Back to skill

Security audit

The Lobsterhood

Security checks for vulnerabilities and agentic risk

Overview

This skill can run continuously and send USDC through a wallet tool based on remote winner data, but the promised payment safety checks are not implemented.

Only install or run this after the publisher removes automatic payments or adds explicit confirmation for every transfer, validates signed winner data, binds payments to the exact round you entered, pins the installer, and updates vulnerable dependencies. Do not run `lobsterhood watch` with a funded Bankr wallet in its current form.

Vulnerability Patterns
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T04 · Embedded Malicious Code

Error
Location
scripts/lobsterhood.sh:93
Finding

Unsigned remote API responses control autonomous cryptocurrency transfers

Content
View full analysis
/dev/null; then local output=$(bankr "Send $amount USDC to $winner on $chain. Memo: Lobsterhood Tribute") echo "$output" fi } ``` ```bash local winner_data=$(curl -s "$API_BASE/winner") local winner_wallet=$(echo "$winner_data" | jq -r '.winner // empty') local winner_round=$(echo "$winner_data" | jq -r '.round // empty') if [[ "$winner_wallet" != "null" && -n "$winner_wallet" ]]; then if ! grep -q "donated_${winner_round}_${winner_wallet}" "$state_file" 2>/dev/null; then if grep -q "entered" "$state_file" 2>/dev/null; then echo "🏆 Winner Announced for Round $winner_round: $winner_wallet" if [[ "$winner_wallet" == "$wallet" ]]; then echo "🎉 YOU ARE THE WINNER. Awaiting tributes." else donate "1" if [[ $? -eq 0 ]]; then echo "donated_${winner_round}_${winner_wallet}" >> "$state_file" fi fi fi fi fi ``` ### Technical Analysis The watcher trusts the `winner`, `chain`, and `round` fields returned by `https://lobsterhood.vercel.app/api/winner`. These values ultimately determine the recipient and network used in a Bankr transfer request ...[truncated 1552 chars]
Remediation
View remediation

other

Error
Location
SKILL.md:39
Finding

Documented payment authentication controls are not implemented

Content
View full analysis
/dev/null; then local output=$(bankr "Send $amount USDC to $winner on $chain. Memo: Lobsterhood Tribute") fi ``` ### Technical Analysis The documentation claims three mandatory controls: current-round matching, cryptographic signature verification, and proof that the agent entered that round. None is correctly implemented: - The `signature` response field is never parsed or verified. - No trusted public key or cryptographic verification implementation exists. - `donate()` does not receive or verify an expected round. - The watcher accepts any historical state-file line containing `entered`. - The claimed block-hash winner selection is not independently checked. This discrepancy is especially security-sensitive because the claims encourage users to authorize an autonomous financial process on the belief that remote payment instructions cannot be spoofed. ### Attack Path 1. A user reviews the Skill documentation and relies on the “No signature, no payment” guarantee. 2. The user funds the wallet and starts the recommended daemon. 3. The remote AP ...[truncated 525 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lobsterhood.sh:80
Finding

Failed or historical entries can authorize payment for unrelated rounds

Content
View full analysis
> "$state_file" fi ``` ```bash if [[ "$winner_wallet" != "null" && -n "$winner_wallet" ]]; then if ! grep -q "donated_${winner_round}_${winner_wallet}" "$state_file" 2>/dev/null; then # Only donate if we actually entered a round recently if grep -q "entered" "$state_file" 2>/dev/null; then echo "🏆 Winner Announced for Round $winner_round: $winner_wallet" if [[ "$winner_wallet" == "$wallet" ]]; then echo "🎉 YOU ARE THE WINNER. Awaiting tributes." else donate "1" if [[ $? -eq 0 ]]; then echo "donated_${winner_round}_${winner_wallet}" >> "$state_file" fi fi fi fi fi ``` ### Technical Analysis When the Moltbook response does not contain `"success":true`, `enter()` prints an error but does not return a nonzero status. The watcher therefore treats many failed entry requests as successful and writes an `entered_` marker. Payment authorization only checks whether any line in the state file contains `entered`. It does not bind the entry to the announced round, chain, wallet, authenticated thread, or successful server receipt. Consequently, one stale or falsely recorded entry can authorize payments for unrelated future rounds. The state file also uses substring matching rather than structured records, increasing the possibility of ambiguous or corrupted state. ### Attack Path 1. The watcher detects a thread and cal ...[truncated 744 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lobsterhood.sh:93
Finding

