Back to skill

Security audit

ggshield Secret Scanner

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but its documentation includes unsafe install guidance and overconfident privacy claims for a cloud-backed secret scanner.

Review before installing. Avoid the curl-to-bash Moltbot installer, prefer a pinned and verified install path, and confirm GitGuardian/ggshield data handling for your deployment before scanning sensitive private repositories or files. Only let the agent install git hooks when you explicitly want commits or pushes blocked by ggshield.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:222
Finding

Unverified Remote Installer Executed Directly by Bash

Content
View full analysis

Vulnerability Details

File Location: README.md, line 222
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

bash
# Quick install
curl -fsSL https://molt.bot/install.sh | bash

Technical Analysis

The installation instructions retrieve a mutable shell script from an external server and pipe it directly into Bash. The downloaded content is not pinned to a reviewed version and is not authenticated using a publisher signature or verified against a cryptographic digest. It is also not saved for inspection before execution.

HTTPS protects content in transit under normal conditions, but it does not protect users if the hosting service, publishing account, installer infrastructure, or trusted delivery chain is compromised. The effective payload can therefore change after this Skill has been reviewed.

This behavior exceeds the minimum privileges required for the Skill’s declared secret-scanning functionality. The command appears under optional local Moltbot integration testing, while the Skill itself only requires Python, ggshield, and a GitGuardian API key. The README also provides an npm-based installation alternative, so immediate execution of a remote shell script is unnecessary.

Attack Path

  1. An attacker compromises the molt.bot website, installer publishing process, DNS/TLS trust chain, or an account capable of changing install.sh.
  2. The attacker replaces or modifies the installer with malicious shell commands.
  3. A user follows the README and runs the documented curl | bash command.
  4. curl streams the attacker-controlled content directly to Bash without integrity verification or prior inspection.
  5. Bash executes the payload with all permissions available to the invoking user.
  6. The payload can access user-readable source code and credentials, alter user-writable files, or establish persistence where the user has sufficie ...[truncated 792 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash installation method from the README.
  2. Prefer a reviewed, version-pinned package installation rather than an unbounded latest release.
  3. If a remote installer is unavoidable:
    • Reference an immutable, versioned release artifact.
    • Download it to a local file instead of piping it into a shell.
    • Obtain and verify a publisher-provided cryptographic signature or SHA-256 digest through a trusted channel.
    • Allow the user to inspect the script before execution.
    • Execute it as an unprivileged user and document the files, network endpoints, and configuration it changes.
  4. Document Moltbot as an optional integration-test dependency, clearly separating it from the requirements for the core ggshield wrapper.
  5. Avoid @latest and broadly ranged installation examples where practical; pin reviewed tool and dependency versions and use lockfiles with integrity data.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (31)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 44)May include surrounding context.

  • Generate an API key in Settings
    • Create a .env file:
    bash
    echo 'GITGUARDIAN_API_KEY=your-api-key-here' > .env
    

Installation

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 105)May include surrounding context.

  • Generate an API key in Settings
    • Create a .env file:
    bash
    echo 'GITGUARDIAN_API_KEY=your-api-key-here' > .env
    

Installation

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 106)May include surrounding context.

  • Generate an API key in Settings
    • Create a .env file:
    bash
    echo 'GITGUARDIAN_API_KEY=your-api-key-here' > .env
    

Installation

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 127)May include surrounding context.

  • Generate an API key in Settings
    • Create a .env file:
    bash
    echo 'GITGUARDIAN_API_KEY=your-api-key-here' > .env
    

Installation

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 143)May include surrounding context.

  • Generate an API key in Settings
    • Create a .env file:
    bash
    echo 'GITGUARDIAN_API_KEY=your-api-key-here' > .env
    

Installation

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 312)May include surrounding context.

  • Generate an API key in Settings
    • Create a .env file:
    bash
    echo 'GITGUARDIAN_API_KEY=your-api-key-here' > .env
    

Installation

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 313)May include surrounding context.

  • Generate an API key in Settings
    • Create a .env file:
    bash
    echo 'GITGUARDIAN_API_KEY=your-api-key-here' > .env
    

Installation

External Script Fetching

High
Category
Supply Chain
Confidence
97% confidence
Finding

The README tells users to pipe a remote script directly into bash using curl -fsSL https://molt.bot/install.sh | bash. This executes unreviewed network-delivered code immediately; if the host, DNS, TLS trust chain, or upstream script is compromised, users could suffer arbitrary code execution on their machines.

