Back to skill

Security audit

Stalwart Dokploy Resend Relay

Security checks for vulnerabilities and agentic risk

Overview

This is a plausible mail-server setup guide, but it needs review because it gives under-scoped production deployment instructions that could expose the admin service or spread a relay API key.

Review before installing. Pin the Stalwart image to a specific reviewed version or digest, make sure port 8080 is reachable only by the reverse proxy or localhost and not the public internet, keep the Resend API key server-side in Stalwart rather than in mail clients, and run the sudo commands only on the intended VPS after confirming paths and domains.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:135
Finding

Mutable Container Image Tag Allows Unreviewed Dependency Replacement

Content
View full analysis
Remediation
View remediation
@sha256: ``` - Verify the digest against the publisher's trusted release information before deployment. - Where supported, verify container signatures and provenance using a mechanism such as Sigstore Cosign. - Establish an explicit upgrade process that reviews release notes, retrieves the new digest, tests the image, and updates the Skill only after approval. - Configure deployment tooling so routine redeployments do not silently pull an unreviewed image. - Run the container as a non-root user with minimal Linux capabilities, read-only filesystems where feasible, and only the required volume mounts to limit the impact of a compromised dependency. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:135
Finding

Web Administration Service May Be Published Directly on Port 8080

Content
View full analysis
` - Path: `/` - Internal Path: `/` - HTTPS: enabled - Redeploy after domain change Admin UI URL: - `https://mail./admin/` ``` ### Technical Analysis The Skill groups port `8080` with ports that must be exposed or routed, without distinguishing between a public host-port publication and private container-network access. Port 8080 is subsequently identified as the backend web service that hosts the administration interface. If an operator interprets the instruction as requiring public publication of every listed port, the Stalwart web service may become directly reachable through the VPS address on port 8080. Such access can bypass the Dokploy HTTPS reverse proxy and any security controls enforced at that layer, including TLS, hostname restrictions, access-control middleware, rate limiting, and security headers. ### Attack Path 1. An operator follows the instruction to expose or route all listed ports. 2. Dokploy or Docker publishes container port 8080 on a public host interface. 3. An attacker scans the VPS and discovers the directly reachable service on port 8080. 4. The attacker connects to the administration service directly instead of using `https://mail./admin/`. 5. If the backend accepts plaintext HTTP, an on-path attacker can observe or modify administrative traffic. A remote attacker can also target the backend without reverse-proxy prot ...[truncated 1032 chars]
Remediation
View remediation
:8080 ``` - Publish only the ports required for public mail protocols and HTTPS. Clearly distinguish: - Public mail ports - Public HTTPS entry points - Internal reverse-proxy backend ports - Add a firewall rule denying external access to TCP port 8080. - Verify after deployment that the service is not publicly reachable: ```bash nc -zv 8080 ``` The external connection should fail. - Require HTTPS for all administrative access and consider adding IP allowlisting, multifactor authentication, and reverse-proxy rate limiting. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:257
Finding

Resend API Key Is Prescribed as an End-User Mail Client Password

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

If bootstrap keeps resetting after restart, fix volume ownership:

bash
sudo chown -R 2000:2000 /var/lib/docker/volumes/<stalwart-volume>/_data

Stalwart Bootstrap

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

If bootstrap keeps resetting after restart, fix volume ownership:

bash
sudo chown -R 2000:2000 /var/lib/docker/volumes/<stalwart-volume>/_data

Stalwart Bootstrap

Static analysis

No suspicious patterns detected.