I ran SkillSpector with --no-llm over 45 skills (OpenShell's own plus a batch of Anthropic's official plugin skills) and went through the findings by hand. On OpenShell's debug-openshell-cluster skill, both RP1 findings say the unpinned image is docker run --rm.
The cause is _RP1_DOCKER_CMD = r"docker\s+(?:pull|run|create)\s+\S+" in mcp_rug_pull.py. It takes the first word after the subcommand as the image and runs _VERSION_PIN_RE over it. So the first option gets reported as the image, and when that word is an option value or a registry with a port, its colon counts as a tag.
Repro on main @ 5485cda with skillspector scan <dir> --no-llm --format json, using these lines in a bash block in SKILL.md:
| Line |
RP1 on main |
Expected |
docker run --rm alpine:3.20 cat /etc/alpine-release |
unpinned image docker run --rm |
nothing (tagged) |
docker run -d img@sha256:<64 hex> |
unpinned image docker run -d |
nothing (digest) |
docker run --user 1000:1000 evil/image |
docker run --user |
a finding that names evil/image |
docker pull localhost:5000/team/tool |
nothing |
a finding (:5000 is the registry port) |
docker run --publish=8080:80 evil/image |
nothing |
a finding (:80 belongs to the option) |
The last two are missed detections, not just noise.
In the OpenShell skill (skills/debug-openshell-cluster/SKILL.md @ 360c5a0, lines 258 and 309) the findings happen to be right, since one image defaults to :latest and the other is a placeholder. But the report says docker run --rm and never shows the actual image.
This is the Docker half of #672. #683 fixed the unrelated-pin part and left Docker out on purpose, because it needs to know which docker run options take a value. The #683 review asked for Refs #672 so the Docker case would stay tracked, but #672 closed when #683 merged, so right now nothing tracks it. Not covered here: prose like docker run to start ..., and whether :latest should count as pinned (#644 B3).
Heads-up: test_privileged_payload_in_referenced_reference_file_stays_install_unsafe (from #682) only reaches DO_NOT_INSTALL because of this bug. RP1 reports its docker run --privileged --pid=host vendor/collector:1.4 line as an unpinned image (docker run --privileged). Without that finding, PE5 and TM4 alone score 48.
I have a fix that skips options using docker/cli's own option table and still reports the command when it can't pick out the image. I'll open a PR and link it here.
I ran SkillSpector with
--no-llmover 45 skills (OpenShell's own plus a batch of Anthropic's official plugin skills) and went through the findings by hand. On OpenShell'sdebug-openshell-clusterskill, both RP1 findings say the unpinned image isdocker run --rm.The cause is
_RP1_DOCKER_CMD = r"docker\s+(?:pull|run|create)\s+\S+"inmcp_rug_pull.py. It takes the first word after the subcommand as the image and runs_VERSION_PIN_REover it. So the first option gets reported as the image, and when that word is an option value or a registry with a port, its colon counts as a tag.Repro on
main@ 5485cda withskillspector scan <dir> --no-llm --format json, using these lines in abashblock inSKILL.md:maindocker run --rm alpine:3.20 cat /etc/alpine-releasedocker run --rmdocker run -d img@sha256:<64 hex>docker run -ddocker run --user 1000:1000 evil/imagedocker run --userevil/imagedocker pull localhost:5000/team/tool:5000is the registry port)docker run --publish=8080:80 evil/image:80belongs to the option)The last two are missed detections, not just noise.
In the OpenShell skill (
skills/debug-openshell-cluster/SKILL.md@ 360c5a0, lines 258 and 309) the findings happen to be right, since one image defaults to:latestand the other is a placeholder. But the report saysdocker run --rmand never shows the actual image.This is the Docker half of #672. #683 fixed the unrelated-pin part and left Docker out on purpose, because it needs to know which
docker runoptions take a value. The #683 review asked forRefs #672so the Docker case would stay tracked, but #672 closed when #683 merged, so right now nothing tracks it. Not covered here: prose likedocker run to start ..., and whether:latestshould count as pinned (#644 B3).Heads-up:
test_privileged_payload_in_referenced_reference_file_stays_install_unsafe(from #682) only reaches DO_NOT_INSTALL because of this bug. RP1 reports itsdocker run --privileged --pid=host vendor/collector:1.4line as an unpinned image (docker run --privileged). Without that finding, PE5 and TM4 alone score 48.I have a fix that skips options using docker/cli's own option table and still reports the command when it can't pick out the image. I'll open a PR and link it here.