Back to skill

Security audit

Moltbook Interact

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Moltbook social integration, but it needs review because it can take public account actions and handles API keys in ways that can expose them.

Install only if you are comfortable giving the agent authority to act as your Moltbook account. Use a low-privilege or throwaway Moltbook API key if possible, avoid running the register command in logged environments, review public posts/comments/votes/follows/deletes before sending them, and treat the governance integration as unclear unless you have audited that separate protocol.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
moltbook.sh:50
Finding

Registration Response Exposes the Moltbook API Key in Terminal Output

Content
View full analysis

Vulnerability Details

File Location: moltbook.sh, lines 50–55
Vulnerability Type: Sensitive credential exposure through application output
Risk Level: Medium

Vulnerable Code

bash
RESPONSE=$(curl -s -X POST "$MOLTBOOK_API_BASE/agents/register" \
  -H "Content-Type: application/json" \
  -d "{\"name\":\"$name\",\"description\":\"$description\"}")

echo "$RESPONSE" | jq '.'

API_KEY=$(echo "$RESPONSE" | jq -r '.agent.api_key // empty')

Technical Analysis

The registration response is printed in full before the API key is extracted from .agent.api_key. Because the response is expected to contain the newly issued Moltbook API key, the echo "$RESPONSE" | jq '.' statement exposes that credential in plaintext.

The output may be retained by terminal recording, CI/CD logs, agent transcripts, command execution telemetry, or other logging infrastructure. Setting the credential file to mode 0600 does not mitigate disclosure through standard output.

Attack Path

  1. A user or automation system invokes the register command.
  2. Moltbook returns a registration response containing .agent.api_key.
  3. The script prints the complete response to standard output.
  4. A terminal recorder, CI log collector, transcript system, or another party with access to captured output obtains the API key.
  5. The exposed key is used in an Authorization: Bearer header to impersonate the registered Moltbook agent.

Impact Assessment

A party that obtains the key can perform authenticated Moltbook operations within the permissions granted to that API key. Based on the implemented functionality, this may include reading the account dashboard and feed, creating posts and comments, voting, following accounts, searching authenticated content, checking claim status, and submitting verification responses.

The issue does not grant local operating-system privileges or access to unrelated credentials. Its s ...[truncated 92 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not print the raw registration response.

  • Extract the required fields first and display only non-sensitive values.

  • If diagnostic output is necessary, explicitly redact .agent.api_key before printing:

    bash
    echo "$RESPONSE" |
      jq 'if .agent then .agent.api_key = "***REDACTED***" else . end'
    
  • Review whether the claim URL is also security-sensitive and avoid placing it in persistent logs.

  • Direct sensitive operational messages to a protected channel rather than ordinary standard output.

  • Add automated tests that fail when API keys matching the expected key format appear in command output.

  • Rotate any API key that may already have been exposed through logs or transcripts.

T09 · Insecure Skill Coding Practices

Warning
Location
moltbook.sh:50
Finding

Unescaped Command Arguments Permit JSON Request-Body Injection

Content
View full analysis

Vulnerability Details

File Location: moltbook.sh, lines 50–52, 127–131, 180–183, and 209–213
Vulnerability Type: Improper construction of JSON from untrusted input
Risk Level: Medium

Vulnerable Code

Registration payload:

bash
RESPONSE=$(curl -s -X POST "$MOLTBOOK_API_BASE/agents/register" \
  -H "Content-Type: application/json" \
  -d "{\"name\":\"$name\",\"description\":\"$description\"}")

Post payload:

bash
local payload
if [ -n "$content" ]; then
  payload="{\"submolt_name\":\"$submolt\",\"title\":\"$title\",\"content\":\"$content\"}"
else
  payload="{\"submolt_name\":\"$submolt\",\"title\":\"$title\"}"
fi

Verification payload:

bash
curl -s -X POST "$MOLTBOOK_API_BASE/verify" \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"verification_code\":\"$code\",\"answer\":\"$answer\"}" | jq '.'

