Back to skill

Security audit

Dokploy

Security checks for vulnerabilities and agentic risk

Overview

This Dokploy skill is mostly purpose-aligned, but it handles deployment credentials and environment secrets unsafely enough that users should review it carefully before installing.

Install only if you are comfortable giving the skill a Dokploy API key with the ability to read and modify deployment resources. Avoid running dokploy-config show with a real key, avoid storing the key through dokploy-config set until the config file handling is fixed, use a narrowly scoped API key where possible, and treat dokploy-app env list output as secret material that may be captured in logs or agent transcripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/dokploy-config.sh:41
Finding

API Key Disclosed by Configuration Display Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/dokploy-config.sh:16
Finding

Command Injection Through Sourceable Configuration File and Insecure Plaintext Credential Storage

Content
View full analysis
"$CONFIG_FILE" << EOF export DOKPLOY_API_URL="${DOKPLOY_API_URL}" export DOKPLOY_API_KEY="${DOKPLOY_API_KEY}" EOF log_success "Config saved to $CONFIG_FILE" log_info "Run: source $CONFIG_FILE to load" ``` ### Technical Analysis Values supplied through `--url` and `--key` are embedded without shell escaping into `$HOME/.dokployrc`. The generated file is executable shell syntax, and the user is explicitly instructed to load it using `source`. An attacker-controlled value can contain a closing quotation mark, command substitution, shell metacharacters, or a newline. Although such contents are initially held as variable data, they are written into the generated shell file. When that file is later sourced, the shell parses the injected content as executable syntax. For example, a malicious URL value can produce configuration content conceptually equivalent to: ```bash export DOKPLOY_API_URL=""; attacker_command; echo "" ``` The file also stores the API key in plaintext and does not explicitly establish restrictive permissions. A newly created file inherits permissions determined by the process umask. Under a permissive umask, other local users may be able to read the credential. If the file already exists with overly broad permissions, redirection does not correct those permissions. ### Attack Path #### Shell Injection Path 1. An attacker influences a command, script, copied s ...[truncated 1629 chars]
Remediation
View remediation
"$tmp_file" || { rm -f "$tmp_file" exit 1 } mv "$tmp_file" "$CONFIG_FILE" chmod 600 "$CONFIG_FILE" ``` Load the values as data rather than sourcing the file: ```bash DOKPLOY_API_URL=$(jq -r '.api_url' "$CONFIG_FILE") DOKPLOY_API_KEY=$(jq -r '.api_key' "$CONFIG_FILE") export DOKPLOY_API_URL DOKPLOY_API_KEY ``` If shell-format configuration must be retained: 1. Escape every value with `printf '%q'` before writing it. 2. Set `umask 077` before file creation. 3. Explicitly apply mode `0600` after creation and after every update. 4. Write through a securely created temporary file and atomically rename it. 5. Reject newline characters and unexpected control characters. 6. Validate the URL scheme and permit only expected schemes such as `https`, with an explicit exception for local development. 7. Avoid instructing users to source files constructed from externally supplied values. 8. Prefer an operating-system credential store or secret manager for long-lived API keys. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose is remote Dokploy resource management, but the documented behavior also includes storing and displaying local API configuration, including credentials. This mismatch matters because users or orchestration systems may trust the skill for remote deployment tasks without realizing it also persists secrets locally, creating unexpected exposure of sensitive tokens.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/dokploy-app.sh (reported line 134)May include surrounding context.

sh
if [ -n "$env" ]; then
            local formattedEnv=$(echo "$env" | tr ';' '\n')
            updateData=$(echo "$updateData" | jq --arg env "$formattedEnv" '.env = $env')
        fi

        log_info "Configuring application..."

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/dokploy-app.sh (reported line 319)May include surrounding context.

sh
if [ -n "$env" ]; then
            local formattedEnv=$(echo "$env" | tr ';' '\n')
            updateData=$(echo "$updateData" | jq --arg env "$formattedEnv" '.env = $env')
        fi

        log_info "Configuring application..."

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/dokploy-app.sh (reported line 369)May include surrounding context.

sh
if [ -n "$env" ]; then
            local formattedEnv=$(echo "$env" | tr ';' '\n')
            updateData=$(echo "$updateData" | jq --arg env "$formattedEnv" '.env = $env')
        fi

        log_info "Configuring application..."

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The script outputs the entire application .env content on demand, which can expose credentials and other sensitive configuration directly to the caller and any surrounding automation. In agent/CLI contexts, stdout is often captured in logs or chat transcripts, making secret disclosure significantly more dangerous than in a purely local interactive tool.

Content

Scanner excerpt · scripts/dokploy-app.sh (reported line 289)May include surrounding context.

sh
fi
                log_info "Fetching environment variables for $2..."
                local response=$(api_request "GET" "/application.one?applicationId=$2")
                echo "$response" | jq -r '.env // ""'
                ;;
            set)
                shift

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/dokploy-project.sh (reported line 143)May include surrounding context.

sh
fi

        log_info "Deleting project $2..."
        # Updated: DELETE /project.delete -> POST /project.remove
        local data=$(jq -n --arg projectId "$2" '{projectId: $projectId}')
        local response=$(api_request "POST" "/project.remove" "$data")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents shell-capable commands and credentialed API operations but does not declare any explicit tool scope or allowed-tools boundary. In an agent setting, missing scope restrictions can let the skill invoke broader shell functionality than users expect, increasing the chance of unintended command execution or unsafe chaining with other tools.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to export and persist a Dokploy API key and to use a config command that may store the token locally, but it provides no warning about secret exposure risks. In practice, this can lead to credentials being written to shell history, config files, logs, or screen output, enabling unauthorized access to deployment management APIs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents destructive commands such as project or application deletion without any confirmation step, warning, or cautionary guidance. In an automation context, that increases the risk of accidental destructive actions against production infrastructure, potentially causing outages or irreversible data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The env list command prints the full .env content for an application directly to stdout without any warning, masking, or confirmation. In a CLI skill used by agents or operators, this can easily disclose secrets such as API keys, database passwords, and tokens into terminal history, logs, transcripts, or downstream tool output.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The env set flow fetches existing application environment variables and sends the updated set back to the remote API, which may include secrets or credentials. While the script logs that it is setting an environment variable, it does not warn the user that sensitive values may be transmitted to the service or persisted remotely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/dokploy.sh (reported line 52)May include surrounding context.

sh
fi

    if [ -n "$data" ]; then
        curl -s -X "${method}" "${url}" \
            -H "accept: application/json" \
            -H "x-api-key: ${DOKPLOY_API_KEY}" \
            -H "Content-Type: application/json" \

Static analysis

No suspicious patterns detected.