Exposed container registry
SkillCloud & infraFind and loot exposed container registries, image pull/push, secrets baked in layers, and registry misconfig. Load on exposed Docker registry (port 5000, /v2/), a registry URL, harbor/ECR/ GCR/ACR references, or "container registry". Signals: /v2/_catalog, registry:2, unauth pull/push.
Use Exposed container registry in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add Exposed container registry and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the Exposed container registry skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/cloud/cloud-docker-registry/SKILL.md and read by Ahel’s review.
When it applies
A Docker/OCI registry is reachable — a self-hosted registry (:5000, /v2/), or a cloud one
(ECR/GCR/ACR/Harbor) with weak auth. Images are goldmines: source, configs, and baked-in secrets.
Why it works
Registries are often deployed without auth ("internal only") or with over-broad pull access. Image
layers preserve everything added at build time — .env files, cloud keys, private source,
tokens — even if a later layer deletes them, earlier layers keep them.
Method
- Detect & enumerate:
curl -s https://registry:5000/v2/_catalog(repo list) and.../v2/<repo>/tags/list.registry:2banner / an unauth/v2/= exposed. - Pull images:
docker pull registry:5000/<repo>:<tag>orcrane pull(no docker daemon). Anonymous pull of private images is the finding. - Mine layers for secrets:
crane export/docker savethen scan withtrufflehog filesystem/ grep for keys,.env, kubeconfig, cloud creds (→ validate withcode-review-secrets-detection). - Push (critical): if anonymous/weak push works, you can poison images (supply-chain) — prove with a harmless tag, don't tamper real images.
- Cloud registries: test misconfigured ECR/GCR/ACR policies; leaked registry creds → pull private images.
Gotchas
- Scan all layers/history, not just the final image — secrets hide in intermediate layers.
- Anonymous push is critical (supply-chain); anonymous pull of private images is high — rate accordingly.
- Only pull what proves the issue; images can be large and contain real data — handle carefully.
Verify success
Anonymous/unauthorized pull of a private image, a live secret extracted from its layers, or a successful (harmless) push proving write access.
References
Docker registry API docs; crane/trufflehog; "hacking Docker registries" write-ups.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Ahel review
S4info
community integration, published by noorqureshi, not docker
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Item type
- skill
- Key
cloud-docker-registry- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · nvidia
The pick for Infrahttp-to-https
Skill · thedaviddias
The pick for Infrasecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secretssupply-chain-risk-auditor
Skill · trailofbits
The pick for Supply Chainsupply-chain-digital-twin
Skill · a5c-ai
The pick for Supply Chain