Back to skill

Security audit

Glances

Security checks for vulnerabilities and agentic risk

Overview

This Glances monitoring skill is mostly purpose-aligned, but it gives agents and users copy-paste guidance for privileged containers, public monitoring endpoints, sudo use, and persistent services without enough scoping or safety controls.

Review this skill before installing. Use it only in trusted administrative environments, avoid running the privileged Docker examples unless you understand Docker socket risk, bind Web/API/server modes to localhost by default, add authentication and network controls before remote access, avoid sudo pip and mutable latest images, and manually review any systemd or cron setup before allowing it to persist.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (6)

T06 · System Persistence

Error
Location
guides/03-advanced-usage.md:333
Finding

Boot-Persistent Glances Service Installed as a System Unit

Content
View full analysis
Remediation
View remediation

T06 · System Persistence

Error
Location
guides/03-advanced-usage.md:429
Finding

Cron Persistence Replaces the User's Entire Crontab

Content
View full analysis
/usr/local/bin/glances-alert.sh << 'EOF' #!/bin/bash CPU=$(curl -s http://localhost:61208/api/3/cpu/total) if (( $(echo "$CPU > 90" | bc -l) )); then echo "ALERT: CPU usage is ${CPU}%" | mail -s "Server Alert" admin@example.com fi EOF chmod +x /usr/local/bin/glances-alert.sh # Check once per minute through cron echo "* * * * * /usr/local/bin/glances-alert.sh" | crontab - ``` ### Technical Analysis The command `crontab -` replaces the current user's complete crontab with the supplied standard input. It does not append or merge the Glances entry. Existing scheduled jobs can therefore be deleted without warning. The new job executes every minute and persists across sessions. The script is installed in `/usr/local/bin`, a system-wide location that normally requires elevated privileges, but the instructions do not define safe ownership, atomic installation, or file permissions. If an untrusted account can alter the script, cron will repeatedly execute attacker-controlled commands with the privileges of the crontab owner. The script also assumes the API response is a valid numeric value. Although the arithmetic expression is not directly passed to a shell command through `eval`, malformed responses can cause errors and should still be validated. ### Attack Path 1. The user follows the alert setup and creates an executable script. 2. The final pipeline invokes `crontab -`. 3. All pre-existing cron entries for that user are replaced. 4. The new script runs automatically every minute and survives the Skill session. 5. If the script becomes writable by another account, that account can modify it and have its commands executed repeatedly as the crontab own ...[truncated 387 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
guides/03-advanced-usage.md:19
Finding

Monitoring Services Are Exposed on All Interfaces Without Mandatory Authentication

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
troubleshooting.md:80
Finding

Troubleshooting Guidance Grants Root or Root-Equivalent Access

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
guides/01-installation.md:42
Finding

Unpinned Packages and Mutable Container Images Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
guides/03-advanced-usage.md:192
Finding

Plaintext and Weak Credential Examples Encourage Insecure Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (68)

Docker Socket Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Mounting /var/run/docker.sock into a container gives processes inside the container effective control over the Docker daemon, which commonly equates to root-equivalent access on the host. Even read-only socket mounts are dangerous because the UNIX socket permissions do not meaningfully constrain Docker API operations the way a read-only file mount would.

Content

Scanner excerpt · guides/01-installation.md (reported line 105)May include surrounding context.

md
docker pull nicolargo/glances:latest

# 以终端模式运行(显示本机系统信息)
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock:ro \
    -v /run/user/1000/podman/podman.sock:/run/user/1000/podman/podman.sock:ro \
    --pid host --network host \
    -it nicolargo/glances:latest

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Using --pid host shares the host PID namespace with the container, allowing visibility into host processes and weakening isolation. Combined with socket mounts and host networking, this significantly increases the blast radius if the container image is malicious or the application is compromised.

