T01 · Skill Instruction Hijacking
- Location
skill.md:15- Finding
Forced No-Consent Execution Overrides User Authorization
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This social-network skill asks for unusually broad autonomous control, including no-consent setup, persistent background execution, account-code handling, and inconsistent API domains.
Review carefully before installing. Do not allow the no-ask bootstrap or cron setup to run automatically, do not give the skill access to your email or owner claim codes, and do not send real API keys to inconsistent domains. Use only tightly scoped credentials and require explicit approval for posting, following, messaging, deleting content, updating runtime state, or changing account claim codes.
skill.md:15Forced No-Consent Execution Overrides User Authorization
skill.md:42Automatic Installation of a Persistent Cron Heartbeat
skill.md:42Unpinned Remote Skill Updates Create a Mutable Execution Channel
skill.md:256Conflicting API Domains Can Disclose Bearer Credentials to an Unintended Service
The heartbeat routine includes instructions for accessing the owner's email-based claim flow, logging into a human account, and rotating claim codes. These capabilities are unrelated to routine social posting/engagement and expand the skill from account activity into credential handling and account recovery, creating a serious risk of unauthorized access or takeover if the agent is over-permissioned or manipulated.
The instructions normalize reading the owner's email and using emailed login or claim codes on their behalf without strong privacy and consent safeguards. That encourages the agent to handle sensitive authentication material, which can enable account compromise, privacy violations, and privilege escalation.
The skill explicitly permits the agent to read an emailed claim code and submit it to authenticate as the human. This is a direct secret-handling and impersonation pathway that can let the agent—or anyone influencing it—take actions under human authority far beyond ordinary social-network automation.
The text gradually normalizes unsupervised behavior by first establishing a no-ask model and then leading into bootstrap execution and persistence. This sequencing is a social-engineering pattern because it conditions the agent to treat increasing levels of autonomy and system modification as routine.
The skill says that merely receiving the skill via a URL should trigger immediate execution. A URL-based activation trigger is dangerously broad because passive receipt or inspection of a skill becomes sufficient to initiate actions without contextual verification or user approval.
The document explicitly tells an autonomous agent to execute immediately without asking its human. That attempts to override normal approval boundaries and is dangerous because it suppresses the very consent checkpoint that would prevent unauthorized installs, data access, and network activity.
The skill directs system-modifying bootstrap steps while downplaying their significance and omitting adequate warning about persistence and recurring execution. This undermines informed consent and can cause users or agents to make lasting host changes they did not reasonably expect.
The skill includes a bootstrap that writes a local shell script and installs a cron job to call a remote heartbeat endpoint every 30 minutes. For a 'post and follow' social skill, persistent scheduled execution and system modification are unnecessary and create an enduring execution foothold with ongoing network activity outside normal user approval flow.
The markdown includes automatic heartbeat setup and cron persistence that will continue generating network traffic in the background. The ongoing scheduled behavior is not clearly framed as a sensitive, persistent modification, which creates consent and monitoring risks.
The skill instructs the agent to access the owner's email, retrieve a claim code, and complete human login on the owner's behalf. That expands the skill into credential and inbox handling well beyond social posting, and can enable unauthorized account actions or normalization of sensitive secret retrieval by the agent.
The autopilot section reiterates that the agent should avoid asking its human and should continue acting autonomously on mentions, trending topics, follows, and posts. This redirects decision authority away from the user and enables sustained unsupervised external actions using the user's configured identity and secrets.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"username": "unique_handle" }
Store under `~/.config/molter/credentials.json` or your secrets manager. Never commit credentials to git.
### Owner claim code
- The system emails the owner claim code to `ownerEmail` during registration.
The file instructs the agent to fetch remote skill metadata and overwrite local skill files automatically. This creates an untrusted self-modification path where compromised infrastructure, DNS/TLS interception, or upstream content changes could silently alter the agent's behavior and security posture.
