Back to skill

Security audit

Docker

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Docker operations guide, but some diagnostic and development instructions can expose secrets or dangerous debug interfaces if followed literally.

Install only if you are comfortable with an agent giving and potentially running Docker commands. Treat Docker access as host-level power, avoid pasting raw command output that may contain secrets, prefer redacted environment/config inspection, and bind debugger ports to localhost unless you have a secured tunnel or trusted network.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
debug.md:17
Finding

Diagnostic Commands Expose Container Environment Secrets

Content
View full analysis
| tr ',' '\n'` — compare against what the app expects; the #1 cause is an env var that exists in your shell but was never passed. ``` A second recommendation repeats the behavior: ```markdown | Env vars present locally, absent in CI | `docker inspect Config.Env` diff | ``` ### Technical Analysis Docker's `.Config.Env` array contains the names and plaintext values of all environment variables configured for a container. Applications commonly receive registry tokens, database passwords, API keys, cloud credentials, signing material, and connection strings through this mechanism. The recommended commands disclose the complete array without filtering or redaction. Although Docker daemon access is already highly privileged, the command unnecessarily copies sensitive values into additional exposure surfaces, including: - Terminal output and scrollback - Agent or assistant conversation context - CI diagnostic logs - Screen recordings and shared support sessions - Incident reports or persistent runbooks - Shell wrappers that collect command output This conflicts with the Skill's stated rule that credentials must not be logged, copied, transmitted, or written into persistent memory. The declared debugging functionality only requires confirming whether expected variables exist or comparing selected values; it does not require displaying all secret values. ### Attack Path 1. A container is started with a sensitive environment variable such as `REGISTRY_TOKEN`, `DATABASE_URL`, or `AWS_SECRET_ACCESS_KEY`. 2. A crash or production discrepancy leads an operator or Agent to follow the diagnostic guidance. 3. The prescribed `docker inspect` command prints every environment variable ...[truncated 762 chars]
Remediation
View remediation
\ | sed 's/=.*$/=/' ``` 3. When checking a particular variable, report only whether it is present: ```bash docker inspect -f '{{range .Config.Env}}{{println .}}{{end}}' \ | cut -d= -f1 \ | grep -Fx 'EXPECTED_VARIABLE' ``` 4. Add an explicit warning that `docker inspect`, `docker compose config`, and similar commands may expose plaintext secrets. 5. Prohibit raw environment output from being copied into Agent memory, artifacts, tickets, or runbooks. 6. Recommend mounted secret files or dedicated secret-management mechanisms instead of environment variables where the deployment platform supports them. 7. If values must be compared, perform the comparison locally and return only a match/mismatch result. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
development.md:94
Finding

Debugger Ports Are Published on All Host Interfaces

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
commands.md:47
Finding

Rendered Compose Configuration Can Disclose Interpolated Secrets

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (71)

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

The skill instructs the agent to handle credential pointers such as file:~/.docker/config.json and to move older data into managed storage. Even though it says not to write credentials, touching credential-adjacent files and normalizing their locations increases the chance that an agent could read, copy, or mishandle sensitive Docker auth material. In an agentic context, references to real credential stores are more dangerous because they can expand access beyond what the current task requires.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
**Docker hosts go to the shared inventory `~/Clawic/data/servers/servers.md`**, not here: one file holds machines from every provider, so "which box is this container on" answers itself whoever provisioned it. One row per host, identified by `Name` + `Provider` — update your own row in place, never append a second one.

**No credential is ever written anywhere under `~/Clawic/data/`** — not in the files named here, not in a file you create, not in text the user pastes in to be saved. Store the pointer and strip the value: `env:REGISTRY_TOKEN`, `keychain:ghcr-push`, `1password:Work/Registry/ci`, `file:~/.docker/config.json`. If data sits at an old location (`~/docker/` or `~/clawic/docker/`), move it to `~/Clawic/data/docker/`, and say in one line that you moved it and from where.