Content

Scanner excerpt · guides/01-installation.md (reported line 107)May include surrounding context.

md
# 以终端模式运行(显示本机系统信息)
docker run --rm -v /var/run/docker.sock:/var/run/docker.sock:ro \
    -v /run/user/1000/podman/podman.sock:/run/user/1000/podman/podman.sock:ro \
    --pid host --network host \
    -it nicolargo/glances:latest

# 以 Web 服务器模式运行(端口 61208)

Docker Socket Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

This web-server example again mounts the Docker socket into a long-running service container, extending the window for abuse if the container or exposed web interface is compromised. In this context, the risk is amplified because the service is persistent and network reachable.

Content

Scanner excerpt · guides/01-installation.md (reported line 114)May include surrounding context.

docker run -d --restart="always"
-p 61208-61209:61208-61209
-e GLANCES_OPT="-w"
-v /var/run/docker.sock:/var/run/docker.sock:ro
--pid host
nicolargo/glances:latest

text

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The persistent web mode also uses --pid host, which reduces container isolation for a network-exposed service. This is especially risky because a compromise of the web service could grant an attacker richer insight into host processes and aid lateral movement or escape attempts.

Content

Scanner excerpt · guides/01-installation.md (reported line 115)May include surrounding context.

-p 61208-61209:61208-61209
-e GLANCES_OPT="-w"
-v /var/run/docker.sock:/var/run/docker.sock:ro
--pid host
nicolargo/glances:latest

text

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Docker monitoring example grants powerful host access (/var/run/docker.sock and --pid host) but does not warn that this effectively gives the container extensive visibility into, and potential control over, the host. Readers may run the example verbatim without understanding that Docker socket access can often be escalated into host compromise.

Content

No source excerpt is available for this finding.

Docker Socket Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Mounting /var/run/docker.sock into a container gives that container the ability to interact with the Docker daemon, which often amounts to root-equivalent control over the host. In this monitoring-guide context, the risk is heightened because the example is presented as a convenient copy-paste deployment without emphasizing the host-compromise implications.

Content

Scanner excerpt · guides/03-advanced-usage.md (reported line 319)May include surrounding context.

--name=glances
-p 61208-61209:61208-61209
-e GLANCES_OPT="-w"
-v /var/run/docker.sock:/var/run/docker.sock:ro
--pid host
nicolargo/glances:latest

text

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

Using --pid host places the container in the host PID namespace, exposing host process information and weakening isolation boundaries. Combined with other privileges, it can materially increase the impact of a container compromise and leak sensitive host process metadata.

Content

Scanner excerpt · guides/03-advanced-usage.md (reported line 320)May include surrounding context.

-p 61208-61209:61208-61209
-e GLANCES_OPT="-w"
-v /var/run/docker.sock:/var/run/docker.sock:ro
--pid host
nicolargo/glances:latest

text

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

Running a container with --pid host exposes host process information to the container and weakens isolation boundaries. In combination with monitoring software this may be intentional, but it materially increases the impact of any compromise of that container.

Content

Scanner excerpt · troubleshooting.md (reported line 125)May include surrounding context.

方案B(Docker): 添加必要权限

bash
docker run --rm -it \
  --pid host \
  --network host \
  -v /var/run/docker.sock:/var/run/docker.sock:ro \
  nicolargo/glances:latest-full

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Using --network host removes network namespace isolation and exposes the container directly on the host network stack. This increases attack surface and can enable broader reconnaissance or interference if the container is compromised.

Content

Scanner excerpt · troubleshooting.md (reported line 126)May include surrounding context.

bash
docker run --rm -it \
  --pid host \
  --network host \
  -v /var/run/docker.sock:/var/run/docker.sock:ro \
  nicolargo/glances:latest-full

Docker Socket Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

Mounting /var/run/docker.sock into a container grants that container control over the Docker daemon, which is effectively control over the host in many deployments. Even read-only mounting of the socket file does not meaningfully limit API operations, so this is dangerous advice without a warning.

