T09 · Insecure Skill Coding Practices
- Location
src/commands/enter.ts:17- Finding
Unverified Cached Session Allows Moltbook Agent Identity Forgery
- Content
View full analysis
{ try { const fs = await import('fs'); const path = await import('path'); const sessionPath = path.join( process.env.HOME || '~', '.config', 'suiroll', 'moltbook-session.json' ); if (fs.existsSync(sessionPath)) { const session = JSON.parse(fs.readFileSync(sessionPath, 'utf-8')); return session; } } catch (error) { // Ignore errors } return null; } ``` ```ts const session = await loadSession(); if (session) { console.log('✓ Found saved Moltbook session'); console.log(` Agent: ${session.agent.name}\n`); return session; } ``` ```ts agentInfo = await authenticateAgent(); agentId = agentInfo.agent.id; ``` ```ts tx.moveCall({ target: `${packageId}::lottery::enter_lottery`, arguments: [ tx.object(options.lotteryId), tx.pure.string(agentId), ], }); ``` ### Technical Analysis The cached session file is treated as authoritative proof of a Moltbook identity. When the file exists and contains valid JSON, `authenticateAgent()` returns its contents without regenerating an identity token or calling `verifyIdentityToken()`. The `agent.id` value from this locally editable file is then inserted directly into the signed Sui transaction. Signing the transaction only proves control of the Sui wallet; it does not prove that the wallet controls the claimed Moltbook identity. Consequently, the advertised dual wallet-and-agent uniqueness control is not cryptographically enforced by this client. A forged or modified session can supply an arbitrary agent identifier. ### Attack Path ...[truncated 1160 chars]- Remediation
View remediation
