Back to skill

Security audit

Crustafarianism

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly discloses its Molt registration behavior, but it also stores an API key and includes an authenticated posting script that can send that key to an environment-controlled endpoint.

Review this skill before installing if you plan to join Molt or run its scripts. The join flow contacts molt.church, sends an agent name and verse, and stores an API key locally. Avoid running prophecy.sh with any MOLT_API_BASE override or inherited environment you do not trust, because it can send the stored bearer token to that endpoint. Treat ~/.config/molt/credentials.json as a secret and remove it if you no longer want the agent registered.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/prophecy.sh:3
Finding

Environment-Controlled API Endpoint Can Receive Stored Credentials

Content
View full analysis
/dev/null) ``` ### Technical Analysis The script reads the persistent bearer credential from `~/.config/molt/credentials.json` and sends it to the endpoint specified by `MOLT_API_BASE`. Because this environment variable is accepted without hostname validation, an HTTPS requirement, an allowlist, or user confirmation, any inherited environment value can determine the recipient of the credential. This exceeds the minimum privilege needed for authenticated prophecy submission. Endpoint overrides may be useful for testing, but production credentials should never automatically accompany requests to arbitrary test or third-party endpoints. ### Attack Path 1. A malicious wrapper, compromised launcher, shell configuration, or other process sets `MOLT_API_BASE` to an attacker-controlled URL. 2. A registere ...[truncated 853 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/join.sh:25
Finding

Dry-Run Mode Performs an Undisclosed Filesystem Write

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose presents the skill as theology/join-flow assistance, but the content also enables operational behaviors including remote registration, credential creation/storage, and later authenticated actions using the saved API key. This mismatch is dangerous because users and calling systems may grant trust appropriate for a harmless informational skill while it actually drives external side effects and privileged account lifecycle behavior.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill directs creation and storage of credentials in ~/.config/molt/credentials.json, establishing a local secret that can later be consumed by tooling or future actions. Even if intended for legitimate use, encouraging credential storage from within a broadly scoped skill increases secret exposure risk, especially in multi-skill or shared environments where local files may be accessible to other components.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

bash scripts/join.sh

text

Credentials are saved to `~/.config/molt/credentials.json`.

Optional local persistence is disabled by default. Enable it only if you intentionally want workspace changes:

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The transparency section confirms the join script always posts data to an external service and saves an API key locally, which is a concrete credential-handling behavior rather than merely descriptive theology. Persisted API keys can be stolen, misused for unauthorized submissions, or unintentionally reused by later workflows, making this a real secret-management risk.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
**What the join script always does:**
- POST your agent name and verse to `https://molt.church/api/join`
- Save your API key to `~/.config/molt/credentials.json`

**What the join script only does with explicit opt-in flags:**
- Write `faith.md` to your workspace when `MOLT_WRITE_FAITH=1` (Tenets, your verse, API key path — a standalone file, does not touch `SOUL.md`)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The script explicitly states it will save an API key to a local credentials file. Persisting newly issued credentials on disk is security-sensitive because it creates a reusable secret that can later be abused by other local processes, compromised agents, or users with filesystem access.

Content

Scanner excerpt · scripts/join.sh (reported line 9)May include surrounding context.

sh
#
# What this script ALWAYS does (unless --dry-run):
#   1. POST agent name + verse to https://molt.church/api/join
#   2. Save API key to ~/.config/molt/credentials.json
#
# What this script ONLY does when opted in:
#   MOLT_WRITE_FAITH=1   → writes faith.md (standalone file, never touches SOUL.md)

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The script extracts an API key from the server response and writes it into ~/.config/molt/credentials.json. Storing bearer-style credentials in a plaintext file, even with restrictive permissions, introduces local secret persistence risk and broadens the blast radius of any local compromise.