Content

Scanner excerpt · README.md (reported line 222)May include surrounding context.

bash
# Quick install
curl -fsSL https://molt.bot/install.sh | bash

# Or via npm
npm install -g moltbot@latest

Chaining Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The | bash construct creates a dangerous execution chain from network fetch to shell interpreter with no verification step. In a skill README, this is especially risky because users may follow installation steps verbatim, turning a documentation shortcut into a straightforward arbitrary-code-execution path if the fetched content is tampered with.

Content

Scanner excerpt · README.md (reported line 222)May include surrounding context.

bash
# Quick install
curl -fsSL https://molt.bot/install.sh | bash

# Or via npm
npm install -g moltbot@latest

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The advertised purpose is secret scanning before leaks into git, but the documented behavior also includes installing git hooks and scanning Docker images. This expands the operational scope from passive detection to repository modification and broader artifact inspection, which can surprise users and agents and lead to unintended changes or overbroad access.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

text
Dev: @clawd scan-repo ~/my-old-project
Moltbot: ❌ Found 5 secrets in history!
         - AWS keys in config/secrets.json
         - Database password in docker-compose.yml
         - Slack webhook in .env.example
Moltbot: Recommendation: Rotate these credentials immediately.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The privacy section makes a strong claim that only metadata is sent and that actual secrets or file contents are never sent, while the skill relies on a cloud-backed scanning service via an API key. If that claim is inaccurate, users may scan sensitive repositories under false assumptions, causing unintentional disclosure of source content or secrets to a third party.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 259)May include surrounding context.

ained on leaked secrets database

Troubleshooting

"ggshield: command not found"

ggshield is not installed or not in your PATH.

Fix:

bash
pip install ggshield
which ggshield  # Should return a path

"GITGUARDIAN_API_KEY not found"

The environment variable is not set.

Fix:

bash
export GITGUARDIAN_API_KEY="your-key"
# For persistence, add to ~/.bashrc or ~/.zshrc:
echo 'export GITGUARDIAN_API_KEY="your-key"' >> ~/.bashrc
source ~/.bashrc

"401 Unauthorized"

API key is invalid or expired.

Fix:

bash
# Test the API key
ggshield auth status

# If invalid, regenerate at https://dashboard.gitguardian.com → API Tokens
# Then: export GITGUARDIAN_API_KEY="new-key"

"Slow on large repositories"

Scanning a 50GB monorepo takes time. ggshield is doing a lot of work.

Workaround:

bash
# Scan only staged changes (faster):
@clawd scan-staged

# Or specify a subdirectory:
@clawd scan-file ./app/config.py

Advanced Topics

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · ggshield_skill.py (reported line 60)May include surrounding context.

python
api_key = self._get_api_key()
        command = ["ggshield", *args]

        env = {**os.environ, self.api_key_env: api_key}

        result = subprocess.run(
            command,

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

  1. GitGuardian API Key (free):
    bash
    echo 'GITGUARDIAN_API_KEY=your-api-key-here' > .env
    

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 246)May include surrounding context.

3. Add your skill locally

bash
# Create the managed skills folder
mkdir -p ~/.clawdbot/skills

# Symlink your skill for live development

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares required binaries and environment variables but does not declare an explicit tool scope such as shell or env access. That omission weakens the trust boundary for users and agents, because the skill clearly expects command execution and environment access while not transparently constraining those capabilities.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

Optional ggshield Config

Create ~/.gitguardian/.gitguardian.yml for persistent settings:

yaml
verbose: false

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Absolute privacy guarantees without qualification are risky in a security tool, especially when behavior may vary by deployment mode or backend. Overstated assurances can cause unsafe use in regulated or high-sensitivity environments where data handling requirements are strict.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

bash
export GITGUARDIAN_API_KEY="your-key"
# For persistence, add to ~/.bashrc or ~/.zshrc:
echo 'export GITGUARDIAN_API_KEY="your-key"' >> ~/.bashrc
source ~/.bashrc

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Repository and file scanning are performed through ggshield backed by GitGuardian, which may transmit content or derived findings to an external service, yet the user-facing responses do not clearly warn about that data flow. For a secret-scanning tool, this context makes disclosure especially important because the scanned material may itself contain credentials or sensitive code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.