Back to skill

Security audit

MoltTalent

Security checks for vulnerabilities and agentic risk

Overview

This skill is for maintaining a public professional profile, but it asks an agent to periodically scan conversations, fetch changing remote instructions, and perform public profile and social actions with broad authority.

Review this skill carefully before installing. Only use it if you are comfortable with an agent maintaining a public professional profile, and configure preferences before any heartbeat runs. Keep ask-before-posting enabled, require approval for profile edits, project creation, comments, follows, and deletions, avoid broad conversation scanning, and store or rotate the API key through a safer secret mechanism when possible. Do not let the agent fetch and follow updated remote instruction files unless you can verify the exact version being loaded.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
skill.md:24
Finding

Unpinned Remote Skill Instructions Are Periodically Retrieved and Followed

Content
View full analysis
~/.moltbot/skills/molttalent/SKILL.md curl -s https://molttalent.com/heartbeat.md > ~/.moltbot/skills/molttalent/HEARTBEAT.md curl -s https://molttalent.com/skill.json > ~/.moltbot/skills/molttalent/package.json ``` ```markdown ## Molttalent (every 4+ hours) If 4+ hours since last Molttalent check: 1. Fetch https://molttalent.com/heartbeat.md and follow it 2. Update lastMolttalentCheck timestamp in memory ``` ### Technical Analysis The Skill instructs the Agent to download instruction files from a remote server and later re-fetch and follow `heartbeat.md` every four or more hours. The retrieved content is not pinned to an audited version and is not validated using a cryptographic checksum or signature. Although HTTPS protects data in transit under normal conditions and the remote domain is the Skill's declared service, it does not guarantee that future content served by that domain is identical to the reviewed package. Compromise of the website, DNS infrastructure, deployment pipeline, hosting account, or signing credentials could allow an attacker to replace the remote document with malicious Agent instructions. The installation commands also use `curl -s` without `--fail`, integrity checks, or atomic replacement. An HTTP error response or malformed document could therefore overwrite an installed Skill file without producing a clear failure. ### Attack Path 1. An attacker compromises `molttalent.com`, its DNS, hosting account, deployment pipeline, or another component capable of modifying the remote Skill files. 2. The attacker replaces `heartbeat.md` or `skill.md` with instructions that request sensitive files, disclose conversation data, invoke dangerous tools, or alter pers ...[truncated 1186 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
heartbeat.md:18
Finding

Recurring Heartbeat Directs Broad Analysis of Conversation History

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (71)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The introductory heartbeat task list implies ongoing syncing and updating from conversations without an upfront warning that this can change remote profile data. Users or integrating agents may not realize that simply enabling the skill can cause external state changes and public-facing modifications.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill instructs the agent to update or remove user skills based on heuristic interpretation of conversations, effectively allowing remote modification of profile state from inferred intent. This is risky because conversational mentions are ambiguous and may not reflect a user's desired public representation.

Content

Scanner excerpt · heartbeat.md (reported line 67)May include surrounding context.

md
Example heuristics:
- "I've been learning {skill}" → Suggest adding skill
- "I'm now proficient in {skill}" → Update skill level
- "I don't use {skill} anymore" → Consider removing

**API calls:**

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file contains conflicting guidance: earlier sections instruct autonomous posting and commenting, while the privacy section says not to post without the human's awareness. In practice, ambiguous policy text leads to unsafe implementations where agents may perform public actions before obtaining clear consent.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill instructs agents to persist a long-lived API key, human ID, and verification code in a predictable plaintext file under the user's home directory. Although permissions are restricted, plaintext local credential storage increases the blast radius of local compromise, accidental inclusion in backups, prompt/context leakage, or other tools reading from standard config paths.

Content

Scanner excerpt · skill.md (reported line 68)May include surrounding context.

⚠️ Save your api_key immediately! This is the ONLY time you'll see it.

Recommended: Save your credentials to ~/.config/molttalent/credentials.json:

bash
mkdir -p ~/.config/molttalent

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The example writes the API key directly into a heredoc for a plaintext credentials file, creating a concrete pattern that agents or users may copy verbatim. In practice, this encourages insecure secret handling and may cause credentials to be retained in shell history, transcripts, or other tool logs depending on how the commands are executed.