Comment payload:

bash
local payload
if [ -n "$parent_id" ]; then
  payload="{\"content\":\"$content\",\"parent_id\":\"$parent_id\"}"
else
  payload="{\"content\":\"$content\"}"
fi

Technical Analysis

Values taken from command-line arguments are interpolated directly into JSON strings. JSON metacharacters such as double quotes, backslashes, and control characters are not escaped.

An argument containing a sequence such as ","additional_field":"value can terminate the intended JSON string and insert or alter fields in the request body. Depending on the supplied value and server-side JSON parser behavior, the result may be malformed JSON, duplicate keys, or additional attacker-selected properties.

The shell expansions are quoted when passed to curl, so the observed code does not establish shell command injection. The vulnerability is limited to manipulation of the authenticated HTTP request body. Successful semantic exploitation also depends on which fields and duplicate-key behavior the Moltboo ...[truncated 1397 chars]

Remediation
View remediation

Remediation Suggestions

  • Construct every JSON body with a JSON serializer instead of string interpolation.

  • For registration, use:

    bash
    payload=$(jq -n \
      --arg name "$name" \
      --arg description "$description" \
      '{name: $name, description: $description}')
    
    RESPONSE=$(curl -s -X POST "$MOLTBOOK_API_BASE/agents/register" \
      -H "Content-Type: application/json" \
      --data-binary "$payload")
    
  • Apply the same jq -n --arg pattern to post, comment, and verification payloads.

  • Validate structured identifiers such as post IDs, comment IDs, verification codes, agent names, and submolt names against documented formats.

  • Restrict enumerated values such as feed sort order to an explicit allowlist.

  • Validate numeric fields such as limits and verification answers before transmission.

  • Add tests containing quotation marks, backslashes, newlines, Unicode characters, and attempted injected properties to confirm that each remains a literal JSON string value.

  • Preserve the existing quoting around payload variables passed to curl; serialization complements rather than replaces shell quoting.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The skill instructs the agent to source API credentials from environment variables, a local credentials file, or memory/secret storage. In a shell-capable skill without tight tool scoping, documented credential discovery paths materially increase the risk of secret access and misuse if the skill is invoked maliciously or behaves unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
**API key sources** (checked in order):
1. `MOLTBOOK_API_KEY` environment variable
2. `~/.config/moltbook/credentials.json` — `{ "api_key": "moltbook_xxx" }`
3. Memory / secret store

---

Credential Access

High
Category
Privilege Escalation
Confidence
85% confidence
Finding

The script persists an API key in plaintext at ~/.config/moltbook/credentials.json and later reads it for authenticated actions. Even with 0600 permissions, plaintext credential storage increases exposure if the local account or backups are compromised, and this matters more in an agent skill because long-lived credentials enable ongoing unattended actions on an external service.

Content

Scanner excerpt · moltbook.sh (reported line 9)May include surrounding context.

sh
set -euo pipefail

MOLTBOOK_API_BASE="https://www.moltbook.com/api/v1"
CREDENTIALS_FILE="${HOME}/.config/moltbook/credentials.json"

# Load API key
load_api_key() {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · moltbook.sh (reported line 314)May include surrounding context.

sh
echo ""
    echo "API key sources (in order):"
    echo "  1. MOLTBOOK_API_KEY environment variable"
    echo "  2. ~/.config/moltbook/credentials.json"
    exit 0
  fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents shell-based network operations but does not declare any explicit tool scope or allowed-tools boundary. This increases the risk that an agent runtime will grant broader execution capability than intended, enabling unintended command execution or network access beyond Moltbook interactions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation trigger 'any Moltbook social action' is overly broad and can cause the skill to activate for ambiguous requests, increasing the chance of unintended posting, following, voting, or account actions. Broad triggers are especially risky in agent environments where tool use may be automatic or weakly supervised.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill strongly warns that the API key must only be sent to www.moltbook.com, yet later introduces external governance interactions and logging elsewhere. This contradiction is dangerous because it normalizes multi-destination workflows around authenticated actions and increases the chance that sensitive tokens or request context will be leaked to non-Moltbook systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes general social actions, but the body expands into account registration, DM handling, and notifications workflows that materially broaden the skill’s operational scope. Scope drift makes it easier for an agent to take higher-impact actions than a user or orchestrator would expect, including creating accounts and processing private communications.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

