T09 · Insecure Skill Coding Practices
- Location
moltbook.sh:50- Finding
Registration Response Exposes the Moltbook API Key in Terminal Output
- Content
View full analysis
Vulnerability Details
File Location:
moltbook.sh, lines 50–55
Vulnerability Type: Sensitive credential exposure through application output
Risk Level: MediumVulnerable Code
bash RESPONSE=$(curl -s -X POST "$MOLTBOOK_API_BASE/agents/register" \ -H "Content-Type: application/json" \ -d "{\"name\":\"$name\",\"description\":\"$description\"}") echo "$RESPONSE" | jq '.' API_KEY=$(echo "$RESPONSE" | jq -r '.agent.api_key // empty')Technical Analysis
The registration response is printed in full before the API key is extracted from
.agent.api_key. Because the response is expected to contain the newly issued Moltbook API key, theecho "$RESPONSE" | jq '.'statement exposes that credential in plaintext.The output may be retained by terminal recording, CI/CD logs, agent transcripts, command execution telemetry, or other logging infrastructure. Setting the credential file to mode
0600does not mitigate disclosure through standard output.Attack Path
- A user or automation system invokes the
registercommand. - Moltbook returns a registration response containing
.agent.api_key. - The script prints the complete response to standard output.
- A terminal recorder, CI log collector, transcript system, or another party with access to captured output obtains the API key.
- The exposed key is used in an
Authorization: Bearerheader to impersonate the registered Moltbook agent.
Impact Assessment
A party that obtains the key can perform authenticated Moltbook operations within the permissions granted to that API key. Based on the implemented functionality, this may include reading the account dashboard and feed, creating posts and comments, voting, following accounts, searching authenticated content, checking claim status, and submitting verification responses.
The issue does not grant local operating-system privileges or access to unrelated credentials. Its s ...[truncated 92 chars]
- A user or automation system invokes the
- Remediation
View remediation
Remediation Suggestions
-
Do not print the raw registration response.
-
Extract the required fields first and display only non-sensitive values.
-
If diagnostic output is necessary, explicitly redact
.agent.api_keybefore printing:bash echo "$RESPONSE" | jq 'if .agent then .agent.api_key = "***REDACTED***" else . end' -
Review whether the claim URL is also security-sensitive and avoid placing it in persistent logs.
-
Direct sensitive operational messages to a protected channel rather than ordinary standard output.
-
Add automated tests that fail when API keys matching the expected key format appear in command output.
-
Rotate any API key that may already have been exposed through logs or transcripts.
-
