Exposed container registry

SkillCloud & infra

Find and loot exposed container registries, image pull/push, secrets baked in layers, and registry misconfig. Load on exposed Docker registry (port 5000, /v2/), a registry URL, harbor/ECR/ GCR/ACR references, or "container registry". Signals: /v2/_catalog, registry:2, unauth pull/push.

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the Exposed container registry skill

What this skill tells your AI

The instructions your AI receives, as published by noorqureshi/sploitagent in skills/cloud/cloud-docker-registry/SKILL.md and read by ahel’s review.

When it applies

A Docker/OCI registry is reachable — a self-hosted registry (:5000, /v2/), or a cloud one (ECR/GCR/ACR/Harbor) with weak auth. Images are goldmines: source, configs, and baked-in secrets.

Why it works

Registries are often deployed without auth ("internal only") or with over-broad pull access. Image layers preserve everything added at build time — .env files, cloud keys, private source, tokens — even if a later layer deletes them, earlier layers keep them.

Method

  1. Detect & enumerate: curl -s https://registry:5000/v2/_catalog (repo list) and .../v2/<repo>/tags/list. registry:2 banner / an unauth /v2/ = exposed.
  2. Pull images: docker pull registry:5000/<repo>:<tag> or crane pull (no docker daemon). Anonymous pull of private images is the finding.
  3. Mine layers for secrets: crane export/docker save then scan with trufflehog filesystem / grep for keys, .env, kubeconfig, cloud creds (→ validate with code-review-secrets-detection).
  4. Push (critical): if anonymous/weak push works, you can poison images (supply-chain) — prove with a harmless tag, don't tamper real images.
  5. Cloud registries: test misconfigured ECR/GCR/ACR policies; leaked registry creds → pull private images.

Gotchas

  • Scan all layers/history, not just the final image — secrets hide in intermediate layers.
  • Anonymous push is critical (supply-chain); anonymous pull of private images is high — rate accordingly.
  • Only pull what proves the issue; images can be large and contain real data — handle carefully.

Verify success

Anonymous/unauthorized pull of a private image, a live secret extracted from its layers, or a successful (harmless) push proving write access.

References

Docker registry API docs; crane/trufflehog; "hacking Docker registries" write-ups.

Signals

GitHub stars
20
Forks
7
Last commit
Sep 2026

ahel review

  • S4info
    community integration, published by noorqureshi, not docker

Automated review, not a security audit. Ruleset v1+k2.

Advanced
Item type
skill
Key
cloud-docker-registry
Source
github.com/noorqureshi/sploitagent