Back to skill

Security audit

Docker容器管理工具

Security checks across malware telemetry and agentic risk

Overview

This Docker skill is not malicious, but it asks for powerful command and write access while its scope and safety controls are too broad for automatic approval.

Review before installing. Use this only for Docker-specific work, and require explicit confirmation before actions such as deleting containers, pruning images or volumes, changing Compose files, exposing ports, modifying networks, or overwriting configuration files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a Docker management tool, but it also advertises unrelated capabilities such as static analysis, vulnerability detection, report generation, and CI/CD integration without clear evidence or scope boundaries. This kind of capability inflation can mislead users and agents into delegating broader security-sensitive tasks to a skill that also has exec/write access, increasing the chance of unsafe or unintended operations.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The primary-functions section broadens the skill from Docker management into generic file processing, API integration, and command execution. In a skill with read/exec/write tools, this ambiguity is dangerous because it obscures the real trust boundary and may cause an agent or user to authorize powerful actions beyond the expected Docker-focused use case.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The invocation guidance is overly broad, covering general code generation, programming help, debugging, testing, and deployment scenarios. This can cause the skill to be selected for many loosely related requests, exposing users to unnecessary exec/write actions in contexts where a narrower, less-privileged skill would be safer.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises file handling and system command execution but does not provide a prominent warning that these actions can modify the filesystem, affect running services, or execute impactful host-level operations. In the context of a Docker/operations skill with exec and write permissions, lack of upfront warning materially increases the risk of accidental destructive or security-relevant actions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.