Back to skill

Security audit

Docker Health Monitor

Security checks for vulnerabilities and agentic risk

Overview

This Docker health skill mostly matches its purpose, but its default health report can unexpectedly pull images from registries and change local Docker state.

Install only if you are comfortable granting the skill Docker daemon access. Avoid running the default `--all` or `--images` checks on sensitive hosts unless you accept outbound registry traffic, possible registry credential use, bandwidth/storage consumption, and local Docker image cache changes. Prefer `--status`, `--resources`, or `--restarts` for passive checks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/docker-health.sh:159
Finding

Image Freshness Check Performs Undisclosed Mutating Docker Pulls

Content
View full analysis
/dev/null; then local new_digest new_digest=$(docker inspect --format '{{index .RepoDigests 0}}' "$image" 2>/dev/null || true) if [[ -n "$local_digest" && -n "$new_digest" && "$local_digest" != "$new_digest" ]]; then echo -e " ${YELLOW}→ Update available${NC} (digest changed)" outdated=1 elif [[ -z "$local_digest" ]]; then echo -e " ${GREEN}✓ Up to date${NC} (no prior digest to compare)" else echo -e " ${GREEN}✓ Up to date${NC}" fi else echo -e " ${RED}✗ Pull failed${NC} (check registry access or image name)" fi ``` The related documentation in `SKILL.md:57-58` presents the image check as advisory: ```markdown - `--images` checks are advisory — uses `docker inspect` for image digests and checks for newer versions; requires network access to the registry ``` ### Technical Analysis The script claims that `docker pull` only retrieves a manifest and does not pull layers. That claim is incorrect. A successful `docker pull` may: - Download image configuration and filesystem layers. - Update the local tag or image reference. - Consume network bandwidth and Docker storage. - Contact registries derived from existing container image references. - Use credentials configured for the Docker client or credential helper. - Store attacker-controlled image content in the local Docker image cache. The operation is reached through both `--images` and the default `--all` execution path. Consequently, a command presented as a monitoring or advisory audit performs state-changing network and Docker operations without explicit confirmation. The script does not exe ...[truncated 1979 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Docker Socket Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Access to /var/run/docker.sock is effectively equivalent to root on the host because it allows control over containers, mounts, images, and potentially the host filesystem. In the context of an agent skill, broad or automatic invocation combined with Docker socket access makes accidental misuse or abuse especially dangerous.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
## Notes

- Requires access to the Docker socket (`/var/run/docker.sock`) — run as root or add user to the `docker` group
- `--resources` runs `docker stats` in non-streaming mode (one-shot per container) for quick snapshots
- `--images` checks are advisory — uses `docker inspect` for image digests and checks for newer versions; requires network access to the registry
- Works with both local Docker and remote Docker contexts (DOCKER_HOST env var)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The invocation description is broad enough to trigger on many routine Docker-related requests without clearly limiting scope to read-only health checks. In an agent environment, this can cause the skill to be selected in contexts where it gains Docker socket access and performs actions or disclosures the user did not explicitly intend.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
92% confidence
Finding

Telling operators to run the skill as root normalizes elevated execution for a task that may be invoked frequently and automatically. If the script or surrounding agent behavior is flawed, root execution greatly increases the blast radius, including host-level file access and unrestricted Docker control.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
## Notes

- Requires access to the Docker socket (`/var/run/docker.sock`) — run as root or add user to the `docker` group
- `--resources` runs `docker stats` in non-streaming mode (one-shot per container) for quick snapshots
- `--images` checks are advisory — uses `docker inspect` for image digests and checks for newer versions; requires network access to the registry
- Works with both local Docker and remote Docker contexts (DOCKER_HOST env var)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The image freshness check performs docker pull as part of a monitoring workflow, which mutates local system state and contacts external registries. In a skill advertised as a health monitor, this exceeds read-only expectations and can unexpectedly change cached images, consume bandwidth, trigger credentialed registry access, or prepare newer images for later deployment without explicit user consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment says the code will 'just get the manifest, don't pull layers,' but the implementation calls docker pull, which can update local image metadata and download content. This misleading documentation increases operational risk because reviewers or users may treat the script as passive monitoring when it actually changes host state and performs network actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script performs networked image pulls during a health check without clearly warning users in the CLI help or high-level description. In the context of an agent skill, this is more dangerous because users may invoke a seemingly observational health report and unintentionally trigger outbound network access, registry authentication, bandwidth consumption, and local image mutation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The documentation states that image update checks may contact external registries, but it does not clearly warn users at invocation time that running this check can initiate network traffic and potentially disclose which images are in use. In sensitive environments, even advisory registry lookups can create privacy, policy, or egress-compliance issues.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.