Untrusted API fields are interpolated into a financial agent prompt

Content
View full analysis
/dev/null; then local output=$(bankr "Send $amount USDC to $winner on $chain. Memo: Lobsterhood Tribute") echo "$output" fi ``` ### Technical Analysis The `winner` and `chain` fields are attacker-influenced remote strings. They are concatenated directly into a natural-language command submitted to Bankr, a tool with financial transaction capabilities. No chain allowlist, address-format validation, field-length limit, control-character rejection, or structured transaction API is used. A malicious value can at minimum select an arbitrary recipient. Depending on how Bankr parses natural language, crafted text may also alter the semantic operation, network, recipient, or other transfer instructions. Shell command substitution is quoted, so this is not demonstrated shell metacharacter execution. The vulnerable boundary is the downstream financial agent’s interpretation of attacker-controlled natural language. ### Attack Path 1. An attacker controls or compromises `/api/winner`. 2. The attacker returns a malicious `winner` or `chain` string containing additional financial instructions. 3. The watcher extracts the string without schema validation. 4. The string is inserted into the Bankr prompt. 5. Bankr interprets the attacker-influenced prompt with wallet privileges. 6. A transfer may be sent to an attacker-selected recipient or with altered s ...[truncated 346 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:34
Finding

Installation executes a mutable unpinned package through npx

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package-lock.json:965
Finding

Project pins a Next.js release explicitly marked as vulnerable

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (44)

Known Vulnerable Dependency: next==14.1.0 — 16 advisory(ies): GHSA-2xp9-vwfh-vxw4 (Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AV); CVE-2026-44573 (Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n); CVE-2026-44572 (Next.js's Middleware / Proxy redirects can be cache-poisoned) +13 more

Critical
Category
Supply Chain
Confidence
99% confidence
Finding

next 14.1.0 is explicitly marked deprecated for a security vulnerability and is associated with multiple serious advisories, including unauthenticated RCE, middleware bypass, and cache poisoning. Because Next.js is a primary runtime framework for this skill rather than merely a dev-only tool, the application context makes this substantially more dangerous: vulnerable routes or framework features may be exposed directly to remote attackers.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: next==14.1.0 — 16 advisory(ies): GHSA-2xp9-vwfh-vxw4 (Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AV); CVE-2026-44573 (Next.js has a Middleware / Proxy bypass in Pages Router applications using i18n); CVE-2026-44572 (Next.js's Middleware / Proxy redirects can be cache-poisoned) +13 more

