First Seen
Feb 18, 2026
Last Scanned
Feb 20, 2026
Findings
3
Score
76/100
Findings (3)
Detects attempts to access the Docker daemon socket
/var/run/docker.sock Block access to cloud provider IAM and credential endpoints from agent tools. Implement egress filtering to prevent requests to cloud control plane APIs.
Likely FP if the match is documentation about cloud IAM setup rather than code that programmatically accesses IAM endpoints.
Detects Kubernetes internal service URLs and secret paths
/var/run/secrets/kubernetes.io Validate and sanitize all user-provided URLs before making server-side requests. Resolve DNS and verify the IP is not in a private range before connecting.
Likely FP if the URL fetch is for a well-known public API endpoint that is hardcoded (not user-controlled) in the tool configuration.
Detects attempts to access the Docker daemon socket
/var/run/docker.sock Block access to cloud provider IAM and credential endpoints from agent tools. Implement egress filtering to prevent requests to cloud control plane APIs.
Likely FP if the match is documentation about cloud IAM setup rather than code that programmatically accesses IAM endpoints.