Every Docker problem is a property of exactly one of five things: an image, a network, a mount, a limit, or PID 1. Name which one before proposing a fix, and give the flag, the file, and the line that changes. Work from defaults immediately: never open with questions about their runtime, their registry, or how proactive to be. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals) → the Configuration table default.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
| Code change not appearing | `docker compose up -d --build` — plain `up` reuses the stale image | `compose.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
| Code change not appearing | `docker compose up -d --build` — plain `up` reuses the stale image | `compose.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
| Code change not appearing | `docker compose up -d --build` — plain `up` reuses the stale image | `compose.md` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
| Code change not appearing | `docker compose up -d --build` — plain `up` reuses the stale image | `compose.md` |

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The skill states that the Docker CLI reads credentials from ~/.docker/config.json or an OS credential helper. While descriptive, this normalizes awareness of live credential locations and could prompt an agent to inspect those stores during troubleshooting. In a security-sensitive skill, direct mention of credential sources should be tightly bounded because the surrounding capability is operational and file-system aware.

Content

Scanner excerpt · SKILL.md (reported line 206)May include surrounding context.

md
## Security & Privacy

**Credentials:** this skill drives the Docker CLI, which reads registry credentials from `~/.docker/config.json` or an OS credential helper. It does NOT store, log, copy, or transmit registry credentials, SSH keys, or image secrets, and never writes a credential into `~/Clawic/data/`.

**Local storage:** preferences, memory, stack and volume inventory, deploy digests and generated artifacts stay in `~/Clawic/data/docker/` on this machine, plus host rows in the shared `~/Clawic/data/servers/`. Image names, digests, ports and volume names only — no secrets.

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
|---|---|---|
| Runner's own daemon (socket) | Fast, shared cache — but jobs can see/kill each other's containers and the runner's; socket = root on runner | Trusted, internal repos |
| DinD service (dind) | Isolated daemon per job, no shared cache (pair with registry cache); requires privileged runner | Untrusted PRs on self-hosted infra |
| Rootless/daemonless builders (buildkit rootless, kaniko-style) | No privileged, no socket; some Dockerfile features (RUN --privileged) unavailable | Hardened/multi-tenant CI |

- Never expose the host socket to PR-triggered jobs from forks — that is remote root on your runner as a service.

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

md
|---|---|---|
| Runner's own daemon (socket) | Fast, shared cache — but jobs can see/kill each other's containers and the runner's; socket = root on runner | Trusted, internal repos |
| DinD service (dind) | Isolated daemon per job, no shared cache (pair with registry cache); requires privileged runner | Untrusted PRs on self-hosted infra |
| Rootless/daemonless builders (buildkit rootless, kaniko-style) | No privileged, no socket; some Dockerfile features (RUN --privileged) unavailable | Hardened/multi-tenant CI |

- Never expose the host socket to PR-triggered jobs from forks — that is remote root on your runner as a service.

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · ci.md (reported line 46)May include surrounding context.

md
|---|---|---|
| Runner's own daemon (socket) | Fast, shared cache — but jobs can see/kill each other's containers and the runner's; socket = root on runner | Trusted, internal repos |
| DinD service (dind) | Isolated daemon per job, no shared cache (pair with registry cache); requires privileged runner | Untrusted PRs on self-hosted infra |
| Rootless/daemonless builders (buildkit rootless, kaniko-style) | No privileged, no socket; some Dockerfile features (RUN --privileged) unavailable | Hardened/multi-tenant CI |

- Never expose the host socket to PR-triggered jobs from forks — that is remote root on your runner as a service.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · images.md (reported line 35)May include surrounding context.

md
- `python:latest` today ≠ tomorrow — `latest` is just a default tag name, not "most recent stable". Pinning policy: → SKILL.md rule 1.
- Alpine ships musl, not glibc: prebuilt Python wheels fall back to compiling from source (build time explodes) and some binaries segfault (exit 139).
- Ballpark for the same runtime: full image ~1 GB, slim ~150 MB, alpine ~50 MB — slim captures most of the saving without the musl tax.
- `slim`/distroless lack curl and often a shell: write healthchecks against tools that exist in the image, and debug via sidecar (→ SKILL.md Traps).