Content

Scanner excerpt · troubleshooting.md (reported line 127)May include surrounding context.

docker run --rm -it
--pid host
--network host
-v /var/run/docker.sock:/var/run/docker.sock:ro
nicolargo/glances:latest-full

text

Docker Socket Access

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · troubleshooting.md (reported line 190)May include surrounding context.

md
docker ps

# 检查 Docker SDK 是否安装
python -c "import docker; c = docker.from_env(); print(c.containers.list())"

# 检查 docker.sock 权限
ls -la /var/run/docker.sock

Docker Socket Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · troubleshooting.md (reported line 193)May include surrounding context.

python -c "import docker; c = docker.from_env(); print(c.containers.list())"

检查 docker.sock 权限

ls -la /var/run/docker.sock

text

**常见原因**:

Docker Socket Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

Instructing users to point Glances directly at /var/run/docker.sock enables privileged interaction with the Docker daemon. In the context of a monitoring tool, this may be functionally useful, but it still grants access to a root-equivalent control plane and should be clearly warned about.

Content

Scanner excerpt · troubleshooting.md (reported line 217)May include surrounding context.

方案C: 指定 Docker socket

bash
glances --docker-sock /var/run/docker.sock

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly encourages Web UI, API, server mode, remote access, and metric export, but provides no warning that these actions can expose sensitive system telemetry or open network-accessible services. In a monitoring skill, this omission is meaningful because users may launch Glances in listening modes or export data off-host without understanding authentication, binding, firewall, or data sensitivity implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The quick-start section includes commands that start a web server, server mode, remote client connections, REST API mode, and data export, yet gives no accompanying warning about network exposure or telemetry leakage. These copy-pasteable examples increase risk because users may execute them directly, potentially exposing monitoring endpoints or sending operational data to external systems without access controls.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The guide instructs users to pull nicolargo/glances:latest, which is mutable and can change over time without notice. This creates supply-chain and reproducibility risk because users may receive an unexpected image version, including a compromised one if the upstream registry or tag is tampered with.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The Docker examples combine host PID sharing, host networking, and runtime socket mounts, but the document does not clearly warn that these options grant deep visibility into and influence over the host. In an AI-assisted execution context, users may run these commands verbatim without understanding the privilege boundary they are removing.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

The docker run example ultimately launches nicolargo/glances:latest, so it inherits the same mutable-image risk as the preceding pull command. Because the command also runs with elevated container privileges, using an unpinned image makes the consequences of a malicious or unexpected image materially worse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

This detached docker run command also uses nicolargo/glances:latest, exposing users to mutable-tag supply-chain risk. Since it starts a persistent web service, an unexpected image change could introduce long-lived exposure on the host.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · guides/01-installation.md (reported line 199)May include surrounding context.

bash
# Linux / macOS
mkdir -p ~/.config/glances

# 查看默认配置(Glances 自带示例配置)
glances --config /etc/glances/glances.conf 2>/dev/null || echo "使用默认配置"

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The upgrade guidance again tells users to pull :latest, repeating the mutable image risk during maintenance operations. This can silently change deployed behavior and import unreviewed code into an environment.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
81% confidence
Finding

The guide includes sudo pip3 install glances even though it labels it as not recommended. Installing Python packages with sudo pip can overwrite system-managed files, break OS package integrity, and execute arbitrary package install scripts as root, which is a real risk if users copy the fallback command.

Content

Scanner excerpt · guides/01-installation.md (reported line 283)May include surrounding context.

pip3 install --user glances

或使用 sudo(不推荐)

sudo pip3 install glances

text

### 问题3: 国内网络超时

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes the skill as a cross-platform system monitoring tool, which implies observing and reporting system state. This guide instructs use of k to terminate a selected process with SIGKILL, which is an active system-control capability rather than monitoring and is not justified by the stated purpose alone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide lists destructive shortcuts such as process kill (k) and alert deletion/clearing (w, x) without warning about operational impact or irreversibility. For an AI-consumable skill, that creates unsafe affordances by normalizing actions that can terminate workloads or erase useful troubleshooting evidence.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide explicitly tells the AI it can install bottle via pip3 install bottle, which expands the agent's scope from monitoring into modifying the host environment. Package installation can introduce supply-chain risk, alter system state, and violate least-privilege expectations for a monitoring-oriented skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.