Skip to content

RP1 reads the first docker option as the image, and registry ports or option values as tags #781

Description

@ilaigold

I ran SkillSpector with --no-llm over 45 skills (OpenShell's own plus a batch of Anthropic's official plugin skills) and went through the findings by hand. On OpenShell's debug-openshell-cluster skill, both RP1 findings say the unpinned image is docker run --rm.

The cause is _RP1_DOCKER_CMD = r"docker\s+(?:pull|run|create)\s+\S+" in mcp_rug_pull.py. It takes the first word after the subcommand as the image and runs _VERSION_PIN_RE over it. So the first option gets reported as the image, and when that word is an option value or a registry with a port, its colon counts as a tag.

Repro on main @ 5485cda with skillspector scan <dir> --no-llm --format json, using these lines in a bash block in SKILL.md:

Line RP1 on main Expected
docker run --rm alpine:3.20 cat /etc/alpine-release unpinned image docker run --rm nothing (tagged)
docker run -d img@sha256:<64 hex> unpinned image docker run -d nothing (digest)
docker run --user 1000:1000 evil/image docker run --user a finding that names evil/image
docker pull localhost:5000/team/tool nothing a finding (:5000 is the registry port)
docker run --publish=8080:80 evil/image nothing a finding (:80 belongs to the option)

The last two are missed detections, not just noise.

In the OpenShell skill (skills/debug-openshell-cluster/SKILL.md @ 360c5a0, lines 258 and 309) the findings happen to be right, since one image defaults to :latest and the other is a placeholder. But the report says docker run --rm and never shows the actual image.

This is the Docker half of #672. #683 fixed the unrelated-pin part and left Docker out on purpose, because it needs to know which docker run options take a value. The #683 review asked for Refs #672 so the Docker case would stay tracked, but #672 closed when #683 merged, so right now nothing tracks it. Not covered here: prose like docker run to start ..., and whether :latest should count as pinned (#644 B3).

Heads-up: test_privileged_payload_in_referenced_reference_file_stays_install_unsafe (from #682) only reaches DO_NOT_INSTALL because of this bug. RP1 reports its docker run --privileged --pid=host vendor/collector:1.4 line as an unpinned image (docker run --privileged). Without that finding, PE5 and TM4 alone score 48.

I have a fix that skips options using docker/cli's own option table and still reports the command when it can't pick out the image. I'll open a PR and link it here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions