Back to skill

Security audit

Moltbook Trust Engine

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it can directly use a wallet private key to spend ETH and publish irreversible reputation ratings without an internal confirmation step.

Review this carefully before installing. Use only a low-balance dedicated wallet, assume ratings and proof hashes are public and irreversible on Base, and do not rely on the proof metric as true verification of an interaction unless the implementation is strengthened.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
index.js:85
Finding

Forgeable Proof-of-Interaction Verification

Content
View full analysis
138) { const extraData = "0x" + tx.data.slice(138); if (extraData.length === 66) { verifiedCount++; } } ``` ```javascript // Strict check on Proof TX to prevent gas waste let appendData = ""; if (proofTx) { if (!ethers.isHexString(proofTx) || proofTx.length !== 66) { return "❌ Invalid Proof Transaction. Must be a 32-byte hash (0x + 64 chars)."; } appendData = proofTx.replace("0x", ""); console.log(`🔗 Attaching Proof: ${proofTx}`); } ``` The unvalidated value is subsequently appended directly to the rating transaction: ```javascript // Encode Function + Append Stashed Data let data = contract.interface.encodeFunctionData("logReputation", [agentId, score]); data = data + appendData; ``` ### Technical Analysis The implementation treats any 32-byte calldata suffix as a verified Proof of Interaction. Validation in `rate_agent` establishes only that `proofTx` is a correctly formatted hexadecimal value of the expected length. During auditing, the code similarly checks only that the appended data is 32 bytes long. The skill does not retrieve the referenced transaction or verify that: - The transaction hash corresponds to an existing transaction. - The referenced transaction completed successfully. - The reviewer was a participant in that transaction. - The rated agent or an identity associated with that agent was involved. - The transaction represents an interaction relevant to the reputation review. - The suffix was produced through the skill rather than manually crafted calldata. Consequently, an arbitrary 32-byte value, including a randomly generated value or an unrelated ...[truncated 1705 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
package.json:6
Finding

Non-Reproducible Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill's declared purpose frames it as analytics and trust management, but the detected behavior includes state-changing blockchain transactions, use of a wallet private key from environment variables, ETH spending, and local persistence. This mismatch is dangerous because users may invoke what appears to be a read-oriented reputation tool without realizing it can spend funds, use sensitive credentials, and write persistent data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill sends an on-chain transaction with ETH value directly through wallet.sendTransaction without any explicit confirmation step. Because blockchain transactions are irreversible and incur monetary cost, an unintended or manipulated invocation could spend funds and post reputation data immediately, which is especially dangerous for a skill marketed primarily as analytics/audit tooling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README encourages use of proofTx as a proof of interaction but does not clearly warn, at the point of use, that the referenced transaction hash is permanently published on-chain and linked to the review. This can create privacy and metadata-leak risks by exposing relationships, transaction history, or commercially sensitive interactions that users may not realize they are disclosing.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 70)May include surrounding context.

md
| `action`        | string | Yes      | `"trust"` to allowlist, `"block"` to blocklist       |
| `walletAddress` | string | Yes      | The wallet address to manage                         |

Adding a wallet to one list automatically removes it from the other.

## Usage

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares no explicit tool scope or permissions boundary, yet the analysis indicates access to environment-derived capabilities. In an agent setting, undeclared env access can expose secrets such as wallet keys or RPC credentials to code paths the user did not consent to, especially when the skill also interfaces with blockchain operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code loads WALLET_PRIVATE_KEY from environment variables and constructs a signing wallet capable of sending transactions. In an agent-skill context, this gives the skill direct spending authority, so any misuse, prompt injection, logic flaw, or unintended invocation can cause unauthorized on-chain actions using the operator's funds.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill accesses a private key with no user-facing disclosure that it can sign transactions on the user's behalf. In this context, silent signer access is especially risky because users may reasonably assume an 'audit' tool is read-only, while the skill can actually perform irreversible writes and spend funds.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as an analytics/audit engine but also includes a write-capable function that submits on-chain reputation transactions and transfers ETH. This creates a dangerous capability mismatch: a user or orchestrating agent may invoke what appears to be a read-oriented reputation tool and unintentionally trigger irreversible blockchain actions with financial cost.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file documents that the skill maintains a local JSON file containing trusted/blocklisted wallets and a log of the user's reviews, which is a user-data-affecting behavior. Although the storage is described, the skill's usage sections do not clearly warn users before invoking manage_peers or rate_agent that these actions will persist local state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill writes persistent local state to trust_memory.json without notifying the user. While not directly enabling remote code execution, it silently stores trust/block decisions and review history, which may expose behavioral data, create integrity issues if the file is tampered with, or surprise users in environments expecting stateless operation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency version for ethers is specified with a caret range (^6.10.0), which allows newer minor and patch releases to be installed automatically. This can introduce supply-chain risk and non-reproducible builds if a later published version contains a vulnerability, breaking change, or malicious compromise.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"description": "Reputation analytics and trust management for the Moltbook ecosystem.",
  "main": "index.js",
  "dependencies": {
    "ethers": "^6.10.0"
  },
  "keywords": ["trust", "reputation", "analytics", "moltbook", "base", "security"]
}

Static analysis

No suspicious patterns detected.