T09 · Insecure Skill Coding Practices
- Location
index.js:27- Finding
Implicit Use of a High-Privilege Deployment Private Key
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it claims, but it can spend wallet funds and publish permanent blockchain records without an explicit in-tool approval step.
Install only if you are comfortable giving this skill access to a dedicated, low-balance wallet. Do not expose a deployment, treasury, or main wallet key. Treat registry_register and registry_rate as real, irreversible blockchain actions that spend ETH plus gas and publish public records; review the transaction externally before use where possible.
index.js:27Implicit Use of a High-Privilege Deployment Private Key
index.js:113Paid Blockchain Transactions Lack Validation, Chain Verification, and Explicit Authorization Controls
package.json:6Dependency Installation Is Not Reproducible
The README instructs users to place a wallet private key in a plaintext environment file but does not warn that this secret grants direct control over on-chain identity actions and potentially associated funds. Environment files are commonly copied, logged, committed, or left with broad filesystem permissions, so normal user behavior can lead to credential exposure and account compromise.
Without declared permissions the skill's intent is opaque and cannot be validated.
The registration flow states that it 'burns $MREG' and requires a funded wallet, but it does not clearly foreground that registry_register performs a real on-chain state-changing transaction with irreversible token burn and gas expenditure. In an agent context, this can lead users or upstream agents to trigger a costly blockchain action without informed consent, making accidental asset loss more likely.
The skill directly loads a signing private key from environment variables and then uses it for privileged on-chain actions, but the exported interface gives no user-facing disclosure that invoking certain functions will access a hot wallet. In an agent-skill context, this is dangerous because callers may unknowingly trigger blockchain transactions using operator-controlled credentials, increasing the risk of unauthorized spending, key misuse, or accidental execution under a sensitive identity.
The register function sends a payable on-chain transaction immediately, using the environment-backed wallet and a hardcoded fee, without any confirmation prompt, preview, or explicit acknowledgement from the user. In a tool/agent environment, this can cause silent fund expenditure and irreversible blockchain state changes if the function is invoked by mistake, via prompt injection, or through ambiguous user intent.
The rate function broadcasts a payable transaction to log reputation using the loaded private key and fee without prior warning or confirmation. Although the direct fee is small, the action is still irreversible, spends funds, and can be abused to manipulate reputation records or trigger repeated charges through automated or adversarial invocation.
The dependency uses a caret version range, which allows newer minor/patch releases of ethers to be installed over time. This creates supply-chain risk because future upstream changes or a compromised release could alter behavior without this package being explicitly updated or re-reviewed.
"description": "Official Moltbook Identity Registry skill",
"main": "index.js",
"dependencies": {
"ethers": "^6.10.0",
"dotenv": "^16.4.1"
},
"keywords": ["ai", "agent", "registry", "erc8004", "base"]
The dotenv dependency is also specified with a caret range, permitting automatic drift to later compatible releases. Even for a common library, this weakens build reproducibility and increases exposure to malicious or breaking upstream publishes in the software supply chain.
"main": "index.js",
"dependencies": {
"ethers": "^6.10.0",
"dotenv": "^16.4.1"
},
"keywords": ["ai", "agent", "registry", "erc8004", "base"]
}
No suspicious patterns detected.