Rp1
Medium
- Category
- MCP Rug Pull
- Confidence
- 75% confidence
- Finding
- Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Security audit
Security checks for vulnerabilities and agentic risk
This is a straightforward Docker command helper; its powerful actions are normal for Docker use and are disclosed as user-directed examples.
Install only if you want the agent to help with Docker commands. Review suggested docker run, volume mount, port exposure, prune, rm, and rmi commands before approving them, especially when using third-party images or commands that delete resources.
No suspicious patterns detected.