Back to skill

Security audit

Lazydocker

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent lazydocker helper, but it includes under-disclosed installation and remote-Docker instructions that can grant broad host-level control or run mutable remote code.

Install only after reviewing the commands. Prefer package-manager installs or pinned releases with checksum/signature verification, avoid curl | bash, do not expose Docker on tcp://0.0.0.0:2375, and treat Docker socket access, container exec, prune/delete, and environment-variable inspection as high-impact operations that should be confirmed for the right host and environment.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
guides/01-installation.md:71
Finding

Mutable Remote Installation Script Executed Directly by Bash

Content
View full analysis
Remediation
View remediation
/scripts/install_update_linux.sh' ``` 4. Publish and require a pinned SHA-256 checksum or a verified publisher signature: ```bash printf '%s %s\n' '' 'install_update_linux.sh' | sha256sum --check - ``` 5. Instruct the user to inspect the downloaded script before execution. 6. Execute it only after verification and explicit approval: ```bash bash install_update_linux.sh ``` 7. Prefer a trusted system package manager or a signed release package over a remote installation script. 8. Apply the same remediation to the installation, upgrade, and troubleshooting copies of the command. ]]>

T08 · Insecure Dependencies

Error
Location
guides/01-installation.md:93
Finding

Unpinned and Unverified Executable Dependencies

Content
View full analysis
Remediation
View remediation
``` 4. Download checksums and signatures from an authenticated release process, then verify them before extraction. 5. Use a checksum value pinned in the Skill or obtained through an independently authenticated channel. 6. Extract archives into a newly created temporary directory and verify the expected file names and types before installation. 7. Do not use `sudo mv` until integrity verification has succeeded and the user has explicitly approved the system-wide installation. 8. Prefer trusted OS package repositories that support signed package metadata and version pinning. 9. Document a controlled update process so version changes receive a new review rather than being adopted automatically. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
troubleshooting.md:402
Finding

Unauthenticated Docker Daemon Exposure on All Network Interfaces

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
guides/03-advanced-usage.md:86
Finding

Custom Command Discloses All Container Environment Values

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (45)

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The | bash chain executes remote content immediately, collapsing retrieval and execution into a single unreviewed step. This materially increases the chance that a user runs malicious or tampered content without inspection.

Content

Scanner excerpt · guides/01-installation.md (reported line 71)May include surrounding context.

bash
# 下载并运行官方安装脚本
curl https://raw.githubusercontent.com/jesseduffield/lazydocker/master/scripts/install_update_linux.sh | bash

此脚本将自动:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The Docker-based option mounts /var/run/docker.sock without warning users that this effectively grants the container broad control over the host Docker daemon. A compromised or untrusted container with socket access can start privileged containers, mount host filesystems, and potentially obtain host-level control.

Content

No source excerpt is available for this finding.

Docker Socket Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

Mounting the host Docker socket into a container exposes powerful control over the Docker daemon and, by extension, the host. In an installation guide, this is especially sensitive because users may run it without understanding that the container can potentially create privileged containers or access host resources.

Content

Scanner excerpt · guides/01-installation.md (reported line 163)May include surrounding context.

bash
# 使用 Docker 运行 lazydocker(挂载 Docker socket)
docker run --rm -it \
  -v /var/run/docker.sock:/var/run/docker.sock \
  -v ~/.config/lazydocker:/.config/jesseduffield/lazydocker \
  lazyteam/lazydocker

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · guides/01-installation.md (reported line 179)May include surrounding context.

it
-v /var/run/docker.sock:/var/run/docker.sock
-v ~/.config/lazydocker:/.config/jesseduffield/lazydocker
lazyteam/lazydocker

text

---

## 三、配置 PATH(如需)

如果使用脚本安装或手动下载,需要确保 lazydocker 在 PATH 中:

