Back to skill

Security audit

Dockerps

Security checks for vulnerabilities and agentic risk

Overview

This Docker monitoring skill includes a cleanup command that can delete Docker resources without warning or confirmation, so users should review it before installing.

Install only if you are comfortable giving this skill access to your Docker daemon and you understand that running cleanup can remove stopped containers and dangling images outside this skill's own files. Prefer reviewing or changing the cleanup command to require explicit confirmation and scoping before using it on shared or important Docker hosts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:100
Finding

Unsafe and Incorrect Positional Argument Handling in Docker Commands

Content
View full analysis
" docker top $2 2>/dev/null || echo 'Container not found' } cmd_logs() { local container="${2:-}" local lines="${3:-}" [ -z "$container" ] && die "Usage: $SCRIPT_NAME logs " docker logs --tail ${3:-50} $2 2>/dev/null } cmd_inspect() { local container="${2:-}" [ -z "$container" ] && die "Usage: $SCRIPT_NAME inspect " docker inspect $2 2>/dev/null | python3 -c 'import json,sys;d=json.load(sys.stdin)[0];print("Name:",d["Name"]);print("State:",d["State"]["Status"])' 2>/dev/null } ``` The command dispatcher removes the subcommand before invoking each handler: ```bash case "$cmd" in list) shift; cmd_list "$@" ;; stats) shift; cmd_stats "$@" ;; top) shift; cmd_top "$@" ;; logs) shift; cmd_logs "$@" ;; inspect) shift; cmd_inspect "$@" ;; cleanup) shift; cmd_cleanup "$@" ;; esac ``` ### Technical Analysis After `main` executes `shift`, the first user-supplied command argument becomes `$1`. However, `cmd_top` and `cmd_inspect` retrieve the container from `$2`, while `cmd_logs` retrieves the container from `$2` and the line count from `$3`. Consequently, documented invocations are interpreted incorrectly: - `script.sh top my-container` leaves `$2` empty and fails the validation check. - `script.sh inspect my-container` leaves `$2` empty and fails. - `script.sh logs my-container 100` treats `100` as the container and defaults the log count to 50. The variables are subsequently expanded without quotes and without an option terminator. Shell metacharacters introduced through parameter expansion are not reparsed as shell synt ...[truncated 1557 chars]
Remediation
View remediation
" local container="$1" docker top -- "$container" } cmd_logs() { [ "$#" -ge 1 ] && [ "$#" -le 2 ] || die "Usage: $SCRIPT_NAME logs [lines]" local container="$1" local lines="${2:-50}" [[ "$lines" =~ ^[1-9][0-9]*$ ]] || die "Log line count must be a positive integer" docker logs --tail "$lines" -- "$container" } cmd_inspect() { [ "$#" -eq 1 ] || die "Usage: $SCRIPT_NAME inspect " local container="$1" docker inspect -- "$container" | python3 -c 'import json,sys; d=json.load(sys.stdin)[0]; print("Name:",d["Name"]); print("State:",d["State"]["Status"])' } ``` Compatibility of `--` should be verified against the minimum supported Docker CLI version. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:119
Finding

Unscoped Destructive Docker Cleanup Without Confirmation

Content
View full analysis
/dev/null && docker image prune -f 2>/dev/null && echo Cleaned } ``` The associated documentation only presents the command as follows: ```bash ### `cleanup` ```bash scripts/script.sh cleanup ``` ``` ### Technical Analysis The cleanup function invokes daemon-wide Docker pruning with the force flag: - `docker container prune -f` removes all stopped containers visible to the selected Docker daemon. - `docker image prune -f` removes dangling images visible to that daemon. - `-f` bypasses Docker's interactive confirmation. The operation has no preview, confirmation, age restriction, label filter, project boundary, or target list. The documentation also does not explain the exact deletion scope. A general cleanup request can therefore cause deletion of unrelated resources owned by other applications or users sharing the same daemon. ### Attack Path 1. An attacker or ambiguous user request persuades an agent to perform Docker cleanup. 2. The agent invokes `scripts/script.sh cleanup`. 3. The script runs both prune operations with `-f`, so no interactive approval is required. 4. Every eligible stopped container and dangling image visible to the active Docker context is deleted. 5. Unrelated workloads may lose stopped container state or cached images and may require reconstruction or image retrieval. The attack requires the skill process to have permission to communicate with the relevant Docker daemon. ### Impact Assessment The operation can delete all stopped containers and dangling images within the active Docker daemon's scope. This may destroy data retained only in stopped containers' writable layers, disrupt rollback or troubleshooting workflows, remove build artifacts, and increase downtime or network usage ...[truncated 392 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as a monitoring tool for viewing container processes and stats, but it also includes destructive cleanup behavior that prunes stopped containers and unused images. This mismatch can mislead users or calling agents into invoking the skill in contexts where only read-only inspection is expected, causing unintended state changes and potential data loss or operational disruption.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is described as a monitoring/viewing utility, but it also exposes a destructive cleanup command that prunes containers and images. That mismatch is dangerous because users or higher-level agents may invoke the skill under the assumption it is read-only, causing irreversible deletion of Docker resources and operational disruption.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Pruning containers and images is not justified by the stated purpose of viewing container processes and stats. In agent contexts, unnecessary destructive capability broadens the attack surface and enables accidental or adversarial data/environment loss if the tool is selected for benign monitoring tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented cleanup command provides no warning that it may delete Docker resources and alter system state. In an agent or automation setting, undocumented destructive behavior increases the likelihood of accidental execution, potentially removing stopped containers and unused images that users expected to retain for debugging, rollback, or recovery.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
80% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · scripts/script.sh (reported line 9)May include surrounding context.

sh
DATA_DIR="$HOME/.local/share/dockerps"
mkdir -p "$DATA_DIR"

#
#
#
#

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

docker container prune -f and docker image prune -f run with force enabled and no warning, prompt, or dry-run behavior. This makes accidental invocation easy and can immediately delete stopped containers and unused images, disrupting workflows and potentially removing forensic or recovery artifacts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.