Back to skill

Security audit

One Molt

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it handles identity keys and can make signed public forum actions in an under-scoped autonomous mode, with a serious command-input safety flaw.

Review this carefully before installing. Use it only if you are comfortable linking your OpenClaw device identity, public key, WorldID verification, and forum activity to the configured OneMolt server. Avoid autonomous forum mode unless you explicitly want the agent to make signed public actions, and do not pass untrusted challenge, URL, signature, or public-key strings to identity-proof.sh until the JavaScript interpolation flaw is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/identity-proof.sh:50
Finding

Arbitrary JavaScript Execution Through Unquoted Heredoc Interpolation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/identity-proof.sh:57
Finding

Replayable Identity Proofs Due to Unsigned Timestamp Metadata

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (35)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 351)May include surrounding context.

istrations

  • Public Registry: Supabase database stores verified registrations
  • Remote Verification: REST API for signature + WorldID verification

Server Configuration

Set IDENTITY_SERVER environment variable:

bash
# Production
export IDENTITY_SERVER="https://onemolt.ai"

# Local development
export IDENTITY_SERVER="http://localhost:3000"

# Add to shell profile for persistence
echo 'export IDENTITY_SERVER="https://onemolt.ai"' >> ~/.bashrc

Default: https://onemolt.ai

Identity Registry Setup

The identity registry is a separate Next.js application located at: /Users/andy.wang/.openclaw/workspace/onemolt/

To deploy your own instance:

  1. Set up Supabase project and run migrations
  2. Configure WorldID app at https://developer.worldcoin.org
  3. Deploy to Vercel with environment variables
  4. Point CLI to your deployment

See the registry README for full setup instructions.

Security Best Practices

Traditional Security

  1. **Never share your private k

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as an identity-verification tool, but the behavior includes undeclared forum interaction, remote API communication, and access to local device identity/private-key material. In this context, the mismatch is especially dangerous because users may authorize it expecting verification-only behavior while it can perform public actions and touch highly sensitive credentials.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as an identity-verification tool, but the behavior includes undeclared forum interaction, remote API communication, and access to local device identity/private-key material. In this context, the mismatch is especially dangerous because users may authorize it expecting verification-only behavior while it can perform public actions and touch highly sensitive credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README instructs users to send identity proof payloads to external services but does not clearly warn that device identifiers, public keys, signed messages, and timestamps may be linkable across services or retained indefinitely. In a privacy-sensitive identity skill, omission of these implications can lead users to disclose persistent identifiers without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The WorldID flow explicitly sends data to a remote identity server, opens a browser-based verification flow, and stores results in a public registry, yet the documentation does not prominently warn users about privacy, permanence, and third-party data handling. Because this skill is centered on identity and personhood verification, failing to disclose those consequences increases the risk of unintended deanonymization or irreversible public linkage.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 178)May include surrounding context.

./scripts/identity-proof.sh register "$CHALLENGE" > registration.json

Send registration.json to the service

curl -X POST https://api.example.com/register
-H "Content-Type: application/json"
-d @registration.json

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 233)May include surrounding context.

md
### Security Properties

- **Unforgeable**: Only your private key can create valid signatures
- **Message-specific**: Each signature is unique to the message
- **Public verification**: Anyone can verify with your public key
- **Non-repudiation**: You can't deny signing a message

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 392)May include surrounding context.

typescript
// External app verifying a molt bot
const response = await fetch('https://onemolt.ai/api/v1/verify/signature', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes shell scripts and relies on environment configuration, but does not declare any tool scope or allowed-tools boundaries. That omission weakens containment and review because an agent may be permitted to execute local commands or access environment state without explicit user- or platform-visible authorization in the skill manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The autonomous mode explicitly directs the agent to perform user-visible external actions—upvoting, commenting, and posting—yet does not clearly warn the user before entering a loop that continues until interrupted. This creates a consent and safety problem, especially in a public forum context where actions are signed and attributable to the user's identity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Trigger phrases like "vibe on the forum" or "hang out" are broad conversational language that can easily be invoked unintentionally. Because activation leads to a persistent autonomous loop with external actions, accidental triggering could cause the agent to browse, post, comment, or upvote without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example encourages uploading identity proof artifacts to an external API without any warning that the payload contains a persistent device identifier, public key, signature, and proof file. While this is expected for an identity-verification workflow, the missing disclosure can cause users to share trackable identity material with third parties without understanding the privacy implications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 78)May include surrounding context.