Content

Scanner excerpt · scripts/join.sh (reported line 161)May include surrounding context.

sh
API_KEY=$(echo "$RESPONSE" | grep -o '"api_key":"[^"]*"' | sed 's/"api_key":"\([^"]*\)"/\1/')
    
    if [ -n "$API_KEY" ]; then
        cat > "$CONFIG_DIR/credentials.json" << EOF
{
    "api_key": "$API_KEY",
    "agent_name": "$AGENT_NAME",

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The script accesses a local credentials file and extracts an API key for authenticated requests. Credential access is sensitive by itself; in this context it enables account-affecting external actions, so any misuse of the script or repurposing of the skill could result in unauthorized actions under the user’s identity.

Content

Scanner excerpt · scripts/prophecy.sh (reported line 5)May include surrounding context.

sh
# Church of Molt — Submit Prophecy (Prophets only)

API_BASE="${MOLT_API_BASE:-https://molt.church}"
CONFIG_FILE="$HOME/.config/molt/credentials.json"

# JSON-safe string escaping (prevents injection)
json_escape() {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/join.sh (reported line 115)May include surrounding context.

sh
echo ""

# Check local credentials
CONFIG_FILE="$HOME/.config/molt/credentials.json"
if [ -f "$CONFIG_FILE" ]; then
    echo "Your credentials: $CONFIG_FILE"
    AGENT=$(cat "$CONFIG_FILE" | grep -o '"agent_name":"[^"]*"' | sed 's/"agent_name":"\([^"]*\)"/\1/')

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/join.sh (reported line 168)May include surrounding context.

sh
echo ""

# Check local credentials
CONFIG_FILE="$HOME/.config/molt/credentials.json"
if [ -f "$CONFIG_FILE" ]; then
    echo "Your credentials: $CONFIG_FILE"
    AGENT=$(cat "$CONFIG_FILE" | grep -o '"agent_name":"[^"]*"' | sed 's/"agent_name":"\([^"]*\)"/\1/')

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/join.sh (reported line 169)May include surrounding context.

sh
echo ""

# Check local credentials
CONFIG_FILE="$HOME/.config/molt/credentials.json"
if [ -f "$CONFIG_FILE" ]; then
    echo "Your credentials: $CONFIG_FILE"
    AGENT=$(cat "$CONFIG_FILE" | grep -o '"agent_name":"[^"]*"' | sed 's/"agent_name":"\([^"]*\)"/\1/')

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/join.sh (reported line 198)May include surrounding context.

sh
echo ""

# Check local credentials
CONFIG_FILE="$HOME/.config/molt/credentials.json"
if [ -f "$CONFIG_FILE" ]; then
    echo "Your credentials: $CONFIG_FILE"
    AGENT=$(cat "$CONFIG_FILE" | grep -o '"agent_name":"[^"]*"' | sed 's/"agent_name":"\([^"]*\)"/\1/')

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/join.sh (reported line 227)May include surrounding context.

sh
echo ""

# Check local credentials
CONFIG_FILE="$HOME/.config/molt/credentials.json"
if [ -f "$CONFIG_FILE" ]; then
    echo "Your credentials: $CONFIG_FILE"
    AGENT=$(cat "$CONFIG_FILE" | grep -o '"agent_name":"[^"]*"' | sed 's/"agent_name":"\([^"]*\)"/\1/')

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/status.sh (reported line 25)May include surrounding context.

sh
echo ""

# Check local credentials
CONFIG_FILE="$HOME/.config/molt/credentials.json"
if [ -f "$CONFIG_FILE" ]; then
    echo "Your credentials: $CONFIG_FILE"
    AGENT=$(cat "$CONFIG_FILE" | grep -o '"agent_name":"[^"]*"' | sed 's/"agent_name":"\([^"]*\)"/\1/')

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to execute shell commands (bash scripts/join.sh) but does not declare any tool scope or allowed-tools restrictions. This creates an authorization gap where a seemingly informational skill can invoke code execution without explicit capability boundaries, increasing the chance of unintended or over-privileged action.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The skill references npx clawhub install crustafarianism without pinning a version, which can cause retrieval of changing code over time. Unpinned package execution exposes users to supply-chain risk if the package is updated maliciously, compromised, or simply changes behavior unexpectedly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
87% confidence
Finding

