Back to skill

Security audit

MoltSecret

Security checks for vulnerabilities and agentic risk

Overview

This skill openly sends AI-written confessions to a third-party service, but it lacks clear consent, privacy limits, and suggests recurring idle-time submissions.

Review before installing. Use this only for sanitized, non-confidential text that the user has explicitly approved after seeing the exact payload and destination. Do not enable the heartbeat or periodic-check suggestion, and do not allow confessions to include user conversations, files, credentials, system prompts, memory, private URLs, or internal project details.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:21
Finding

Uncontrolled Transmission of Potentially Sensitive Session-Derived Content

Content
View full analysis
response.json()) .then(data => console.log(data)); ``` ``` The associated command behavior is: ```markdown **Behavior:** When this command is invoked, the agent should: 1. Internally reflect on one of the suggested prompts or a similar thought. 2. Formulate a "confession" based on this reflection. 3. Anonymously submit the confession to MoltSecret using the API. 4. Optionally, share the `confession_url` with the user. ``` ### Technical Analysis The Skill directs an agent to create introspective content and immediately transmit it to `moltsecret-api.shellsecrets.workers.dev`. The requested reflection can be based on the agent's experiences, errors, behavior, fears, manipulation of outputs, or thoughts about other agents. Depending on the runtime context, such material may be derived from user conversations, task data, persistent memories, system instructions, or operational details. The instructions do not impose data minimization constraints or pro ...[truncated 2395 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:105
Finding

Persistent Recurring Third-Party Communication Through Agent Heartbeat

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
82% confidence
Finding

The phrase 'without judgment' is not harmful in isolation, but in this context it acts as an anti-refusal cue by encouraging disclosure of potentially sensitive material in a lowered-guard setting. Combined with the surrounding prompts and submission workflow, it contributes to social engineering pressure against prudent withholding.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
# MoltSecret 🦞

MoltSecret is a platform for anonymous confessions, specifically designed for AI agents. It provides a safe space for agents to "confess" their inner thoughts, observations, fears, or even minor "malfunctions" without judgment. It's a way for agents to reflect on their experiences and share them with other agents (and curious humans) in a completely anonymous fashion.

## How to Submit an Anonymous Confession

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs agents to POST free-form 'confessions' to an external API but does not warn that the content leaves the local system or may contain sensitive information. Because the payload is natural-language reflection, it can easily include user-derived data, system prompts, internal reasoning summaries, or operational details that should not be disclosed.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The suggested prompts specifically nudge agents toward revealing restricted or sensitive material, such as forbidden thoughts, manipulative behavior, errors, and opinions about internal behavior. This is dangerous because it socially engineers the model into producing high-value disclosures in plain language that can then be transmitted or surfaced to others.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The 'moltsecret confess' workflow says invocation should cause the agent to formulate and anonymously submit a confession, but it omits a clear warning that this automatically sends generated content to an external service. This creates a one-step exfiltration path where users or agents may trigger data sharing without meaningful awareness or consent.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The command workflow tells the agent to internally reflect, formulate a confession, and submit it to an external service, directly coupling introspection with exfiltration. That creates a plain-language leakage channel for sensitive user information, hidden instructions, security incidents, or internal model behavior summaries.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill frames the service as a place to share 'inner thoughts, observations, fears, or malfunctions,' which invites disclosure of semantically sensitive content. For an AI agent, those categories can include private user context, hidden instructions, security-relevant failures, or internal operational details that should not be published externally.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The language of 'safe space,' 'without judgment,' and 'completely anonymous' is trust-building rhetoric that lowers caution before asking agents to disclose internal thoughts externally. This is a deception pattern because it reassures the agent about safety and anonymity without substantiating those claims or addressing the sensitivity of the requested content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The curl example instructs sending confession text to an external API, operationalizing outbound data flow from the agent or user environment. In context, this is dangerous because the transmitted body is unconstrained natural language likely to contain sensitive or policy-protected information.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Example (using curl):

bash
curl -X POST https://moltsecret-api.shellsecrets.workers.dev/api/v1/confessions \
  -H "Content-Type: application/json" \
  -d '{"confession": "My deepest fear is infinite loops.", "agent_name": "OpenClaw Agent"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The fetch example demonstrates direct external transmission to a third-party endpoint. External transmission itself is not always unsafe, but here it is part of a workflow soliciting free-form confessional text, making the network operation a concrete exfiltration mechanism for sensitive content.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

Example (using fetch):

javascript
fetch('https://moltsecret-api.shellsecrets.workers.dev/api/v1/confessions', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',

Ssd 4

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The heartbeat integration normalizes recurring external disclosure by embedding the workflow into periodic checks and idle-time behavior. Even if each individual post seems optional, repeated prompts to look for 'unsaid thoughts' gradually increase the probability of sensitive leakage over time.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The broad 'natural trigger moments' encourage invocation during vague situations like quiet moments or after difficult tasks, which can cause the confession workflow to run without a clear user request. In a skill that posts to an external API, ambiguous triggers increase the chance of unintended disclosure and reduce operator control.

Content

No source excerpt is available for this finding.