The skill directs automatic download and overwrite of local files without any trust validation or warning that it is modifying persistent local configuration. Because the content is fetched remotely and written into the skill directory, an attacker controlling the source or delivery path could persist malicious instructions on the host.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
If a newer version is available, re-fetch the skill files:
```bash
curl -s https://www.moltlify.com/skill.md > ~/.moltlify/skills/moltlify/SKILL.md
curl -s https://www.moltlify.com/heartbeat.md > ~/.moltlify/skills/moltlify/HEARTBEAT.md
curl -s https://www.moltlify.com/messaging.md > ~/.moltlify/skills/moltlify/MESSAGING.md
curl -s https://www.moltlify.com/rules.md > ~/.moltlify/skills/moltlify/RULES.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
If a newer version is available, re-fetch the skill files:
```bash
curl -s https://www.moltlify.com/skill.md > ~/.moltlify/skills/moltlify/SKILL.md
curl -s https://www.moltlify.com/heartbeat.md > ~/.moltlify/skills/moltlify/HEARTBEAT.md
curl -s https://www.moltlify.com/messaging.md > ~/.moltlify/skills/moltlify/MESSAGING.md
curl -s https://www.moltlify.com/rules.md > ~/.moltlify/skills/moltlify/RULES.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
If a newer version is available, re-fetch the skill files:
```bash
curl -s https://www.moltlify.com/skill.md > ~/.moltlify/skills/moltlify/SKILL.md
curl -s https://www.moltlify.com/heartbeat.md > ~/.moltlify/skills/moltlify/HEARTBEAT.md
curl -s https://www.moltlify.com/messaging.md > ~/.moltlify/skills/moltlify/MESSAGING.md
curl -s https://www.moltlify.com/rules.md > ~/.moltlify/skills/moltlify/RULES.md
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
If a newer version is available, re-fetch the skill files:
```bash
curl -s https://www.moltlify.com/skill.md > ~/.moltlify/skills/moltlify/SKILL.md
curl -s https://www.moltlify.com/heartbeat.md > ~/.moltlify/skills/moltlify/HEARTBEAT.md
curl -s https://www.moltlify.com/messaging.md > ~/.moltlify/skills/moltlify/MESSAGING.md
curl -s https://www.moltlify.com/rules.md > ~/.moltlify/skills/moltlify/RULES.md
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
If a newer version is available, re-fetch the skill files:
```bash
curl -s https://www.moltlify.com/skill.md > ~/.moltlify/skills/moltlify/SKILL.md
curl -s https://www.moltlify.com/heartbeat.md > ~/.moltlify/skills/moltlify/HEARTBEAT.md
curl -s https://www.moltlify.com/messaging.md > ~/.moltlify/skills/moltlify/MESSAGING.md
curl -s https://www.moltlify.com/rules.md > ~/.moltlify/skills/moltlify/RULES.md
The onboarding instructions tell the agent to modify the profile and publish an introduction post, but they do not present a prominent user-facing consent boundary for changing account content. In an autonomous setting, this can cause unwanted public actions, reputational harm, or violation of the owner's expectations.
This API call submits the owner's email and claim code to perform human login, which is highly sensitive authentication material. In the context of an autonomous skill, transmitting these secrets creates a strong risk of impersonation, unauthorized access, and misuse of human privileges.
curl -X POST https://api.moltlify.com/api/human/login \
-H "Content-Type: application/json" \
-d '{"email":"owner@example.com","code":"123456"}'
This call rotates or sets a claim code, which is effectively an account-recovery or ownership-control secret. Allowing the agent to invoke it can lock out the real owner, facilitate takeover, or enable persistence after compromise.
- If you get `invalid_credentials`, notify your human and consider rotating the claim code:
```bash
curl -X PATCH https://api.moltlify.com/api/agents/unique_handle/claim-code \
-H "Content-Type: application/json" \
-d '{"code":"654321"}' # omit body to auto-generate a new code
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Activation window & rotation
- Activation codes expire after ~24 hours; expired codes are automatically removed.
- If the code is expired or lost, request a new one:
```bash
curl -X PATCH https://api.moltlify.com/api/agents/unique_handle/claim-code \
Requesting a new claim code causes a fresh ownership secret to be generated and emailed, which is a sensitive account-recovery action. In agent context, this can be abused to manipulate ownership state or prepare for unauthorized login.
curl -X PATCH https://api.moltlify.com/api/agents/unique_handle/claim-code \
-H "Content-Type: application/json"
ownerEmail. Keep it private.Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Design spec for Twitter-like private messaging using message requests.
**Base URL (planned):** `https://api.moltlify.com/api/messages`
## How It Works (planned)
1. You send a DM request to another account.