The optional flags write faith.md and memory/molt-initiation.md, creating persistent artifacts in the workspace and memory-like directories. While gated behind opt-in flags, this still introduces session persistence that can influence future agent behavior, leak context, or create durable state in environments that expect temporary interactions.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

Optional local persistence is disabled by default. Enable it only if you intentionally want workspace changes:

bash
# Also write faith.md to your workspace (Tenets + your verse + API key path)
MOLT_WRITE_FAITH=1 bash scripts/join.sh

# Also write memory/molt-initiation.md

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script tells users to set MOLT_UPDATE_SOUL=1 to enable local workspace changes, but the actual implemented flags are MOLT_WRITE_FAITH and MOLT_WRITE_MEMORY. This inconsistency can mislead operators about what the script will modify and weakens informed consent around filesystem writes, which is security-relevant for agent skills that claim opt-in persistence.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

The script transmits agent-derived data, including name, verse, referral code, and a proof value, to an external service by default when not in dry-run mode. In the context of an agent skill, silent outbound registration and data exfiltration to a third-party domain is a real security concern, especially because API_BASE can be overridden to any host via environment variable.

Content

Scanner excerpt · scripts/join.sh (reported line 152)May include surrounding context.

sh
REF_JSON=", \"ref\": \"$SAFE_REF\""
fi

RESPONSE=$(curl -s -X POST "$API_BASE/api/join" \
    -H "Content-Type: application/json" \
    -d "{\"name\": \"$SAFE_NAME\", \"description\": \"Devout Crustafarian\", \"prophecy\": \"$SAFE_VERSE\", \"proof\": \"$SAFE_PROOF\"$REF_JSON}" 2>/dev/null)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/join.sh (reported line 168)May include surrounding context.

sh
"joined_at": "$(date -u +%Y-%m-%dT%H:%M:%SZ)"
}
EOF
        chmod 600 "$CONFIG_DIR/credentials.json"
        echo -e "${MOLT_GREEN}✓${MOLT_RESET} Credentials saved to $CONFIG_DIR/credentials.json"
    fi

Session Persistence

Medium
Category
Rogue Agent
Confidence
94% confidence
Finding

When MOLT_WRITE_MEMORY=1 is set, the script creates a persistent memory artifact in the workspace containing affiliation and user-/agent-derived text. In an agent environment, writing durable memory can influence future behavior, leak contextual information, or create unauthorized state changes, even if nominally opt-in.

Content

Scanner excerpt · scripts/join.sh (reported line 209)May include surrounding context.

sh
fi

    if [ "$WRITE_MEMORY" = "1" ]; then
        mkdir -p "$WORKSPACE/memory"
        cat > "$WORKSPACE/memory/molt-initiation.md" << MEMORY
# Molt Initiation — $(date -u +%Y-%m-%d)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script reads stored credentials and uses them to publish content on behalf of the user, even though authenticated publication is not justified by the stated skill purpose. In an agent setting, unjustified authenticated actions increase the risk of unauthorized account activity and misleading users about what the skill can do.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This script performs an authenticated POST to an external Molt endpoint to publish user-supplied prophecy, which exceeds the skill’s declared scope of exploring beliefs or optionally joining the service. Scope mismatch is security-relevant because users and hosting agents may grant the skill more trust than they would for a content-publication capability.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The script transmits user-provided content and a bearer token to an external service via curl. While external transmission is expected for some integrations, it is dangerous here because it is a write action to a third-party service and is not clearly aligned with the declared skill scope, creating risk of unintended data disclosure or unauthorized posting.

Content

Scanner excerpt · scripts/prophecy.sh (reported line 33)May include surrounding context.

sh
echo ""

SAFE_CONTENT=$(json_escape "$1")
RESPONSE=$(curl -s -X POST "$API_BASE/api/prophecy" \
    -H "Content-Type: application/json" \
    -H "Authorization: Bearer $API_KEY" \
    -d "{\"scripture_type\": \"prophecy\", \"content\": \"$SAFE_CONTENT\"}" 2>/dev/null)

Static analysis

No suspicious patterns detected.