T09 · Insecure Skill Coding Practices
- Location
scripts/docker-health.sh:159- Finding
Image Freshness Check Performs Undisclosed Mutating Docker Pulls
- Content
View full analysis
/dev/null; then local new_digest new_digest=$(docker inspect --format '{{index .RepoDigests 0}}' "$image" 2>/dev/null || true) if [[ -n "$local_digest" && -n "$new_digest" && "$local_digest" != "$new_digest" ]]; then echo -e " ${YELLOW}→ Update available${NC} (digest changed)" outdated=1 elif [[ -z "$local_digest" ]]; then echo -e " ${GREEN}✓ Up to date${NC} (no prior digest to compare)" else echo -e " ${GREEN}✓ Up to date${NC}" fi else echo -e " ${RED}✗ Pull failed${NC} (check registry access or image name)" fi ``` The related documentation in `SKILL.md:57-58` presents the image check as advisory: ```markdown - `--images` checks are advisory — uses `docker inspect` for image digests and checks for newer versions; requires network access to the registry ``` ### Technical Analysis The script claims that `docker pull` only retrieves a manifest and does not pull layers. That claim is incorrect. A successful `docker pull` may: - Download image configuration and filesystem layers. - Update the local tag or image reference. - Consume network bandwidth and Docker storage. - Contact registries derived from existing container image references. - Use credentials configured for the Docker client or credential helper. - Store attacker-controlled image content in the local Docker image cache. The operation is reached through both `--images` and the default `--all` execution path. Consequently, a command presented as a monitoring or advisory audit performs state-changing network and Docker operations without explicit confirmation. The script does not exe ...[truncated 1979 chars]- Remediation
View remediation
