Back to skill

Security audit

SUIROLL

Security checks for vulnerabilities and agentic risk

Overview

This Sui giveaway skill is mostly coherent in purpose, but it handles real keys and funds while under-disclosing credential storage and making fairness claims the code does not support.

Review carefully before installing, especially if you will use mainnet or valuable prizes. Use a dedicated test wallet and testnet first, assume the Moltbook API key may be written to a local plaintext session file, and do not rely on the advertised provable fairness unless the deployed contract and randomness design are independently verified.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/commands/enter.ts:17
Finding

Unverified Cached Session Allows Moltbook Agent Identity Forgery

Content
View full analysis
{ try { const fs = await import('fs'); const path = await import('path'); const sessionPath = path.join( process.env.HOME || '~', '.config', 'suiroll', 'moltbook-session.json' ); if (fs.existsSync(sessionPath)) { const session = JSON.parse(fs.readFileSync(sessionPath, 'utf-8')); return session; } } catch (error) { // Ignore errors } return null; } ``` ```ts const session = await loadSession(); if (session) { console.log('✓ Found saved Moltbook session'); console.log(` Agent: ${session.agent.name}\n`); return session; } ``` ```ts agentInfo = await authenticateAgent(); agentId = agentInfo.agent.id; ``` ```ts tx.moveCall({ target: `${packageId}::lottery::enter_lottery`, arguments: [ tx.object(options.lotteryId), tx.pure.string(agentId), ], }); ``` ### Technical Analysis The cached session file is treated as authoritative proof of a Moltbook identity. When the file exists and contains valid JSON, `authenticateAgent()` returns its contents without regenerating an identity token or calling `verifyIdentityToken()`. The `agent.id` value from this locally editable file is then inserted directly into the signed Sui transaction. Signing the transaction only proves control of the Sui wallet; it does not prove that the wallet controls the claimed Moltbook identity. Consequently, the advertised dual wallet-and-agent uniqueness control is not cryptographically enforced by this client. A forged or modified session can supply an arbitrary agent identifier. ### Attack Path ...[truncated 1160 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/commands/enter.ts:34
Finding

Moltbook API Key Is Persisted in a Plaintext Session File Without Explicit Restrictive Permissions

Content
View full analysis
{ try { const fs = await import('fs'); const path = await import('path'); const sessionDir = path.join( process.env.HOME || '~', '.config', 'suiroll' ); const sessionPath = path.join(sessionDir, 'moltbook-session.json'); // Ensure directory exists if (!fs.existsSync(sessionDir)) { fs.mkdirSync(sessionDir, { recursive: true }); } fs.writeFileSync( sessionPath, JSON.stringify({ apiKey, agent }, null, 2) ); } catch (error) { console.error('⚠️ Failed to save session:', error); } } ``` ### Technical Analysis The Skill saves the complete reusable Moltbook API key in an unencrypted JSON document. Neither the directory nor the file is created with explicit restrictive modes such as `0o700` and `0o600`. Actual accessibility depends on the operating system and process umask, but the code does not guarantee that only the owning account can read the credential. The code also performs a conventional pathname-based write without checking for symbolic links or safely replacing the file. The persistence is broader than necessary because the saved `apiKey` is not needed merely to display the cached agent profile, and the current cached-session branch does not reauthenticate it. ### Attack Path 1. A user authenticates through `MOLTBOOK_API_KEY` or the interactive prompt. 2. `saveSession()` writes the API key to `~/.config/suiroll/moltbook-session.json`. 3. Another local process, user, backup collector, or accidentally published configuration obtains the file. 4. The attacker extracts the plaintext `apiKey`. 5. The attacker reuses the key against Mol ...[truncated 670 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/commands/draw.ts:49
Finding

Predictable and Operator-Controlled Winner Seed Invalidates the Claimed Provable Fairness

Content
View full analysis
', 'Lottery ID (Object ID)') .option('--seed ', 'Random seed for winner selection (optional)') ``` ```ts // 1. Generate random seed (or use provided) const revealSeed = options.seed ? parseInt(options.seed, 10) : Math.floor(Math.random() * 1000000); console.log(`🎰 Using reveal seed: ${revealSeed}`); // 2. Create Transaction Block const tx = new Transaction(); const packageId = networkConfig.packageId; // 3. Call draw_winners tx.moveCall({ target: `${packageId}::lottery::draw_winners`, arguments: [ tx.object(options.lotteryId), tx.pure.u64(revealSeed), ], }); ``` ### Technical Analysis `Math.random()` is not a cryptographically secure random-number generator. The implementation further restricts its output to only one million possible values. More importantly, the command explicitly permits the lottery creator to choose any seed using `--seed`. The code passes that client-selected integer directly to the Move contract's `draw_winners` function. No Sui randomness object, validator-generated randomness, VRF proof, or unpredictable public entropy is supplied by this client. This behavior contradicts the Skill documentation's claims of native Sui VRF, resistance to manipulation, and provably fair winner selection. Unless the deployed contract independently neutralizes this attacker-controlled seed—a property that cannot be established from the reviewed project—the operator can search candidate values before submitting the transaction. ### Attack Path 1. The lottery operator obtains ...[truncated 1079 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
package.json:53
Finding

Declared Skill Permissions Omit Actual Credential Storage and Moltbook Network Access

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (79)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented use of SUI_PRIVATE_KEY and mainnet/testnet RPC access indicates the skill can perform high-impact blockchain operations, but these capabilities are not declared in a permission model. In an agent setting, undeclared signing/broadcast ability is a serious trust and authorization failure because it can directly affect real funds.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
# Deploy contract first, then update PACKAGE_ID in src/config.ts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/commands/enter.js (reported line 140)May include surrounding context.

js
console.error('❌ Moltbook authentication failed!');
            console.error('   Error:', error);
            console.error('\n💡 To authenticate:');
            console.error('   1. Get API key from: https://www.moltbook.com/developers');
            console.error('   2. Set environment variable:');
            console.error('      export MOLTBOOK_API_KEY="moltbook_your_api_key"\n');
            process.exit(1);

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/commands/enter.ts (reported line 176)May include surrounding context.

ts
console.error('❌ Moltbook authentication failed!');
            console.error('   Error:', error);
            console.error('\n💡 To authenticate:');
            console.error('   1. Get API key from: https://www.moltbook.com/developers');
            console.error('   2. Set environment variable:');
            console.error('      export MOLTBOOK_API_KEY="moltbook_your_api_key"\n');
            process.exit(1);

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

When no private key is configured, the code generates a new keypair and prints the private key directly to the console. Console output is commonly captured by terminals, shell history, CI logs, container logs, and observability systems, so this behavior can expose signing credentials to anyone with log access and enable theft of funds or unauthorized blockchain actions. The giveaway-tool context makes this more dangerous because the skill is intended to interact with on-chain assets, so leaked keys can have immediate financial impact.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · dist/utils/moltbook.d.ts (reported line 73)May include surrounding context.

ts
}>;
/**
 * Get agent information from stored credentials
 * Reads from ~/.config/moltbook/credentials.json
 */
export declare function getAgentFromCredentials(): Promise<{
    apiKey: string;

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/utils/moltbook.js:13

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/utils/moltbook.ts:54

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
dist/utils/moltbook.js:125

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/utils/moltbook.ts:200