Back to skill

Security audit

BBDuck

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for local image compression, but it asks users to run an unpinned third-party Docker service that may be exposed beyond the local machine.

Review the Docker service before installing. Prefer a pinned image digest, bind the service to 127.0.0.1 only, add resource limits, and avoid uploading sensitive images unless you trust the container publisher and network exposure is controlled.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Execution of an Unpinned Third-Party Container Image

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20-24; duplicated in README.md:8-12
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code:

bash
docker run -d -p 28642:8000 zhaoolee/bbduck:latest

Technical Analysis

The documented installation procedure executes the third-party container image zhaoolee/bbduck:latest. The latest tag is mutable and does not identify a fixed, previously reviewed image. Its contents can change after this Skill has been audited without any corresponding change to the repository.

If the image publisher account, registry, or build pipeline is compromised—or if the publisher replaces the image—the same documented command will download and execute different code. The project provides no immutable digest, signature-verification procedure, software bill of materials, or documented trust policy for this image.

The image executes inside a container, which ordinarily limits its privileges. However, it still processes user-supplied local images, can communicate over the network according to the runtime configuration, and exposes an HTTP service on the host. Host compromise is not established by the reviewed files and would require an additional container-runtime vulnerability or unsafe runtime privileges.

Attack Path

  1. An attacker compromises the image publisher account, image registry, or upstream container build process.
  2. The attacker publishes a modified image under zhaoolee/bbduck:latest.
  3. A user follows the documented docker run command.
  4. Docker resolves the mutable tag and downloads the attacker-controlled image.
  5. Malicious code runs in the container and receives images submitted to the compression API.
  6. The malicious container may disclose uploaded content, return manipulated output, attack network-reachable services, or consume host resources within the limits imposed by Docker.

Impact Assessment

S ...[truncated 636 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the mutable tag with a reviewed immutable digest:

    bash
    docker run -d \
      -p 127.0.0.1:28642:8000 \
      zhaoolee/bbduck@sha256:<verified-image-digest>
    
  2. Record the image version, digest, source repository, and review date in both SKILL.md and README.md.

  3. Verify a cryptographic image signature before execution, such as with Docker Content Trust or Sigstore Cosign, where supported by the publisher.

  4. Review the image Dockerfile and included software, and generate or obtain a software bill of materials.

  5. Configure automated vulnerability scanning for the pinned image, but update the digest only after reviewing and testing the replacement.

  6. Apply runtime hardening, including a read-only filesystem, a non-root user, dropped Linux capabilities, resource limits, and restricted outbound networking where compatible with the service.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Docker Service Published on All Host Network Interfaces

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20-28; duplicated in README.md:8-12
Vulnerability Type: Unintended network exposure of an unauthenticated local service
Risk Level: Medium

Vulnerable Code:

bash
docker run -d -p 28642:8000 zhaoolee/bbduck:latest

The service is subsequently described as local:

text
Default access addresses:
- API root: http://127.0.0.1:28642
- Swagger UI: http://127.0.0.1:28642/docs
- OpenAPI JSON: http://127.0.0.1:28642/openapi.json

Technical Analysis

Docker port publication using -p 28642:8000 normally binds the container port to all host interfaces. Merely documenting the client address as 127.0.0.1 does not restrict the listening socket to loopback.

This creates a mismatch between the claimed local-only deployment model and the actual runtime configuration. The documented API accepts image uploads, performs resource-intensive compression, stores generated outputs, and creates downloadable ZIP archives. No authentication, authorization, request-size restriction, rate limiting, output isolation, or retention policy is described.

Whether the service is reachable from another machine depends on the host firewall, network topology, Docker configuration, and cloud security rules. Nevertheless, the command itself unnecessarily exposes the port beyond loopback and creates an exploitable network surface wherever inbound access is allowed.

Attack Path

  1. A user starts the service with the documented -p 28642:8000 option.
  2. Docker publishes TCP port 28642 on the host's external network interfaces.
  3. A host firewall or network policy permits another device to reach that port.
  4. An attacker discovers the service through scanning, API documentation, or knowledge of the default port.
  5. The attacker invokes the unauthenticated compression or ZIP-download endpoints.
  6. The attacker submits large or numerous images to consume resources ...[truncated 917 chars]
Remediation
View remediation

Remediation Suggestions

  1. Bind the published port explicitly to IPv4 loopback:

    bash
    docker run -d \
      -p 127.0.0.1:28642:8000 \
      zhaoolee/bbduck@sha256:<verified-image-digest>
    
  2. If IPv6 access is supported, ensure the service is not unintentionally published on external IPv6 interfaces.

  3. Verify the resulting listener with host networking tools and test that the service cannot be reached through the host's LAN address.

  4. Document firewall requirements and clearly state that remote exposure is unsupported unless authentication and TLS are configured.

  5. If remote access is necessary, place the API behind an authenticated reverse proxy with TLS, request-size limits, rate limiting, timeouts, and per-user authorization.

  6. Add resource constraints to the container, including CPU, memory, process, and storage limits, to reduce denial-of-service impact.

  7. Configure generated-output isolation, unpredictable identifiers, access checks, and automatic deletion so one caller cannot obtain another caller's files.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README instructs users to start and connect to a local Dockerized service but does not include any warning about trust, image provenance, exposed ports, or the risks of running local containers. In a skill context, this can normalize launching unreviewed code on the user's machine and exposing a service on 28642, increasing supply-chain and local attack-surface risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This README is a markdown file, so trigger quality applies. The example phrase “帮我压一张图,但尽量别看出变化” describes a very natural, everyday request without clear activation boundaries, negative examples, or constraints, which could cause the skill to match generic image-help requests unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file instructs the agent to call the ZIP download endpoint and then save the returned content as a zip file, but it does not include any warning or disclosure to the user that a local file will be created. For markdown files, data-affecting behaviors like file creation should be explicitly signposted so users understand the side effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.