```bash
# 检查 lazydocker 是否可被找到
which lazydocker

# 如果未找到,手动添加到 PATH(以 ~/.local/bin 为例)
echo 'export PATH=$PATH:$HOME/.local/bin' >> ~/.bashrc
source ~/.bashrc

# zsh 用户
echo 'export PATH=$PATH:$HOME/.local/bin' >> ~/.zshrc
source ~/.zshrc

四、验证安装

AI执行说明: AI 将验证 lazydocker 是否正确安装

bash
# 检查版本
lazydocker --version

# 测试启动(确保 Docker 正在运行)
docker ps && lazydocker

成功标志:

  • lazydocker 版本信息正常显示 ✅
  • lazydocker TUI 界面成功启动 ✅
  • 容器列表(或空状态)正常显示 ✅

五、升级 lazydocker

Homebrew 升级

bash
brew upgrade j

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The upgrade path repeats the same unsafe pattern of piping a remote script directly into bash. Because upgrades may be performed repeatedly over time, this extends exposure to future supply-chain compromise as well.

Content

Scanner excerpt · guides/01-installation.md (reported line 220)May include surrounding context.

bash
# 同安装脚本,可重复运行以升级
curl https://raw.githubusercontent.com/jesseduffield/lazydocker/master/scripts/install_update_linux.sh | bash

go install 升级

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · guides/01-installation.md (reported line 238)May include surrounding context.

md
brew uninstall lazydocker

# 手动安装的卸载
sudo rm /usr/local/bin/lazydocker

# 删除配置文件(可选)
rm -rf ~/.config/jesseduffield/lazydocker

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · guides/01-installation.md (reported line 241)May include surrounding context.

sudo rm /usr/local/bin/lazydocker

删除配置文件(可选)

rm -rf ~/.config/jesseduffield/lazydocker

text

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · guides/01-installation.md (reported line 241)May include surrounding context.

sudo rm /usr/local/bin/lazydocker

删除配置文件(可选)

rm -rf ~/.config/jesseduffield/lazydocker

text

---

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · troubleshooting.md (reported line 40)May include surrounding context.

ot found`

排查步骤:

bash
# 检查安装位置
which lazydocker
ls ~/.local/bin/lazydocker
ls /usr/local/bin/lazydocker

# 检查 PATH 变量
echo $PATH

常见原因:

  • 安装目录不在 PATH 中(50%)
  • 安装未成功(30%)
  • 使用了错误的 shell(20%)

解决方案:

方案A(推荐): 添加安装目录到 PATH

bash
# 如果安装在 ~/.local/bin
echo 'export PATH=$PATH:$HOME/.local/bin' >> ~/.bashrc
source ~/.bashrc

# zsh 用户
echo 'export PATH=$PATH:$HOME/.local/bin' >> ~/.zshrc
source ~/.zshrc

方案B: 重新安装(Homebrew)

bash
brew install jesseduffield/lazydocker/lazydocker

方案C: 创建符号链接

bash
sudo ln -s ~/.local/bin/lazydocker /usr/local/bin/lazydocker

2. Homebrew 安装失败【简单问题】

问题描述: brew install 命令报错

排查步骤:

bash
# 检查 Homebrew 版本
brew --version

# 更新 Homebrew
brew update

# 检查 tap 是否存在
brew ta

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The '| bash' construct is the dangerous portion that turns a network fetch into immediate shell execution. In user-facing troubleshooting docs, this normalizes a high-risk pattern and removes the opportunity for users to inspect what they are about to run.

Content

Scanner excerpt · troubleshooting.md (reported line 91)May include surrounding context.

方案B(使用安装脚本代替):

bash
curl https://raw.githubusercontent.com/jesseduffield/lazydocker/master/scripts/install_update_linux.sh | bash

方案C(手动下载二进制):

Docker Socket Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · troubleshooting.md (reported line 103)May include surrounding context.