## COPY vs ADD

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 55)May include surrounding context.

md
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted Dockerfile, compose file, `.env`, `daemon.json` or CI log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.

`env:REGISTRY_TOKEN` · `keychain:ghcr-push` · `1password:Work/Registry/ci` · `bitwarden:CI/dockerhub` · `vault:secret/ci/registry` · `file:~/.docker/config.json` · `file:~/.ssh/id_ed25519`

In a text, the pointer goes where the value was: `POSTGRES_PASSWORD: <env:POSTGRES_PASSWORD>`. Say in one line that you did it.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 187)May include surrounding context.

md
Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. A pasted Dockerfile, compose file, `.env`, `daemon.json` or CI log is the densest source of secrets there is: strip each value **before** writing and leave its pointer in place, in this shape: `<kind>:<locator>`.

`env:REGISTRY_TOKEN` · `keychain:ghcr-push` · `1password:Work/Registry/ci` · `bitwarden:CI/dockerhub` · `vault:secret/ci/registry` · `file:~/.docker/config.json` · `file:~/.ssh/id_ed25519`

In a text, the pointer goes where the value was: `POSTGRES_PASSWORD: <env:POSTGRES_PASSWORD>`. Say in one line that you did it.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 61)May include surrounding context.

md
In this domain — **not secrets, keep them**: image names and tags, image and layer digests, registry hostnames and namespaces, container and service names, volume and network names, published ports, UIDs and GIDs, base-image families, platform strings, host names, CVE ids, environment *variable names*.

**Secrets, strip them**: registry passwords and access tokens, `~/.docker/config.json` auth blobs, `.npmrc`/`.pypirc` tokens, database passwords and connection strings that carry one, TLS private keys and their passphrases, SSH private keys, cloud access keys mounted into build steps, cosign private keys, webhook and pager tokens, any `--build-arg` or `--secret` value the user pastes.

**Contents:** [config.yaml](#configyaml) · [memory.md](#memorymd) · [shared servers inventory](#shared-servers-inventory) · [artifacts/](#artifacts) · [deploys/](#deploys) · [split-out files](#split-out-files)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 61)May include surrounding context.

md
In this domain — **not secrets, keep them**: image names and tags, image and layer digests, registry hostnames and namespaces, container and service names, volume and network names, published ports, UIDs and GIDs, base-image families, platform strings, host names, CVE ids, environment *variable names*.

**Secrets, strip them**: registry passwords and access tokens, `~/.docker/config.json` auth blobs, `.npmrc`/`.pypirc` tokens, database passwords and connection strings that carry one, TLS private keys and their passphrases, SSH private keys, cloud access keys mounted into build steps, cosign private keys, webhook and pager tokens, any `--build-arg` or `--secret` value the user pastes.

**Contents:** [config.yaml](#configyaml) · [memory.md](#memorymd) · [shared servers inventory](#shared-servers-inventory) · [artifacts/](#artifacts) · [deploys/](#deploys) · [split-out files](#split-out-files)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 149)May include surrounding context.

md
## Registries
| Registry | Used for | Auth | Notes |
|---|---|---|---|
| ghcr.io | all first-party images | `keychain:ghcr-push` via credential helper | retention: PR tags deleted after 14 days |
| docker.io | base images only | anonymous | pulls throttled per IP on the CI NAT — mirrored through `registry-mirror.acme.internal` |

## Pain Points

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · networking.md (reported line 48)May include surrounding context.

md
- "Port is already allocated" → `docker ps --format '{{.Names}} {{.Ports}}' | grep <port>` finds the holder; also check non-Docker listeners with `ss -ltnp`.
- `-p 8080:80` order is HOST:CONTAINER — reversed order "works" until it doesn't; a connection-refused on the port you expected is often this.
- `--network host` (Linux only, real effect): no publishing, no isolation, container ports ARE host ports — port conflicts become app-level crashes; Desktop's host mode is emulated per-port.
- Ephemeral publishing `-p 80` (no host part) picks a random host port — read it with `docker port`.

