Back to skill

Security audit

Docker Mirror

Security checks for vulnerabilities and agentic risk

Overview

This Docker mirror helper has a clear purpose, but its wrapper can execute unsafe shell input and can hide third-party mirror provenance by retagging images as originals.

Review this skill before installing. It should only be used in environments where you trust the listed mirrors and understand that Docker access can affect host-adjacent state. Avoid untrusted image names or arguments, prefer digest-pinned images, and do not use this wrapper for arbitrary Docker commands until the sg -c argument handling is fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/docker.sh:9
Finding

Shell Command Injection Through Untrusted Docker Arguments

Content
View full analysis
&1; then echo "Done!" exit 0 fi ``` ```bash echo "Trying: docker pull $MIRROR_PATH" if sg docker -c "docker pull $MIRROR_PATH" 2>&1; then # Success — tag back to original image name and clean up echo "Tagging $MIRROR_PATH -> $IMAGE" sg docker -c "docker tag '$MIRROR_PATH' '$IMAGE'" 2>/dev/null echo "Cleaning up" sg docker -c "docker rmi '$MIRROR_PATH'" 2>/dev/null echo "Done!" exit 0 fi ``` ### Technical Analysis The script incorporates user-controlled arguments into strings passed to `sg docker -c`. The `-c` option causes a shell to parse the supplied string again. Consequently, shell metacharacters contained in `$*`, `$IMAGE`, or the derived `$MIRROR_PATH` can become command separators, substitutions, or redirections during this second parsing stage. The quotes surrounding the outer Bash expansion do not prevent injection because they only ensure that the constructed text is passed to `sg` as one argument. The shell started by `sg -c` subsequently reparses that text as executable shell syntax. The `docker tag` and `docker rmi` commands attempt to surround values with single quotes, but these quotes are themselves part of the generated command string. An image argument containing a single quote can terminate the quoted section and inject additional shell syntax. ### Attack Path 1. An attacker influences an argument supplied to `scripts/docker.sh`, either as an image name or as an argument to a forwarded Docker command. 2. The attac ...[truncated 1474 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/docker.sh:23
Finding

Unverified Third-Party Mirror Images Are Retagged as Trusted Originals

Content
View full analysis
"docker.m.daocloud.io:library" # official images → library/ ) ``` ```bash for ENTRY in "${MIRRORS[@]}"; do HOST="${ENTRY%%:*}" NS="${ENTRY#*:}" # If image already contains a "/" (user/image format), use image as-is # Otherwise prepend namespace (library) for official images if [[ "$IMAGE" == *"/"* ]]; then MIRROR_PATH="${HOST}/${IMAGE}" else MIRROR_PATH="${HOST}/${NS}/${IMAGE}" fi echo "Trying: docker pull $MIRROR_PATH" if sg docker -c "docker pull $MIRROR_PATH" 2>&1; then # Success — tag back to original image name and clean up echo "Tagging $MIRROR_PATH -> $IMAGE" sg docker -c "docker tag '$MIRROR_PATH' '$IMAGE'" 2>/dev/null echo "Cleaning up" sg docker -c "docker rmi '$MIRROR_PATH'" 2>/dev/null echo "Done!" exit 0 fi done ``` ### Technical Analysis When the original pull fails, the script retrieves an image with the same repository and tag from one of two third-party registries. It does not verify that the mirror-provided manifest digest matches an expected digest from the authoritative registry, nor does it verify a cryptographic signature or trusted provenance attestation. After the pull succeeds, the script retags the mirror image with the originally requested name and removes the mirror-specific tag. This obscures the fact that the local image came from a fallback mirror and makes later use appear equivalent to a successful pull from the original registry. Tags such as `latest`, `alpine`, or version-only tags are mutable references. TLS can protect transport to the selected mirror, but it does not prove that the ...[truncated 1647 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger scope is very broad: it activates not only on pull failures, but on 'any Docker image download scenario' and user requests to pull images. That can cause the skill to intervene in routine Docker operations and silently redirect image sources to third-party mirrors, increasing supply-chain risk and reducing user control over provenance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation states that non-pull commands are passed directly to Docker, but it does not prominently warn that commands like run, stop, or other Docker subcommands can modify containers, images, networks, volumes, and host state. In this context, the skill also relies on group-based Docker access, so unsuspecting users may invoke powerful operations through a wrapper they assume is limited to safe mirror handling.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The script pulls a user-specified Docker image without requiring an immutable tag or digest, so it may fetch whatever 'latest' or a mutable tag points to at execution time. In this skill's context, the risk is amplified because the wrapper automatically retrieves and makes available container images from registries in a network-restricted environment, increasing supply-chain exposure and making accidental execution of an unexpected image more likely.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
84% confidence
Finding

This is the same pull path as the previous finding: the wrapper treats a successful unpinned pull as trustworthy and reports completion, even though the image reference may be mutable. That creates a reproducibility and supply-chain integrity problem, since an attacker controlling or compromising the upstream image could cause different code to be fetched over time.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The mirror fallback pulls from alternate third-party registries using a mutable, user-influenced image reference and then retags the result to the original image name. This is especially dangerous because it silently substitutes content from non-official mirrors, which can break provenance expectations and enable supply-chain compromise if a mirror is malicious, poisoned, or serves a different image than docker.io for the same name.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This successful mirror pull path inherits the same core issue and is more severe in context because the image is immediately normalized via retagging, obscuring that it came from an alternate registry. That can mislead downstream users or automation into trusting the image as if it originated from the canonical source, undermining auditability and increasing the blast radius of a compromised mirror.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The primary manifest description is presented in Chinese, which may impose a language requirement on users without opt-in or explanation. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.