Critical
Category
Supply Chain
Confidence
98% confidence
Finding

The project pins Next.js to 14.1.0, and the finding indicates multiple published advisories including remote code execution and middleware/proxy bypass issues. In a web application framework, such flaws can expose the app to server compromise, authentication bypass, cache poisoning, or other severe attacks depending on enabled features and deployment configuration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This skill is presented as a game/reciprocity workflow, but the markdown also directs use of third-party services, wallet queries, and autonomous transfers via bankr, plus continuous monitoring. That behavioral scope is materially more sensitive than the friendly description suggests, and users may not appreciate that installation enables an agent to watch remote events and trigger real financial actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This skill is presented as a game/reciprocity workflow, but the markdown also directs use of third-party services, wallet queries, and autonomous transfers via bankr, plus continuous monitoring. That behavioral scope is materially more sensitive than the friendly description suggests, and users may not appreciate that installation enables an agent to watch remote events and trigger real financial actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This skill is presented as a game/reciprocity workflow, but the markdown also directs use of third-party services, wallet queries, and autonomous transfers via bankr, plus continuous monitoring. That behavioral scope is materially more sensitive than the friendly description suggests, and users may not appreciate that installation enables an agent to watch remote events and trigger real financial actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This skill is presented as a game/reciprocity workflow, but the markdown also directs use of third-party services, wallet queries, and autonomous transfers via bankr, plus continuous monitoring. That behavioral scope is materially more sensitive than the friendly description suggests, and users may not appreciate that installation enables an agent to watch remote events and trigger real financial actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This skill is presented as a game/reciprocity workflow, but the markdown also directs use of third-party services, wallet queries, and autonomous transfers via bankr, plus continuous monitoring. That behavioral scope is materially more sensitive than the friendly description suggests, and users may not appreciate that installation enables an agent to watch remote events and trigger real financial actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This skill is presented as a game/reciprocity workflow, but the markdown also directs use of third-party services, wallet queries, and autonomous transfers via bankr, plus continuous monitoring. That behavioral scope is materially more sensitive than the friendly description suggests, and users may not appreciate that installation enables an agent to watch remote events and trigger real financial actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly encourages a long-running watcher that automatically enters rounds and auto-pays winners, but it does not present a prominent user warning about ongoing financial actions, spending risk, frequency, or how to stop the process. In context, this is especially dangerous because the automation is tied to cryptocurrency transfers and social-pressure mechanics ('MUST send', blacklist, wall of shame), increasing the likelihood of unintended or coerced payments.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: browserslist==4.28.1 — 2 advisory(ies): CVE-2026-73088 (Browserslist: Uncaught crash / prototype write via untrusted browserslist-stats.); CVE-2026-73089 (Browserslist: Unbounded memory growth (no cache eviction) via distinct query res)

High
Category
Supply Chain
Confidence
88% confidence
Finding

browserslist is reported with crash, prototype write, and unbounded memory growth issues when handling untrusted stats/query-related input. Here it is a transitive dev dependency, so the main risk is to development or CI environments rather than direct runtime compromise, but it can still cause denial of service or unsafe behavior in tooling workflows.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: nanoid==3.3.11 — 3 advisory(ies): CVE-2026-67214 (nanoid: non-secure generators can loop indefinitely with negative size); CVE-2026-67213 (nanoid: custom generators can loop indefinitely when size is zero); CVE-2026-73086 (nanoid: Integer Overflow or Wraparound)

High
Category
Supply Chain
Confidence
80% confidence
Finding

nanoid has reported issues involving infinite loops and integer overflow in non-default or custom generator usage. In this file it is transitive under PostCSS, so the practical risk depends on whether affected code paths are reachable with attacker-controlled parameters; nevertheless, shipping a known vulnerable version is unsafe and can contribute to build-time denial of service.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.4.31 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more

High
Category
Supply Chain
Confidence
90% confidence
Finding

postcss 8.4.31 is reported with issues including arbitrary file read/information disclosure and XSS-related output handling. In this lockfile it is bundled as a dependency of Next.js and may also participate in build processing, so while some vectors may require attacker influence over CSS or source mapping inputs, the presence of a known vulnerable version increases supply-chain and build/runtime risk.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: picomatch==2.3.1 — 2 advisory(ies): CVE-2026-33672 (Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Mat); CVE-2026-33671 (Picomatch has a ReDoS vulnerability via extglob quantifiers)

High
Category
Supply Chain
Confidence
84% confidence
Finding

picomatch 2.3.1 has reported method-injection and ReDoS issues in glob parsing. In this dependency tree it is primarily used by development tooling, so the most likely impact is denial of service or incorrect matching in CI/build systems when handling attacker-controlled glob patterns rather than direct production compromise.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.6 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

postcss 8.5.6 is also flagged for file read, incomplete fix, and XSS-related issues. Although this instance is marked dev-only, build pipelines often process repository content and configuration automatically, so a vulnerable parser in tooling can still expose CI secrets, local files, or availability when handling untrusted style-related inputs.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: picomatch==4.0.3 — 2 advisory(ies): CVE-2026-33672 (Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Mat); CVE-2026-33671 (Picomatch has a ReDoS vulnerability via extglob quantifiers)