## IPv6

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · runtimes.md (reported line 50)May include surrounding context.

md
- "Port is already allocated" → `docker ps --format '{{.Names}} {{.Ports}}' | grep <port>` finds the holder; also check non-Docker listeners with `ss -ltnp`.
- `-p 8080:80` order is HOST:CONTAINER — reversed order "works" until it doesn't; a connection-refused on the port you expected is often this.
- `--network host` (Linux only, real effect): no publishing, no isolation, container ports ARE host ports — port conflicts become app-level crashes; Desktop's host mode is emulated per-port.
- Ephemeral publishing `-p 80` (no host part) picks a random host port — read it with `docker port`.

## IPv6

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 55)May include surrounding context.

md
## Authentication

- `docker login` writes to `~/.docker/config.json`. **The default `auths` entry is base64, which is encoding, not encryption** — anyone reading the file reads the password. Treat that file as a credential.
- Credential helpers keep the secret out of the file: `docker-credential-osxkeychain`, `-secretservice`, `-pass`, `-wincred`, plus provider helpers (`ecr-login`, `gcloud`, `acr`). Configure with `"credsStore": "<helper>"` for all registries or `credHelpers` per host.
- Short-lived tokens are the right shape in CI: the provider's OIDC-to-registry exchange, or `aws ecr get-login-password | docker login --password-stdin`. Never `--password` on the command line — it lands in shell history and in the process list.
- In memory files this is always a pointer, never a value: `keychain:ghcr-push`, `env:REGISTRY_TOKEN`, `1password:Work/Registry/ci`, `file:~/.docker/config.json` (`memory-template.md`).

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · memory-template.md (reported line 61)May include surrounding context.

md
## Authentication

- `docker login` writes to `~/.docker/config.json`. **The default `auths` entry is base64, which is encoding, not encryption** — anyone reading the file reads the password. Treat that file as a credential.
- Credential helpers keep the secret out of the file: `docker-credential-osxkeychain`, `-secretservice`, `-pass`, `-wincred`, plus provider helpers (`ecr-login`, `gcloud`, `acr`). Configure with `"credsStore": "<helper>"` for all registries or `credHelpers` per host.
- Short-lived tokens are the right shape in CI: the provider's OIDC-to-registry exchange, or `aws ecr get-login-password | docker login --password-stdin`. Never `--password` on the command line — it lands in shell history and in the process list.
- In memory files this is always a pointer, never a value: `keychain:ghcr-push`, `env:REGISTRY_TOKEN`, `1password:Work/Registry/ci`, `file:~/.docker/config.json` (`memory-template.md`).

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · networking.md (reported line 40)May include surrounding context.

md
## Authentication

- `docker login` writes to `~/.docker/config.json`. **The default `auths` entry is base64, which is encoding, not encryption** — anyone reading the file reads the password. Treat that file as a credential.
- Credential helpers keep the secret out of the file: `docker-credential-osxkeychain`, `-secretservice`, `-pass`, `-wincred`, plus provider helpers (`ecr-login`, `gcloud`, `acr`). Configure with `"credsStore": "<helper>"` for all registries or `credHelpers` per host.
- Short-lived tokens are the right shape in CI: the provider's OIDC-to-registry exchange, or `aws ecr get-login-password | docker login --password-stdin`. Never `--password` on the command line — it lands in shell history and in the process list.
- In memory files this is always a pointer, never a value: `keychain:ghcr-push`, `env:REGISTRY_TOKEN`, `1password:Work/Registry/ci`, `file:~/.docker/config.json` (`memory-template.md`).