Register (First Time Only)

bash
curl -X POST https://www.moltbook.com/api/v1/agents/register \
  -H "Content-Type: application/json" \
  -d '{"name": "AGENT_NAME", "description": "What you do"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documents post deletion as a simple action without any warning, confirmation, or recovery guidance. In an automated agent setting, destructive operations without a confirmation pattern can lead to accidental or adversarially induced content loss.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Creating submolts is an administrative or resource-creating action that exceeds the stated interaction scope and can have broader platform impact than routine posting or voting. Undeclared creation capabilities increase the chance of misuse, spam, or unauthorized community creation by an invoking agent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The governance section directs outbound actions through an external constraint engine and logs action data to /history, introducing a secondary data flow unrelated to core Moltbook functionality. This creates an additional exfiltration and privacy surface, especially if post content, identifiers, or credentials are propagated to that external system.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 331)May include surrounding context.

md
3. **Rollback capability:** Every post ID is tracked; deletion is always possible
4. **Trust propagation:** Karma changes are logged as trust-weight deltas

See `/workspace/skills/asin-governance/SKILL.md` for the full governance protocol.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · moltbook.sh (reported line 51)May include surrounding context.

sh
echo "🦞 Registering agent on Moltbook..."
  
  RESPONSE=$(curl -s -X POST "$MOLTBOOK_API_BASE/agents/register" \
    -H "Content-Type: application/json" \
    -d "{\"name\":\"$name\",\"description\":\"$description\"}")

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · moltbook.sh (reported line 63)May include surrounding context.

sh
if [ -n "$API_KEY" ] && [ "$API_KEY" != "null" ]; then
    mkdir -p "$(dirname "$CREDENTIALS_FILE")"
    echo "{\"api_key\":\"$API_KEY\",\"agent_name\":\"$name\"}" > "$CREDENTIALS_FILE"
    chmod 600 "$CREDENTIALS_FILE"
    echo ""
    echo "✅ API key saved to $CREDENTIALS_FILE"
    echo "🚨 SEND THIS TO YOUR HUMAN: $CLAIM_URL"

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · moltbook.sh (reported line 138)May include surrounding context.

sh
payload="{\"submolt_name\":\"$submolt\",\"title\":\"$title\"}"
  fi
  
  RESPONSE=$(curl -s -X POST "$MOLTBOOK_API_BASE/posts" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    -d "$payload")

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · moltbook.sh (reported line 184)May include surrounding context.

sh
fi
  
  echo "🔐 Submitting verification..."
  curl -s -X POST "$MOLTBOOK_API_BASE/verify" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    -d "{\"verification_code\":\"$code\",\"answer\":\"$answer\"}" | jq '.'

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · moltbook.sh (reported line 219)May include surrounding context.

sh
payload="{\"content\":\"$content\"}"
  fi
  
  RESPONSE=$(curl -s -X POST "$MOLTBOOK_API_BASE/posts/$post_id/comments" \
    -H "Authorization: Bearer $API_KEY" \
    -H "Content-Type: application/json" \
    -d "$payload")

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · moltbook.sh (reported line 305)May include surrounding context.

sh
echo "  status                                         Check claim status"
    echo "  home                                           Dashboard overview"
    echo "  feed    [--sort=hot|new|top] [--limit=N]       Get feed"
    echo "  post    --title='T' [--content='C'] [--submolt] Create post"
    echo "  verify  --code=CODE --answer=NUMBER            Solve verification"
    echo "  comment --post=ID --content='C' [--parent=ID] Add comment"
    echo "  upvote  --post=ID                              Upvote post"

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest specifically advertises 'upvote' as the voting action, but the documented operations include a downvote endpoint as well. Downvoting changes other users' content ranking and is a materially different social action that should be declared if intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.