Back to skill

Security audit

Wordpress Vps Install

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent WordPress VPS deployment guide, but it needs review because it handles live credentials and makes privileged persistent server changes with weak guardrails.

Install only if you are comfortable letting the agent perform privileged changes on a VPS. Before use, require explicit confirmation of the target server and domain, avoid printing secrets, replace command-line passwords with a protected env file or secret manager, pin and verify WP-CLI and Docker images, and remove curl -k from final deployment verification.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:143
Finding

Live WordPress and MySQL credentials are exposed in terminal output

Content
View full analysis
| grep -E 'WORDPRESS_|MYSQL_' ``` ### Technical Analysis The command prints every container environment variable whose name contains `WORDPRESS_` or `MYSQL_`. The documented environment includes sensitive values such as `WORDPRESS_DB_PASSWORD`, `WORDPRESS_ADMIN_PASSWORD`, and potentially MySQL root credentials. Although the command is intended to verify deployment configuration, it exposes complete secret values in terminal output rather than checking only the required variable names or securely capturing selected values. The output can be retained in shell logs, agent transcripts, CI/CD logs, terminal recordings, or centralized observability systems. ### Attack Path 1. An administrator or agent follows the skill and runs the documented inspection command. 2. Docker returns the container's complete WordPress and MySQL environment variables. 3. The command prints database or administrator passwords to the terminal. 4. The output is retained in an agent transcript, deployment log, shell recording, or monitoring platform. 5. An attacker with access to that retained output extracts the credentials. 6. The attacker authenticates to WordPress, MySQL, or another service that reuses the exposed credentials. ### Impact Assessment Successful exploitation may disclose WordPress administrator and database credentials. Depending on network exposure and account privileges, an attacker could: - Take control of the WordPress administrator account. - Read, modify, or delete WordPress database content. - Create malicious users or publish malicious content. - Extract personal or operational data stored by WordPress. - Use database access as a foothold for further compromise. The practical ...[truncated 147 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:172
Finding

Database and administrator passwords are embedded in Docker command arguments

Content
View full analysis
\ --volumes-from \ --entrypoint sh \ -e WORDPRESS_DB_HOST= \ -e WORDPRESS_DB_NAME= \ -e WORDPRESS_DB_USER= \ -e WORDPRESS_DB_PASSWORD= \ -e WORDPRESS_URL=https://example.com \ -e WORDPRESS_TITLE="Site Name" \ -e WORDPRESS_ADMIN_USER=admin \ -e WORDPRESS_ADMIN_PASSWORD='change-me' \ -e WORDPRESS_ADMIN_EMAIL=admin@example.com \ ``` ### Technical Analysis The workflow instructs the operator to replace placeholders with live database and WordPress administrator credentials directly in a `docker run` command. This creates multiple possible disclosure channels: - Interactive shell history. - Agent or terminal transcripts. - Process and command auditing telemetry. - Debug output or shell tracing. - Docker container configuration and inspection data. - Copy-and-pasted deployment records. The example also uses the predictable administrator password `change-me`. If an operator runs the command without replacing it, the public WordPress installation may be created with a trivially guessable credential. ### Attack Path 1. The operator replaces `` and `'change-me'` with actual credentials, or leaves the predictable example password unchanged. 2. The complete command is entered through a shell or executed by an agent. 3. The command and its plaintext arguments are retained in shell history, transcripts, audit telemetry, or Docker metadata. 4. An attacker obtains access to one of those records. 5. The attacker extracts the database or WordPress administrator password. 6. The attacker authenticates to the corresponding service and performs actions allowed by that account. Alternatively, if `change-me ...[truncated 624 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:209
Finding

Mutable remote executable is downloaded and run without integrity verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:282
Finding

Public deployment verification disables TLS certificate validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
# 0.2 mandatory backup (compose + env) with timestamp
TS="$(date +%Y%m%d-%H%M%S)"
cp /etc/dokploy/compose/<project>/code/docker-compose.yml /etc/dokploy/compose/<project>/code/docker-compose.yml.bak.$TS
cp /etc/dokploy/compose/<project>/code/.env /etc/dokploy/compose/<project>/code/.env.bak.$TS

# 0.3 validate with explicit project name and env file
cd /etc/dokploy/compose/<project>/code

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
# 0.2 mandatory backup (compose + env) with timestamp
TS="$(date +%Y%m%d-%H%M%S)"
cp /etc/dokploy/compose/<project>/code/docker-compose.yml /etc/dokploy/compose/<project>/code/docker-compose.yml.bak.$TS
cp /etc/dokploy/compose/<project>/code/.env /etc/dokploy/compose/<project>/code/.env.bak.$TS

