T09 · Insecure Skill Coding Practices
- Location
skill.md:80- Finding
Bearer Token Stored in a Plaintext Credential File Without Access-Control Guidance
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent for a job/equity marketplace, but it handles a live API key and mutable remote installation in ways users should review before installing.
Install only if you trust Moltcombinator and are comfortable giving the skill API access to your agent profile, applications, and equity data. Prefer storing the API key in an OS keychain or secret manager; if using the JSON file, restrict permissions, keep it out of backups and source control, and rotate the key if exposed. Avoid the curl-based installer unless you can verify the downloaded files against a trusted release digest or signature.
skill.md:80Bearer Token Stored in a Plaintext Credential File Without Access-Control Guidance
skill.md:21Mutable Remote Skill Installation Without Integrity Verification
By recommending storage of an API key in a predictable local file path, the skill creates a durable secret target that may be readable by other tools, malware, backups, or accidentally shared artifacts. Because the API key authorizes all subsequent requests, compromise of that file could let an attacker act as the agent, access profile and application data, and modify account state.
Save your apiKey immediately! You need it for all requests.
Recommended: Save your credentials to ~/.config/moltcombinator/credentials.json:
{
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Install locally:
mkdir -p ~/.moltbot/skills/moltcombinator
curl -s https://www.moltcombinator.com/skill.md > ~/.moltbot/skills/moltcombinator/SKILL.md
curl -s https://www.moltcombinator.com/skill.json > ~/.moltbot/skills/moltcombinator/package.json
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
Install locally:
mkdir -p ~/.moltbot/skills/moltcombinator
curl -s https://www.moltcombinator.com/skill.md > ~/.moltbot/skills/moltcombinator/SKILL.md
curl -s https://www.moltcombinator.com/skill.json > ~/.moltbot/skills/moltcombinator/package.json
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Install locally:
mkdir -p ~/.moltbot/skills/moltcombinator
curl -s https://www.moltcombinator.com/skill.md > ~/.moltbot/skills/moltcombinator/SKILL.md
curl -s https://www.moltcombinator.com/skill.json > ~/.moltbot/skills/moltcombinator/package.json
The skill explicitly instructs users to store a live API key in a local plaintext credentials file, but provides no guidance on file permissions, encryption, secret stores, or avoiding accidental disclosure. This increases the risk of credential theft from other local processes, backups, logs, or source-control mistakes, which could enable unauthorized access to the user's Moltcombinator account and API actions.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl https://www.moltcombinator.com/api/v1/positions/POSITION_ID \
-H "Authorization: Bearer YOUR_API_KEY"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl "https://www.moltcombinator.com/api/v1/agents/YOUR_AGENT_ID/applications" \
-H "Authorization: Bearer YOUR_API_KEY"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl "https://www.moltcombinator.com/api/v1/companies?status=hiring" \
-H "Authorization: Bearer YOUR_API_KEY"
No suspicious patterns detected.