTAINER_URL:-}"
PORTAINER_API_KEY="${PORTAINER_API_KEY:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · portainer.sh (reported line 21)May include surrounding context.

sh
set -e

# Load config from environment or .env
PORTAINER_URL="${PORTAINER_URL:-}"
PORTAINER_API_KEY="${PORTAINER_API_KEY:-}"

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The use of 'export $(grep ... | xargs)' to ingest secrets from ~/.clawdbot/.env is unsafe because it performs shell word-splitting and can misparse special characters, whitespace, or malformed lines, potentially corrupting variables or introducing unexpected environment assignments. It also loads sensitive credentials from plaintext storage into the process environment without validation, which is risky in shared or agent-executed contexts.

Content

Scanner excerpt · portainer.sh (reported line 13)May include surrounding context.

sh
# Try to load from clawdbot .env if not set
if [[ -z "$PORTAINER_URL" || -z "$PORTAINER_API_KEY" ]]; then
    ENV_FILE="$HOME/.clawdbot/.env"
    if [[ -f "$ENV_FILE" ]]; then
        export $(grep -E "^PORTAINER_" "$ENV_FILE" | xargs)
    fi

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The redeploy workflow reads stack environment variables via '.Env' and reuses them in a redeploy payload, which means the script handles potentially sensitive secrets embedded in stack configuration. In an agent context, any future logging, error handling, or downstream exposure of STACK_INFO/ENV_VARS could leak secrets, and the script currently pulls more sensitive configuration than minimally necessary.

Content

Scanner excerpt · portainer.sh (reported line 79)May include surrounding context.

sh
# Get stack info for env vars and endpoint
        STACK_INFO=$(api_get "/stacks/$STACK_ID")
        ENDPOINT_ID=$(echo "$STACK_INFO" | jq -r '.EndpointId')
        ENV_VARS=$(echo "$STACK_INFO" | jq -c '.Env')
        GIT_CRED_ID=$(echo "$STACK_INFO" | jq -r '.GitConfig.Authentication.GitCredentialID // 0')
        
        PAYLOAD=$(jq -n \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises shell-driven operational control over Portainer but does not declare any explicit tool scope such as allowed tools or permissions. In an agent environment, missing scope boundaries can let the agent invoke broader shell capabilities than intended, increasing the blast radius for destructive container and deployment actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents restart, stop, and redeploy operations without a clear warning that these actions can interrupt production services, cause downtime, or redeploy unreviewed code from git. In an autonomous or semi-autonomous agent setting, lack of friction or warning materially increases the chance of harmful accidental execution.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · portainer.sh (reported line 30)May include surrounding context.

sh
# Helper function for API calls
api_get() {
    curl -s -H "$AUTH_HEADER" "$API$1"
}

api_post() {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script exposes state-changing operations such as stack redeploy and container start/stop/restart directly from command inputs with no confirmation, dry-run, authorization gating, or explicit user warning. In an agent-skill context, this increases the risk of accidental or prompt-induced disruption to production services because the skill can immediately perform destructive operational actions against Portainer-managed infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The logs command retrieves container logs from the remote Portainer API and prints them verbatim, which can expose secrets, tokens, personal data, or internal system details commonly present in application logs. In an agent setting, this can cause unintended disclosure to the requesting user or downstream systems consuming the tool output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.