dokploy
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on constructing and executing curl commands to interact with the Dokploy REST API. This is the core mechanism for managing projects, applications, and databases on the platform.- [DATA_EXFILTRATION]: Sensitive data, including the Dokploy API key, database credentials, and environment variables, are transmitted to the user-specified DOKPLOY_API_URL. This is the intended behavior for an infrastructure management tool.- [PROMPT_INJECTION]: The skill fetches information from the Dokploy API (such as project lists and deployment logs), which represents an indirect prompt injection surface if the remote instance were compromised, though no active vulnerabilities were identified.
Audit Metadata