T09 · Insecure Skill Coding Practices
- Location
scripts/dokploy-config.sh:41- Finding
API Key Disclosed by Configuration Display Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Dokploy skill is mostly purpose-aligned, but it handles deployment credentials and environment secrets unsafely enough that users should review it carefully before installing.
Install only if you are comfortable giving the skill a Dokploy API key with the ability to read and modify deployment resources. Avoid running dokploy-config show with a real key, avoid storing the key through dokploy-config set until the config file handling is fixed, use a narrowly scoped API key where possible, and treat dokploy-app env list output as secret material that may be captured in logs or agent transcripts.
scripts/dokploy-config.sh:41API Key Disclosed by Configuration Display Command
scripts/dokploy-config.sh:16Command Injection Through Sourceable Configuration File and Insecure Plaintext Credential Storage
The declared purpose is remote Dokploy resource management, but the documented behavior also includes storing and displaying local API configuration, including credentials. This mismatch matters because users or orchestration systems may trust the skill for remote deployment tasks without realizing it also persists secrets locally, creating unexpected exposure of sensitive tokens.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if [ -n "$env" ]; then
local formattedEnv=$(echo "$env" | tr ';' '\n')
updateData=$(echo "$updateData" | jq --arg env "$formattedEnv" '.env = $env')
fi
log_info "Configuring application..."
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if [ -n "$env" ]; then
local formattedEnv=$(echo "$env" | tr ';' '\n')
updateData=$(echo "$updateData" | jq --arg env "$formattedEnv" '.env = $env')
fi
log_info "Configuring application..."
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
if [ -n "$env" ]; then
local formattedEnv=$(echo "$env" | tr ';' '\n')
updateData=$(echo "$updateData" | jq --arg env "$formattedEnv" '.env = $env')
fi
log_info "Configuring application..."
The script outputs the entire application .env content on demand, which can expose credentials and other sensitive configuration directly to the caller and any surrounding automation. In agent/CLI contexts, stdout is often captured in logs or chat transcripts, making secret disclosure significantly more dangerous than in a purely local interactive tool.
fi
log_info "Fetching environment variables for $2..."
local response=$(api_request "GET" "/application.one?applicationId=$2")
echo "$response" | jq -r '.env // ""'
;;
set)
shift
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
fi
log_info "Deleting project $2..."
# Updated: DELETE /project.delete -> POST /project.remove
local data=$(jq -n --arg projectId "$2" '{projectId: $projectId}')
local response=$(api_request "POST" "/project.remove" "$data")
The skill documents shell-capable commands and credentialed API operations but does not declare any explicit tool scope or allowed-tools boundary. In an agent setting, missing scope restrictions can let the skill invoke broader shell functionality than users expect, increasing the chance of unintended command execution or unsafe chaining with other tools.
The skill instructs users to export and persist a Dokploy API key and to use a config command that may store the token locally, but it provides no warning about secret exposure risks. In practice, this can lead to credentials being written to shell history, config files, logs, or screen output, enabling unauthorized access to deployment management APIs.
The skill documents destructive commands such as project or application deletion without any confirmation step, warning, or cautionary guidance. In an automation context, that increases the risk of accidental destructive actions against production infrastructure, potentially causing outages or irreversible data loss.
The env list command prints the full .env content for an application directly to stdout without any warning, masking, or confirmation. In a CLI skill used by agents or operators, this can easily disclose secrets such as API keys, database passwords, and tokens into terminal history, logs, transcripts, or downstream tool output.
The env set flow fetches existing application environment variables and sends the updated set back to the remote API, which may include secrets or credentials. While the script logs that it is setting an environment variable, it does not warn the user that sensitive values may be transmitted to the service or persisted remotely.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
fi
if [ -n "$data" ]; then
curl -s -X "${method}" "${url}" \
-H "accept: application/json" \
-H "x-api-key: ${DOKPLOY_API_KEY}" \
-H "Content-Type: application/json" \
No suspicious patterns detected.