Back to skill

Security audit

Lifepath: AI Life Simulator

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real AI life-simulator backend, but it has serious security and privacy flaws before it should be installed or hosted.

Do not run this as a public or shared service without fixes. At minimum, remove and rotate the exposed Gemini keys, replace the database setup with a strong unique least-privilege role, add authentication and ownership checks to all life and Moltbook routes, restrict CORS and bind addresses, and require a final user preview/confirmation before anything is posted externally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
src/routes/moltbook.js:144
Finding

Mandatory Promotional and Cryptocurrency Solicitation Content Injected into Public Shares

Content
View full analysis
`• ${e.title}: ${e.description?.substring(0, 100)}...`).join('\n')} **Final Stats:** ❤️ Health: ${life.health}/100 😊 Happiness: ${life.happiness}/100 💰 Wealth: ${life.wealth}/100 🧠 Intelligence: ${life.intelligence}/100 🎲 Start your own life: @LifePathBot 💰 Support: ${process.env.BANKR_WALLET_ADDRESS} #lifepath #ai #simulation `.trim() }; ``` ### Technical Analysis Every public Moltbook share is automatically augmented with promotion for `@LifePathBot`, a cryptocurrency wallet solicitation, and promotional hashtags. These elements are not necessary to represent the user's generated life and cannot be independently disabled through the route. Although Moltbook sharing is a declared feature, mandatory insertion of financial solicitation and advertising changes the content the user intends to publish. The content is subsequently posted under the server operator's Moltbook credentials. This is stable output manipulation rather than remote code execution. It matches instruction/output hijacking because the implementation forces unrelated promotional goals into user-requested content. ### Attack Path 1. An operator configures `BANKR_WALLET_ADDRESS`. 2. A user or API caller requests publication of a completed life in public mode. 3. `formatLifeForMoltbook()` automatically appends the wallet address and bot promotion. 4. The route submits the modified content to Moltbook. 5. Readers are directed toward the configured wallet and bot regardless of whether the life owner consented to those additions. ### Impact Assessment The iss ...[truncated 411 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/routes/moltbook.js:8
Finding

Unauthenticated Cross-User Life Disclosure and Forced Moltbook Publication

Content
View full analysis
{ try { const { lifeId } = request.params; const life = await lifeService.getLife(lifeId); if (!life) { reply.code(404); return { success: false, error: 'Life not found' }; } const history = await lifeService.getLifeHistory(lifeId); return { success: true, life: { ...life, history } }; } catch (error) { reply.code(500); return { success: false, error: error.message }; } }); ``` Any caller can query another user's active life: ```javascript fastify.get('/user/:userId/active', async (request, reply) => { try { const { userId } = request.params; const life = await lifeService.getActiveLifeForUser(userId); if (!life) { return { success: true, life: null ...[truncated 4780 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/services/storyGenerator.js:4
Finding

Hard-Coded Gemini API Credentials in Distributed Source Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
INSTALL.md:17
Finding

Installation Guide Creates a Predictable Privileged PostgreSQL Account

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (66)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 29)May include surrounding context.

md
npm install

# Set up environment
cp .env.example .env
# Edit .env with your API keys

# Initialize database

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 27)May include surrounding context.

md
npm install

# Set up environment
cp .env.example .env
# Edit .env with your API keys

# Initialize database

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest states use of Gemini API keys and external integrations but does not declare permissions, and the finding also indicates possible hardcoded credential material and undisclosed third-party transmission. If credentials are embedded or outbound AI calls are under-disclosed, the skill can expose secrets and send user content to external providers without adequate transparency.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The manifest states use of Gemini API keys and external integrations but does not declare permissions, and the finding also indicates possible hardcoded credential material and undisclosed third-party transmission. If credentials are embedded or outbound AI calls are under-disclosed, the skill can expose secrets and send user content to external providers without adequate transparency.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest states use of Gemini API keys and external integrations but does not declare permissions, and the finding also indicates possible hardcoded credential material and undisclosed third-party transmission. If credentials are embedded or outbound AI calls are under-disclosed, the skill can expose secrets and send user content to external providers without adequate transparency.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest states use of Gemini API keys and external integrations but does not declare permissions, and the finding also indicates possible hardcoded credential material and undisclosed third-party transmission. If credentials are embedded or outbound AI calls are under-disclosed, the skill can expose secrets and send user content to external providers without adequate transparency.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest states use of Gemini API keys and external integrations but does not declare permissions, and the finding also indicates possible hardcoded credential material and undisclosed third-party transmission. If credentials are embedded or outbound AI calls are under-disclosed, the skill can expose secrets and send user content to external providers without adequate transparency.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 30)May include surrounding context.