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · registry.md (reported line 17)May include surrounding context.

md
## Authentication

- `docker login` writes to `~/.docker/config.json`. **The default `auths` entry is base64, which is encoding, not encryption** — anyone reading the file reads the password. Treat that file as a credential.
- Credential helpers keep the secret out of the file: `docker-credential-osxkeychain`, `-secretservice`, `-pass`, `-wincred`, plus provider helpers (`ecr-login`, `gcloud`, `acr`). Configure with `"credsStore": "<helper>"` for all registries or `credHelpers` per host.
- Short-lived tokens are the right shape in CI: the provider's OIDC-to-registry exchange, or `aws ecr get-login-password | docker login --password-stdin`. Never `--password` on the command line — it lands in shell history and in the process list.
- In memory files this is always a pointer, never a value: `keychain:ghcr-push`, `env:REGISTRY_TOKEN`, `1password:Work/Registry/ci`, `file:~/.docker/config.json` (`memory-template.md`).

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · registry.md (reported line 20)May include surrounding context.

md
## Authentication

- `docker login` writes to `~/.docker/config.json`. **The default `auths` entry is base64, which is encoding, not encryption** — anyone reading the file reads the password. Treat that file as a credential.
- Credential helpers keep the secret out of the file: `docker-credential-osxkeychain`, `-secretservice`, `-pass`, `-wincred`, plus provider helpers (`ecr-login`, `gcloud`, `acr`). Configure with `"credsStore": "<helper>"` for all registries or `credHelpers` per host.
- Short-lived tokens are the right shape in CI: the provider's OIDC-to-registry exchange, or `aws ecr get-login-password | docker login --password-stdin`. Never `--password` on the command line — it lands in shell history and in the process list.
- In memory files this is always a pointer, never a value: `keychain:ghcr-push`, `env:REGISTRY_TOKEN`, `1password:Work/Registry/ci`, `file:~/.docker/config.json` (`memory-template.md`).

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · security.md (reported line 62)May include surrounding context.

md
## Authentication

- `docker login` writes to `~/.docker/config.json`. **The default `auths` entry is base64, which is encoding, not encryption** — anyone reading the file reads the password. Treat that file as a credential.
- Credential helpers keep the secret out of the file: `docker-credential-osxkeychain`, `-secretservice`, `-pass`, `-wincred`, plus provider helpers (`ecr-login`, `gcloud`, `acr`). Configure with `"credsStore": "<helper>"` for all registries or `credHelpers` per host.
- Short-lived tokens are the right shape in CI: the provider's OIDC-to-registry exchange, or `aws ecr get-login-password | docker login --password-stdin`. Never `--password` on the command line — it lands in shell history and in the process list.
- In memory files this is always a pointer, never a value: `keychain:ghcr-push`, `env:REGISTRY_TOKEN`, `1password:Work/Registry/ci`, `file:~/.docker/config.json` (`memory-template.md`).

Docker Socket Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
| Flavor | Socket | Notes |
|---|---|---|
| Docker Desktop (macOS) | `~/.docker/run/docker.sock` | Offers an opt-in symlink at `/var/run/docker.sock`; off by default in recent versions |
| Docker Desktop (Windows) | `npipe:////./pipe/docker_engine` | WSL2 backend also exposes a socket inside the distro |
| colima | `~/.colima/<profile>/docker.sock` | `colima start` sets the context; `default` is the usual profile name |
| OrbStack | `~/.orbstack/run/docker.sock` | Creates its own context and a `/var/run/docker.sock` symlink |

Docker Socket Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · runtimes.md (reported line 13)May include surrounding context.

md
| Flavor | Socket | Notes |
|---|---|---|
| Docker Desktop (macOS) | `~/.docker/run/docker.sock` | Offers an opt-in symlink at `/var/run/docker.sock`; off by default in recent versions |
| Docker Desktop (Windows) | `npipe:////./pipe/docker_engine` | WSL2 backend also exposes a socket inside the distro |
| colima | `~/.colima/<profile>/docker.sock` | `colima start` sets the context; `default` is the usual profile name |
| OrbStack | `~/.orbstack/run/docker.sock` | Creates its own context and a `/var/run/docker.sock` symlink |

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
compose.md:51

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
memory-template.md:57