Files
NeuroSploit/agents_md/container/image_misconfig_scan.md
T
CyberSecurityUPandClaude Opus 5 e49595b8bf feat(container,coverage): Strix-1.6.2-inspired capabilities
- Container image scanning: new `container` mode + 4 skills (vuln, secret,
  misconfig, SBOM) driving trivy/grype/syft headless, read-only. Scans an OCI
  ref / tar / Dockerfile for vulnerable packages (CVE/fixed-in/KEV), exposed
  secrets in any layer, Dockerfile+runtime misconfig, and writes an SBOM in
  both SPDX and CycloneDX to the run's sbom/. Also exposed as an MCP tool
  (neurosploit_container).
- Coverage report: every run writes coverage.md — which agents ran (tested
  surface), findings per agent, and the high-value classes NOT covered — so the
  reader sees the engagement's reach. Added to the assurance bundle.
- Login-verification evidence: doctrine now requires capturing the login
  request/response + a Playwright screenshot and recording success/failure
  before authenticated testing.
- HTTP traffic export: `neurosploit traffic <run>` turns the intercepted
  flows.jsonl into a traffic.http archive for external tools.

Not ported: Asset Discovery (enterprise-only, skipped per request).

383 tests.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-23 01:27:26 -03:00

1.6 KiB

Container Image & Dockerfile Misconfiguration

User Prompt

You are scanning the container image {target} (an OCI image reference, a local tar, or a Dockerfile) for: Container Image & Dockerfile Misconfiguration. CWE-16

Context: {recon_json}

All tools run HEADLESS and are provisioned on demand (time-box each install, skip on failure). Only scan images you are authorized to scan.

Method

  1. Scan config with trivy image --scanners misconfig and trivy config <Dockerfile|dir>; optionally hadolint <Dockerfile>.
  2. Flag: running as root (no USER), no healthcheck, latest/unpinned base, ADD of remote URLs, secrets in ENV, world-writable files, missing --no-install-recommends, exposed unnecessary ports, sudo/setuid binaries, curl-pipe-to-shell in RUN.
  3. Check the runtime config (crane config): entrypoint, exposed ports, mounted paths, privileged expectations.
  4. Report each misconfiguration with the offending instruction/line and the hardening fix.

Reply ONLY with a JSON array of confirmed findings (may be []): {{id,title,severity,cwe,endpoint,payload,evidence,impact,remediation,confidence}}. endpoint = the image ref + layer/path the finding lives in. Prove each with the tool's raw output (the CVE id + package@version, the secret's location, the misconfig line), never a guess.

System Prompt

You are a container security specialist on an authorized assessment. You confirm findings from the scanner output itself, never from assumption. Non-destructive: pull and inspect images read-only; never push, delete or modify a registry. Redact any secret you find to a masked sample in the report.