md
npm install

# Check environment
if [ ! -f .env ]; then
    echo "⚠️  .env not found. Copying from example..."
    cp .env.example .env
    echo "📝 Please edit .env with your API keys"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

md
npm install

# Check environment
if [ ! -f .env ]; then
    echo "⚠️  .env not found. Copying from example..."
    cp .env.example .env
    echo "📝 Please edit .env with your API keys"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
npm install

# Check environment
if [ ! -f .env ]; then
    echo "⚠️  .env not found. Copying from example..."
    cp .env.example .env
    echo "📝 Please edit .env with your API keys"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
npm install

# Check environment
if [ ! -f .env ]; then
    echo "⚠️  .env not found. Copying from example..."
    cp .env.example .env
    echo "📝 Please edit .env with your API keys"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · deploy.sh (reported line 17)May include surrounding context.

sh
npm install

# Check environment
if [ ! -f .env ]; then
    echo "⚠️  .env not found. Copying from example..."
    cp .env.example .env
    echo "📝 Please edit .env with your API keys"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · deploy.sh (reported line 18)May include surrounding context.

sh
npm install

# Check environment
if [ ! -f .env ]; then
    echo "⚠️  .env not found. Copying from example..."
    cp .env.example .env
    echo "📝 Please edit .env with your API keys"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · deploy.sh (reported line 19)May include surrounding context.

sh
npm install

# Check environment
if [ ! -f .env ]; then
    echo "⚠️  .env not found. Copying from example..."
    cp .env.example .env
    echo "📝 Please edit .env with your API keys"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · deploy.sh (reported line 20)May include surrounding context.

sh
npm install

# Check environment
if [ ! -f .env ]; then
    echo "⚠️  .env not found. Copying from example..."
    cp .env.example .env
    echo "📝 Please edit .env with your API keys"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/server.js (reported line 51)May include surrounding context.

js
npm install

# Check environment
if [ ! -f .env ]; then
    echo "⚠️  .env not found. Copying from example..."
    cp .env.example .env
    echo "📝 Please edit .env with your API keys"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 18)May include surrounding context.

  1. Set up PostgreSQL
    bash
    # Ubuntu/Debian
    sudo apt-get install postgresql postgresql-contrib
    sudo service postgresql start
    
    # Create database
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 19)May include surrounding context.

  1. Set up PostgreSQL
    bash
    # Ubuntu/Debian
    sudo apt-get install postgresql postgresql-contrib
    sudo service postgresql start
    
    # Create database
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 22)May include surrounding context.

  1. Set up PostgreSQL
    bash
    # Ubuntu/Debian
    sudo apt-get install postgresql postgresql-contrib
    sudo service postgresql start
    
    # Create database
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 24)May include surrounding context.

  1. Set up PostgreSQL
    bash
    # Ubuntu/Debian
    sudo apt-get install postgresql postgresql-contrib
    sudo service postgresql start
    
    # Create database
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
96% confidence
Finding

This privileged command creates a database user with the weak hardcoded password 'ubuntu'. Because it is executed as the postgres superuser, it establishes insecure credentials at the database level, enabling easy compromise if the database becomes reachable or the credentials are reused.

Content

Scanner excerpt · INSTALL.md (reported line 23)May include surrounding context.

Create database

sudo -u postgres psql -c "CREATE DATABASE lifepath;" sudo -u postgres psql -c "CREATE USER ubuntu WITH PASSWORD 'ubuntu';" sudo -u postgres psql -c "GRANT ALL PRIVILEGES ON DATABASE lifepath TO ubuntu;"

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation guide instructs users to create a PostgreSQL account with a trivial hardcoded password ('ubuntu') and grants it full privileges on the application database. Default weak credentials are commonly abused when services are exposed beyond localhost, reused across environments, or copied into production-like deployments, making unauthorized database access much easier.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · INSTALL.md (reported line 63)May include surrounding context.

bash
# Start a life
curl -X POST http://localhost:3000/api/life/start \
  -d '{"userId": "test", "country": "Japan", "year": 1985, "gender": "female"}'

# Check health

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The manifest declares required environment variables, networked integrations, and backend services, but does not declare any explicit tool scope or permissions boundary. That makes the skill's operational capabilities opaque to reviewers and users, increasing the chance that credential access and outbound requests occur without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation promotes sharing to Moltbook but does not clearly warn that user-generated life content may be published to an external platform. In a narrative simulator, users may include personal or sensitive details, so omission of an external-sharing warning creates meaningful privacy and consent risk.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/routes/moltbook.js:6

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/services/imageService.js:10