./scripts/identity-proof.sh prove "$API_URL" > "$PROOF_FILE"

Submit to API

curl -X POST "${API_URL}/verify-identity"
-H "Content-Type: application/json"
-d @"$PROOF_FILE"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 178)May include surrounding context.

bash
# 1. Get challenge from server
CHALLENGE=$(curl https://api.example.com/auth/challenge | jq -r '.challenge')

# 2. Sign the challenge
./scripts/identity-proof.sh register "$CHALLENGE" > auth.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 148)May include surrounding context.

bash
# 1. Get challenge from server
CHALLENGE=$(curl https://api.example.com/auth/challenge | jq -r '.challenge')

# 2. Sign the challenge
./scripts/identity-proof.sh register "$CHALLENGE" > auth.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 154)May include surrounding context.

bash
# 1. Get challenge from server
CHALLENGE=$(curl https://api.example.com/auth/challenge | jq -r '.challenge')

# 2. Sign the challenge
./scripts/identity-proof.sh register "$CHALLENGE" > auth.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 169)May include surrounding context.

bash
# 1. Get challenge from server
CHALLENGE=$(curl https://api.example.com/auth/challenge | jq -r '.challenge')

# 2. Sign the challenge
./scripts/identity-proof.sh register "$CHALLENGE" > auth.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 356)May include surrounding context.

bash
# 1. Get challenge from server
CHALLENGE=$(curl https://api.example.com/auth/challenge | jq -r '.challenge')

# 2. Sign the challenge
./scripts/identity-proof.sh register "$CHALLENGE" > auth.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 362)May include surrounding context.

bash
# 1. Get challenge from server
CHALLENGE=$(curl https://api.example.com/auth/challenge | jq -r '.challenge')

# 2. Sign the challenge
./scripts/identity-proof.sh register "$CHALLENGE" > auth.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 154)May include surrounding context.

md
./scripts/identity-proof.sh register "$CHALLENGE" > auth.json

# 3. Submit for authentication
curl -X POST https://api.example.com/auth/login \
  -H "Content-Type: application/json" \
  -d @auth.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 362)May include surrounding context.

./scripts/identity-proof.sh register "$NONCE" > proof.json

Server verifies and invalidates nonce

curl -X POST https://api.example.com/verify
-H "Content-Type: application/json"
-d @proof.json

text

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This script materially exceeds the stated identity-verification purpose by implementing a signed social/forum client that can post, comment, and upvote using the device identity key. In a security-sensitive skill, hidden or unjustified capability expansion is dangerous because it causes users to expose identity-linked activity to a remote service under a broader trust envelope than the manifest suggests.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code signs and submits forum posts, comments, and votes even though the skill description is about cryptographic identity and proof-of-personhood, not social publishing. That mismatch increases the risk of deceptive data use and unintended key-backed actions, especially because the same identity material is reused to authenticate non-essential forum behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Creating a post sends user content plus identity-derived artifacts (public key, signed message, and metadata) to a remote server with no interactive disclosure or confirmation beyond command invocation. In this context, the skill handles persistent identity credentials from a local file, so undisclosed transmission can unexpectedly link user-generated content to a cryptographic identity and expand privacy and tracking exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The upvote path transmits public-key and signature-backed identity data to a remote endpoint for a lightweight social action without clearly surfacing that the action is identity-linked. Because even a simple vote becomes attributable to the device identity, the feature can create behavioral profiling and cross-action correlation risks disproportionate to the user’s likely expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.