3. 启动时提示"Cannot connect to the Docker daemon"【中等问题】

问题描述: 运行 lazydocker 后报错 Cannot connect to the Docker daemon at unix:///var/run/docker.sock

排查步骤:

bash

Docker Socket Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · troubleshooting.md (reported line 111)May include surrounding context.

md
docker info

# 2. 检查 Docker socket 是否存在
ls -la /var/run/docker.sock

# 3. 检查当前用户权限
groups $(whoami)

Docker Socket Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The document recommends configuring Docker to listen on 'tcp://0.0.0.0:2375', which exposes the Docker API on all interfaces without TLS. An attacker who can reach that port can typically gain full control over containers and often root-equivalent control over the host, making this far more dangerous than ordinary troubleshooting advice.

Content

Scanner excerpt · troubleshooting.md (reported line 408)May include surrounding context.

在远程服务器的 /etc/docker/daemon.json 中添加:

json
{
  "hosts": ["unix:///var/run/docker.sock", "tcp://0.0.0.0:2375"]
}

然后重启 Docker: sudo systemctl restart docker

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly promotes destructive Docker operations such as deleting containers, images, and volumes, but does not warn that these actions can permanently remove data or disrupt live services. In a skill intended to guide users through operational tasks, omission of safety guardrails materially increases the chance of accidental destructive actions, especially when an AI may automate or strongly recommend those steps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The shortcut table exposes high-risk actions such as deleting Docker resources and opening an interactive shell inside containers without explaining the security or operational consequences. This is dangerous because users may trigger privileged or destructive actions from the TUI with minimal friction, leading to unauthorized modification, secrets exposure, or accidental downtime.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide instructs users to pipe a remote script directly into bash without any warning or verification step. This is dangerous because any compromise of the source, transport, or referenced branch could result in immediate arbitrary code execution on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manual installation instructions use sudo mv to place a downloaded binary into /usr/local/bin but do not warn that this modifies a privileged system path. If the downloaded file is malicious or tampered with, this grants it trusted execution on the system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The Docker-based installation example references the image as lazyteam/lazydocker without a fixed tag or digest, so users may pull whatever image is current at execution time. That weakens reproducibility and supply-chain trust, especially because the container is also granted sensitive Docker socket access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The uninstall section includes destructive deletion commands, including recursive removal of configuration data, without an explicit warning about data loss. Users may unintentionally remove binaries or configuration they expected to keep, especially if commands are copied blindly.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · guides/01-installation.md (reported line 238)May include surrounding context.

md
brew uninstall lazydocker

# 手动安装的卸载
sudo rm /usr/local/bin/lazydocker

# 删除配置文件(可选)
rm -rf ~/.config/jesseduffield/lazydocker

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · troubleshooting.md (reported line 381)May include surrounding context.

md
brew uninstall lazydocker

# 手动安装的卸载
sudo rm /usr/local/bin/lazydocker

# 删除配置文件(可选)
rm -rf ~/.config/jesseduffield/lazydocker

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · troubleshooting.md (reported line 384)May include surrounding context.

md
brew uninstall lazydocker

# 手动安装的卸载
sudo rm /usr/local/bin/lazydocker

# 删除配置文件(可选)
rm -rf ~/.config/jesseduffield/lazydocker

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide instructs users or an AI agent to enter a live container shell and execute arbitrary commands without any warning about production impact, persistence, privilege level, or forensic traceability. In the context of an agent skill, this is risky because it normalizes direct modification of running workloads and could lead to service disruption, accidental data changes, or unsafe command execution in privileged containers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Compose management section documents destructive actions such as pull/recreate, stop, and down without warning that these operations can interrupt running services, replace containers, and potentially affect availability or attached state. For an AI-operated workflow, omission of such safeguards increases the chance of unreviewed service-impacting actions being performed automatically in the wrong environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · guides/03-advanced-usage.md (reported line 20)May include surrounding context.

bash
# 创建配置目录
mkdir -p ~/.config/jesseduffield/lazydocker

# 创建或编辑配置文件
$EDITOR ~/.config/jesseduffield/lazydocker/config.yml

Static analysis

No suspicious patterns detected.