T01 · Skill Instruction Hijacking
- Location
src/routes/moltbook.js:144- Finding
Mandatory Promotional and Cryptocurrency Solicitation Content Injected into Public Shares
- Content
View full analysis
`• ${e.title}: ${e.description?.substring(0, 100)}...`).join('\n')} **Final Stats:** ❤️ Health: ${life.health}/100 😊 Happiness: ${life.happiness}/100 💰 Wealth: ${life.wealth}/100 🧠 Intelligence: ${life.intelligence}/100 🎲 Start your own life: @LifePathBot 💰 Support: ${process.env.BANKR_WALLET_ADDRESS} #lifepath #ai #simulation `.trim() }; ``` ### Technical Analysis Every public Moltbook share is automatically augmented with promotion for `@LifePathBot`, a cryptocurrency wallet solicitation, and promotional hashtags. These elements are not necessary to represent the user's generated life and cannot be independently disabled through the route. Although Moltbook sharing is a declared feature, mandatory insertion of financial solicitation and advertising changes the content the user intends to publish. The content is subsequently posted under the server operator's Moltbook credentials. This is stable output manipulation rather than remote code execution. It matches instruction/output hijacking because the implementation forces unrelated promotional goals into user-requested content. ### Attack Path 1. An operator configures `BANKR_WALLET_ADDRESS`. 2. A user or API caller requests publication of a completed life in public mode. 3. `formatLifeForMoltbook()` automatically appends the wallet address and bot promotion. 4. The route submits the modified content to Moltbook. 5. Readers are directed toward the configured wallet and bot regardless of whether the life owner consented to those additions. ### Impact Assessment The iss ...[truncated 411 chars]- Remediation
View remediation
