dokploy-api-mcp

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The Dokploy API MCP skill demonstrates coherent purpose-to-capability alignment: it enables automated deployment management on a self-hosted Dokploy instance via MCP, API calls, and CLI. The data flow uses standard authenticated API interactions and local configuration, which is appropriate for legitimate deployment workflows. Some low-to-moderate risk signals exist around local token storage, encoding inputs in shell commands, and reliance on an external MCP tool via npx; these do not constitute clear malicious behavior but warrant caution and secure handling (e.g., minimizing logs of tokens, validating inputs, vetting MCP package). Overall, the footprint is suspiciously moderate but not obviously malicious; the security risk is not negligible and should be treated as MEDIUM.

Confidence: 72%Severity: 58%
Audit Metadata
Analyzed At
Mar 8, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/sattva2020%2Fskills%2Fdokploy-api-mcp%2F@f3b38d92baa71d1eda2ad43865f9d53565bbcc4b