Back to skill

Security audit

sop-dev-003-docker-workaround-host-commands

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documented Docker-host workaround, but it creates a broad host-execution bridge through Docker commands that needs careful review before use.

Install only if you trust the operators who will review and run host Docker commands. Require explicit human approval for every generated host-commands.sh, reject privileged/host-mounted/socket-mounted Docker commands unless separately justified, prefer pinned image digests, and verify cleanup and logs after each run.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The skill establishes a mechanism for the agent to prepare a host-executed script and have a human/operator run it outside the sandbox. Even though it says to include only Docker commands, this creates a trust bridge from untrusted agent output to host execution, and Docker commands themselves can be highly privileged via mounts, host networking, privileged mode, or access to existing containers.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
- Un comando por línea, con `set -e` implícito (fallo detiene ejecución)
   - Incluir solo comandos Docker; NO comandos arbitrarios de host
   - Comentar cada bloque con propósito
3. **Hacer ejecutable** — `chmod +x /workspace/host-commands.sh`
4. **Registrar en COMMS** — Escribir bloque `WORKBOARD_BLOCK` con:
   - REASON: "Docker operation required — host-commands.sh ready"
   - COMMANDS_FILE: `/workspace/host-commands.sh`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

This SOP creates a host-executed script bridge that lets the agent prepare commands for execution outside the sandbox, relying on a human/operator review step as the primary control. Even though it restricts content to Docker commands, Docker commands on the host can still be highly privileged (e.g. mounting host paths, using --privileged, escaping isolation, accessing secrets, or affecting other containers), so the mechanism materially expands the attack surface if an agent is compromised or makes unsafe decisions.

Content

Scanner excerpt · sop-dev-003-docker-workaround-host-commands.yaml (reported line 30)May include surrounding context.

yaml
\ run --rm <imagen> <comando>\n   # ... más comandos\n   ```\n   - Un comando por\
  \ línea, con `set -e` implícito (fallo detiene ejecución)\n   - Incluir solo comandos\
  \ Docker; NO comandos arbitrarios de host\n   - Comentar cada bloque con propósito\n\
  3. **Hacer ejecutable** — `chmod +x /workspace/host-commands.sh`\n4. **Registrar\
  \ en COMMS** — Escribir bloque `WORKBOARD_BLOCK` con:\n   - REASON: \"Docker operation\
  \ required — host-commands.sh ready\"\n   - COMMANDS_FILE: `/workspace/host-commands.sh`\n\
  \   - STATUS: WAITING_HOST_EXEC\n   - CARD_ID: <card_id>\n5. **Bloquear workboard\

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
\ → escalar a main para decisión de arquitectura\n- Si timeout > 5 min en ejecución\
  \ host → STATUS: BLOCKED → investigar hang\n- Si main/operator no ejecuta en 30\
  \ min → STATUS: ESCALATED → notificar en COMMS_main.md\n\n## Seguridad\n- **NUNCA**\
  \ escribir comandos no-Docker en host-commands.sh (rm -rf, chmod 777, curl | bash,\
  \ etc.)\n- **NUNCA** usar host-commands.sh para operaciones que sandbox puede hacer\n\
  - Auditoría: main/operator revisa host-commands.sh ANTES de ejecutar\n- Log de ejecuciones\
  \ se mantiene en COMMS_main.md con timestamp y resultado\n\n---\n*Ref: ~/.openclaw/workspace/gobierno/SOP_STANDARD.md*"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · sop-dev-003-docker-workaround-host-commands.yaml (reported line 51)May include surrounding context.

yaml
\ → escalar a main para decisión de arquitectura\n- Si timeout > 5 min en ejecución\
  \ host → STATUS: BLOCKED → investigar hang\n- Si main/operator no ejecuta en 30\
  \ min → STATUS: ESCALATED → notificar en COMMS_main.md\n\n## Seguridad\n- **NUNCA**\
  \ escribir comandos no-Docker en host-commands.sh (rm -rf, chmod 777, curl | bash,\
  \ etc.)\n- **NUNCA** usar host-commands.sh para operaciones que sandbox puede hacer\n\
  - Auditoría: main/operator revisa host-commands.sh ANTES de ejecutar\n- Log de ejecuciones\
  \ se mantiene en COMMS_main.md con timestamp y resultado\n\n---\n*Ref: ~/.openclaw/workspace/gobierno/SOP_STANDARD.md*"

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The SOP instructs operators to run docker run --rm <imagen> <comando> without requiring an explicit tag or digest. In a host-execution workflow, using unpinned images can silently pull changing or maliciously replaced content, making builds and executions non-reproducible and potentially exposing the host to unreviewed code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This manifest’s natural-language instructions, title, description, and procedure are all Spanish-only. Under the policy, forcing a specific language without user opt-in or a clearly justified locale-specific scope is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
\ → escalar a main para decisión de arquitectura\n- Si timeout > 5 min en ejecución\
  \ host → STATUS: BLOCKED → investigar hang\n- Si main/operator no ejecuta en 30\
  \ min → STATUS: ESCALATED → notificar en COMMS_main.md\n\n## Seguridad\n- **NUNCA**\
  \ escribir comandos no-Docker en host-commands.sh (rm -rf, chmod 777, curl | bash,\
  \ etc.)\n- **NUNCA** usar host-commands.sh para operaciones que sandbox puede hacer\n\
  - Auditoría: main/operator revisa host-commands.sh ANTES de ejecutar\n- Log de ejecuciones\
  \ se mantiene en COMMS_main.md con timestamp y resultado\n\n---\n*Ref: ~/.openclaw/workspace/gobierno/SOP_STANDARD.md*"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · sop-dev-003-docker-workaround-host-commands.yaml (reported line 51)May include surrounding context.

yaml
\ → escalar a main para decisión de arquitectura\n- Si timeout > 5 min en ejecución\
  \ host → STATUS: BLOCKED → investigar hang\n- Si main/operator no ejecuta en 30\
  \ min → STATUS: ESCALATED → notificar en COMMS_main.md\n\n## Seguridad\n- **NUNCA**\
  \ escribir comandos no-Docker en host-commands.sh (rm -rf, chmod 777, curl | bash,\
  \ etc.)\n- **NUNCA** usar host-commands.sh para operaciones que sandbox puede hacer\n\
  - Auditoría: main/operator revisa host-commands.sh ANTES de ejecutar\n- Log de ejecuciones\
  \ se mantiene en COMMS_main.md con timestamp y resultado\n\n---\n*Ref: ~/.openclaw/workspace/gobierno/SOP_STANDARD.md*"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description field uses Spanish text only ("Descripción de SOP: dev") with no indication that the skill is intended only for Spanish-speaking users or that language selection is configurable. This can violate language/locale policy when a skill imposes a language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.