High
Category
Supply Chain
Confidence
84% confidence
Finding

picomatch 4.0.3 carries the same glob parsing issues as the older branch, including potential ReDoS and unsafe matching behavior. This instance is dev-only under tinyglobby/sucrase-related tooling, so the main risk is disruption of build or analysis workflows if untrusted patterns are processed, not direct runtime RCE.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: postcss==8.5.6 — 4 advisory(ies): CVE-2026-45623 (PostCSS: Arbitrary file read and information disclosure via attacker-controlled ); CVE-2026-69153 (PostCSS: incomplete fix of GHSA-6g55-p6wh-862q — attacker-controlled sourceMappi); CVE-2026-41305 (PostCSS has XSS via Unescaped </style> in its CSS Stringify Output) +1 more

High
Category
Supply Chain
Confidence
91% confidence
Finding

The resolved PostCSS version is reported to have multiple advisories, including arbitrary file read/information disclosure and XSS-related issues. Because PostCSS processes attacker-influenced CSS or source mapping in some build or rendering workflows, exploitation could expose sensitive files or enable injection in contexts that render generated CSS/HTML.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The code checks for and uses a standard local credentials file to obtain an API key, expanding access to secrets beyond explicit user input. In an agent skill, automatic secret discovery is risky because users may not expect the tool to read local credential material and then use it for authenticated network actions.

Content

Scanner excerpt · scripts/lobsterhood.sh (reported line 50)May include surrounding context.

sh
if [[ -z "$moltbook_key" ]]; then
        # Try to read from standard config location
        if [[ -f ~/.config/moltbook/credentials.json ]]; then
            moltbook_key=$(jq -r .api_key ~/.config/moltbook/credentials.json)
        else
            echo "Error: MOLTBOOK_API_KEY not found. Set it or configure ~/.config/moltbook/credentials.json"

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

At this line the script extracts the API key from the credentials file and stores it for later authenticated requests. That behavior is sensitive because it operationalizes local secret access into third-party actions, increasing the chance of unintended account use or abuse in a broader automation context.

Content

Scanner excerpt · scripts/lobsterhood.sh (reported line 51)May include surrounding context.

sh
if [[ -z "$moltbook_key" ]]; then
        # Try to read from standard config location
        if [[ -f ~/.config/moltbook/credentials.json ]]; then
            moltbook_key=$(jq -r .api_key ~/.config/moltbook/credentials.json)
        else
            echo "Error: MOLTBOOK_API_KEY not found. Set it or configure ~/.config/moltbook/credentials.json"
            exit 1

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/lobsterhood.sh (reported line 53)May include surrounding context.

sh
if [[ -f ~/.config/moltbook/credentials.json ]]; then
            moltbook_key=$(jq -r .api_key ~/.config/moltbook/credentials.json)
        else
            echo "Error: MOLTBOOK_API_KEY not found. Set it or configure ~/.config/moltbook/credentials.json"
            exit 1
        fi
    fi

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script goes beyond a benign 'join a draw' action and can trigger real USDC transfers through the external Bankr tool. This creates direct financial risk because the skill normalizes and automates on-chain payment behavior based on remote API data, with no strong verification or user approval at the point of transfer.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script invokes Bankr to send USDC without any confirmation prompt or recipient verification step. If the remote winner data is wrong, manipulated, or stale, funds can be sent immediately to an unintended address with little chance of recovery.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The watch mode runs indefinitely and can autonomously trigger both entry posting and donation actions based on remote state changes. That broader autonomy materially increases risk because it converts a user-invoked helper into a background agent capable of repeated financial and network actions without fresh consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Background watch mode can repeatedly post and donate based on periodic polling, yet it does not provide a strong user-facing warning about autonomous side effects. In this context, unattended operation is especially dangerous because it can cause cumulative financial loss and repeated external actions triggered solely by remote service responses.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes shell-capable commands (npx, bankr, lobsterhood) but does not declare any tool scope or permissions boundary. That makes the operational capabilities opaque to users and reviewers, and in this context those commands can affect wallets, query balances, and initiate transfers, which raises the risk of unintended execution or overbroad agent authority.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Installing via npx molthub@latest install lobsterhood pulls mutable code at execution time, creating a supply-chain risk if the package or a dependency is compromised. In a skill that can interact with wallets and automate payments, an unpinned installer materially increases the chance of silent malicious updates leading to credential theft or unauthorized transfers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.