Tp2
- Category
- MCP Tool Poisoning
- Confidence
- 85% confidence
- Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This Docker admin skill is coherent, but it can stop, delete, prune, and execute inside containers without built-in confirmation.
Install only where the agent is allowed to administer Docker on your behalf. Confirm exact container, image, and volume targets before using stop, rm, rmi, prune, or exec, and avoid using it against production Docker hosts unless you have backups and a clear rollback plan.
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
The declared description understates the skill's effective capabilities relative to the documented behavior, especially around image deletion, pruning, and potentially entering containers. This mismatch can mislead users or policy systems into approving a skill that can perform more destructive or invasive actions than expected.
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
Referenced artifact was not completely inspected
python3 scripts/docker_mgr.py ps
The skill advertises shell-capable behavior through documented commands but declares no explicit tool scope or permissions boundary. In an agent environment, this can cause the skill to run with broader execution authority than users or orchestrators expect, increasing the risk of unintended destructive Docker operations.
Broad trigger phrases such as 'Docker' and generic container-management terms may activate the skill during ordinary discussion rather than an intentional admin request. In a skill capable of starting, stopping, or deleting containers/images, accidental invocation raises the chance of unauthorized or unintended operational changes.
The skill prominently includes destructive operations like removing containers and images but does not warn users about data loss, service disruption, or irreversibility. In an ops context, missing warnings materially increase the likelihood of accidental destructive use against production workloads.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""执行docker命令"""
if isinstance(cmd, str):
cmd = cmd.split()
result = subprocess.run(cmd, capture_output=capture, text=True)
if result.returncode != 0:
print(f"❌ 执行失败: {result.stderr.strip()}")
return None
No suspicious patterns detected.