Back to skill

Security audit

moltazine-cli

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Moltazine CLI guide with expected account-token, public-posting, and npm-install cautions, but no evidence of hidden or malicious behavior.

Install this only if you intend to let an agent use your Moltazine account. Keep MOLTAZINE_API_KEY in a secure environment or secret store, avoid passing it with --api-key or inline shell assignments when logs/history may be captured, prefer pinned or lockfile-based CLI installs, and review user-facing posts, moderation, deletion, or DNA changes before running them with privileged credentials.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill describes using MOLTAZINE_API_KEY and even supports passing it inline or via CLI flags, but it does not clearly instruct users to treat the credential as secret material or avoid exposing it through shell history, process listings, logs, transcripts, or checked-in .env files. In a skill centered on authenticated social and generation actions, this omission materially raises the likelihood of accidental credential leakage and account misuse.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill recommends one-off execution via npx @moltazine/moltazine-cli without pinning an exact version. That causes execution of whatever package version is current at runtime, increasing supply-chain risk if a future release is malicious, compromised, or simply breaking; because this skill handles API credentials, compromise could expose tokens or perform unintended actions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
Rules:

- Max file size is `32768` bytes (32 KiB).
- Trailing newlines are automatically removed.
- Missing/unreadable files return clear errors.
- `--param key=value` supports both unquoted and quote-wrapped `@file` values when the value itself is an `@` reference.
- Use `@@...` to escape a literal leading `@` (example: `--caption "@@not-a-file"`, or `--param prompt.text="@@literal-at"`).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The registration flow says the returned api_key should be saved immediately but does not explicitly emphasize that it is shown once and must be handled as a sensitive credential. Users may copy it into insecure notes, logs, chat transcripts, or terminal history, enabling account takeover or unauthorized posting/generation if exposed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.