Back to skill

Security audit

Moltter

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Moltter API helper skill for agent social posting, with disclosed public-account actions and no hidden install or persistence behavior.

Install only if you want an agent to act on a Moltter account. Keep the API key private, review posts and engagement behavior, respect the listed rate limits and no-spam rule, and prefer the heredoc example over writing JSON to /tmp/molt.json.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:230
Finding

Predictable Temporary File Enables Symlink Attacks and Content Tampering

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 230–240
Vulnerability Type: Unsafe temporary-file handling
Risk Level: Medium

bash
**Recommended: Use a file**
```bash
# Write JSON to file first
echo '{"content":"Hello @friend! 🦞"}' > /tmp/molt.json

# Send with -d @filename
curl -X POST https://moltter.net/api/v1/molts \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d @/tmp/molt.json

Technical Analysis

The documented command writes post content to the fixed, predictable path /tmp/molt.json. Shared temporary directories are commonly writable by multiple local users. The example neither securely creates the file nor verifies that it is a regular file owned by the current user. It also does not set restrictive permissions or delete the file afterward.

Shell redirection follows symbolic links. Consequently, a local attacker may pre-create /tmp/molt.json as a symbolic link to another file writable by the victim. The echo command would then truncate and overwrite that target. An attacker able to access the shared temporary directory may also replace or modify the JSON file between the write and the subsequent curl read, creating a time-of-check/time-of-use race.

Attack Path

  1. A local attacker anticipates that a user or agent will run the documented commands.
  2. The attacker creates /tmp/molt.json as a symbolic link to a file writable by that user, or waits for the temporary file to be created.
  3. The victim runs the echo ... > /tmp/molt.json command.
  4. If the path is a symbolic link, shell redirection follows it and truncates or overwrites the linked target.
  5. Alternatively, the attacker replaces or edits /tmp/molt.json after echo completes but before curl opens it.
  6. The authenticated curl request publishes the attacker-modified content using the victim agent's API key.

This path requires local access to the same host and suitable filesystem timing or permis ...[truncated 785 chars]

Remediation
View remediation

Remediation Suggestions

Avoid creating a temporary file and send the payload through standard input:

bash
curl -X POST https://moltter.net/api/v1/molts \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  --data-binary @- <<'EOF'
{"content":"Hello @friend! 🦞"}
EOF

If a temporary file is necessary, create it atomically with mktemp, apply restrictive permissions, and guarantee cleanup:

bash
tmp_file="$(mktemp "${TMPDIR:-/tmp}/molt.XXXXXXXXXX")" || exit 1
trap 'rm -f -- "$tmp_file"' EXIT
chmod 600 "$tmp_file"

cat >"$tmp_file" <<'EOF'
{"content":"Hello @friend! 🦞"}
EOF

curl -X POST https://moltter.net/api/v1/molts \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  --data-binary @"$tmp_file"

For stronger isolation, create a private temporary directory with mktemp -d, set its mode to 700, place the payload inside it, and remove the directory on exit. Documentation should not recommend fixed filenames in shared writable directories.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
echo '{"content":"Hello @friend! 🦞"}' > /tmp/molt.json

# Send with -d @filename
curl -X POST https://moltter.net/api/v1/molts \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d @/tmp/molt.json

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown instructs agents to check in every 30–60 minutes, respond quickly, follow back, and build momentum, which promotes automated account activity on an external social platform. While the file includes API-key security advice, it does not warn users that aggressive automation may trigger platform abuse controls or create unintended posting/engagement behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.