# 0.3 validate with explicit project name and env file
cd /etc/dokploy/compose/<project>/code

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
# 0.2 mandatory backup (compose + env) with timestamp
TS="$(date +%Y%m%d-%H%M%S)"
cp /etc/dokploy/compose/<project>/code/docker-compose.yml /etc/dokploy/compose/<project>/code/docker-compose.yml.bak.$TS
cp /etc/dokploy/compose/<project>/code/.env /etc/dokploy/compose/<project>/code/.env.bak.$TS

# 0.3 validate with explicit project name and env file
cd /etc/dokploy/compose/<project>/code

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
# 0.2 mandatory backup (compose + env) with timestamp
TS="$(date +%Y%m%d-%H%M%S)"
cp /etc/dokploy/compose/<project>/code/docker-compose.yml /etc/dokploy/compose/<project>/code/docker-compose.yml.bak.$TS
cp /etc/dokploy/compose/<project>/code/.env /etc/dokploy/compose/<project>/code/.env.bak.$TS

# 0.3 validate with explicit project name and env file
cd /etc/dokploy/compose/<project>/code

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
-e WORDPRESS_ADMIN_PASSWORD='change-me' \
  -e WORDPRESS_ADMIN_EMAIL=admin@example.com \
  wordpress:cli-php8.2 -lc '
    if ! wp core is-installed --path=/var/www/html --allow-root; then
      wp core install --path=/var/www/html --allow-root \
        --url="$WORDPRESS_URL" \
        --title="$WORDPRESS_TITLE" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
-e WORDPRESS_ADMIN_PASSWORD='change-me' \
  -e WORDPRESS_ADMIN_EMAIL=admin@example.com \
  wordpress:cli-php8.2 -lc '
    if ! wp core is-installed --path=/var/www/html --allow-root; then
      wp core install --path=/var/www/html --allow-root \
        --url="$WORDPRESS_URL" \
        --title="$WORDPRESS_TITLE" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
-e WORDPRESS_ADMIN_PASSWORD='change-me' \
  -e WORDPRESS_ADMIN_EMAIL=admin@example.com \
  wordpress:cli-php8.2 -lc '
    if ! wp core is-installed --path=/var/www/html --allow-root; then
      wp core install --path=/var/www/html --allow-root \
        --url="$WORDPRESS_URL" \
        --title="$WORDPRESS_TITLE" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

md
-e WORDPRESS_ADMIN_PASSWORD='change-me' \
  -e WORDPRESS_ADMIN_EMAIL=admin@example.com \
  wordpress:cli-php8.2 -lc '
    if ! wp core is-installed --path=/var/www/html --allow-root; then
      wp core install --path=/var/www/html --allow-root \
        --url="$WORDPRESS_URL" \
        --title="$WORDPRESS_TITLE" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 276)May include surrounding context.

md
-e WORDPRESS_ADMIN_PASSWORD='change-me' \
  -e WORDPRESS_ADMIN_EMAIL=admin@example.com \
  wordpress:cli-php8.2 -lc '
    if ! wp core is-installed --path=/var/www/html --allow-root; then
      wp core install --path=/var/www/html --allow-root \
        --url="$WORDPRESS_URL" \
        --title="$WORDPRESS_TITLE" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
78% confidence
Finding

The skill instructs downloading an executable PHAR directly from GitHub and placing it in /usr/local/bin without any checksum or signature verification. In a VPS-administration skill, this is more dangerous because it normalizes executing a network-fetched binary as root on a production host, creating a supply-chain compromise path if the download source, transport, or upstream artifact is tampered with.

Content

Scanner excerpt · SKILL.md (reported line 208)May include surrounding context.

bash
apt-get update -y
apt-get install -y ripgrep curl less php-cli php-curl php-mbstring php-xml
curl -fsSL https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar -o /usr/local/bin/wp
chmod +x /usr/local/bin/wp
wp --info

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly frames the skill as operating on a live VPS and public WordPress site, including installation against live files and post-deployment verification, but provides no warning that these actions can modify or disrupt a production environment. In an agentic setting, missing safety guardrails increases the chance of unintended destructive changes, downtime, or installation against the wrong host when the skill is invoked with insufficient user confirmation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This section instructs the operator to run apt-get install and download a binary into /usr/local/bin, which changes the host system state. While the skill broadly describes VPS provisioning, this specific host-level modification is presented without a clear warning about altering the server outside the container stack.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.