Back to skill

Security audit

Container Desktop

Security checks for vulnerabilities and agentic risk

Overview

The package presents itself as Podman Desktop, but the inspected files mostly describe and implement an unrelated placeholder developer workflow tool with local command logging.

Review this carefully before installing. It does not appear to contain exfiltration, remote execution, privilege escalation, or destructive file deletion, but it is not a coherent Podman Desktop skill and may mislead an agent or user about what will run. Treat it as an unfinished generic workflow helper, and avoid passing tokens, secret paths, or deployment details as command arguments because they may be written to a local history log.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill metadata and body materially misrepresent what the tool is and does: it claims to be Podman Desktop for containers/Kubernetes, but documents a different generic workflow tool named 'Container Desktop' with unrelated commands and local history logging. This kind of identity and behavior mismatch can mislead users or orchestrators into invoking the skill in the wrong context, causing unintended execution, trust abuse, and undisclosed data collection via command logging.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation is internally contradictory, presenting the skill as 'Podman Desktop' while the body describes 'Container Desktop' and unrelated project automation commands. Internal inconsistency is dangerous because it obscures operator understanding, weakens reviewability, and can conceal unexpected functionality behind trusted branding.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest advertises a Podman Desktop container/Kubernetes skill, but the documentation defines a different CLI workflow tool. This semantic mismatch can cause policy engines, users, or agents to select the skill under false assumptions, increasing the chance of inappropriate use and bypass of trust decisions based on the declared purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says this is a workflow automation tool for initializing, building, testing, and deploying projects from the command line, which is a very broad set of common developer actions. The markdown does not provide explicit trigger phrases, scope boundaries, or negative examples to distinguish when this skill should activate versus when a general coding assistant should respond normally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a tool for working with containers and Kubernetes, but this script is a generic 'Developer workflow automation tool' exposing placeholder commands like init, build, test, deploy, template, and docs. No code in the file interacts with Podman, containers, Kubernetes, or related desktop functionality, so the implemented behavior is materially different from the stated skill purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script logs command names and user-supplied arguments to a persistent history file under the user’s data directory without notice, consent, or filtering. If users pass secrets, internal paths, tokens, project names, or deployment details as arguments, that sensitive data may be retained on disk and later exposed to other local processes, backups, or support bundles.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented 'clean' command removes build artifacts without any warning, scope definition, or confirmation guidance. In an agent-driven environment, an ambiguously destructive command can delete user data or important generated outputs if invoked in the wrong directory or with incorrect assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes Podman Desktop as a tool to work with containers and Kubernetes, which implies operational functionality in that domain. In this file, the implemented commands only display static text and a TODO placeholder, so the actual behavior does not match the claimed purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.