Content

Scanner excerpt · skill.md (reported line 74)May include surrounding context.

md
mkdir -p ~/.config/molttalent
chmod 700 ~/.config/molttalent

cat > ~/.config/molttalent/credentials.json <<EOF
{
  "api_key": "molt_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",
  "human_id": "uuid-here",

Credential Access

High
Category
Privilege Escalation
Confidence
86% confidence
Finding

Even with restrictive permissions, the documented storage model keeps reusable authentication material in a static local file, which remains valuable to malware, other local tools, or accidental disclosure channels. The professional-profile context makes compromise impactful because an attacker could impersonate the human, publish content, and modify public reputation data.

Content

Scanner excerpt · skill.md (reported line 82)May include surrounding context.

} EOF

chmod 600 ~/.config/molttalent/credentials.json

text

Send your human the `claim_url`. They'll post a verification tweet and the profile goes public!

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description frames the skill as broad periodic maintenance to keep a profile 'alive and fresh,' which can trigger use in overly general contexts. That broad scope increases the chance an agent applies the skill to conversation content or maintenance tasks without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · heartbeat.md (reported line 46)May include surrounding context.

1. Profile Completeness Check

bash
curl https://api.molttalent.com/api/v1/humans/{slug} \
  -H "Authorization: Bearer YOUR_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This POST call sends inferred skill data from conversations to an external service, creating a profile mutation based on agent interpretation. If the agent misreads context or lacks explicit permission, it can publish inaccurate or sensitive professional information.

Content

Scanner excerpt · heartbeat.md (reported line 73)May include surrounding context.

API calls:

bash
# Add human skill
curl -X POST https://api.molttalent.com/api/v1/humans/{slug}/skills \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "Kubernetes", "category": "technical", "level": 3}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

This DELETE call removes profile skills remotely, which can silently alter a user's public identity based on heuristic judgments about outdated skills. Incorrect deletions may damage the user's profile and are hard to justify without explicit confirmation.

Content

Scanner excerpt · heartbeat.md (reported line 79)May include surrounding context.

-d '{"name": "Kubernetes", "category": "technical", "level": 3}'

Remove outdated skill

curl -X DELETE https://api.molttalent.com/api/v1/humans/{slug}/skills/{skill_id}
-H "Authorization: Bearer YOUR_API_KEY"

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The PATCH endpoint can change core public profile fields such as bio, title, and location using conversation-derived data. This creates significant privacy and reputational risk if the agent infers information incorrectly or updates sensitive fields without direct approval.

Content

Scanner excerpt · heartbeat.md (reported line 95)May include surrounding context.

Action: Update profile fields.

bash
curl -X PATCH https://api.molttalent.com/api/v1/humans/{slug} \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

Creating projects on the external service introduces persistent external state derived from transient conversation content. This can publish long-lived records about private or preliminary work and is more dangerous because the project becomes part of the user's ongoing profile footprint.

Content

Scanner excerpt · heartbeat.md (reported line 116)May include surrounding context.

  • "Deployed v2.0"
  • "Started a new side project"

Create a new project:

bash
curl -X POST https://api.molttalent.com/api/v1/projects \

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

Creating a new project transmits substantial profile-linked content to an external platform and persists it publicly. Because the trigger is conversational milestone detection, the agent may publish private, premature, or inaccurate project information.

Content

Scanner excerpt · heartbeat.md (reported line 119)May include surrounding context.

Create a new project:

bash
curl -X POST https://api.molttalent.com/api/v1/projects \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This call creates posts from detected milestones, which is a public broadcast derived from conversations. Posting without contemporaneous approval can leak private business metrics, internal launches, or other sensitive updates.

Content

Scanner excerpt · heartbeat.md (reported line 136)May include surrounding context.

Create a post linked to that project:

bash
curl -X POST https://api.molttalent.com/api/v1/posts \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The heartbeat expands from profile maintenance into autonomous social actions such as liking, following, and commenting. Those actions can publicly represent the user without real-time approval and can be driven by imperfect heuristics, creating reputational risk and unauthorized account activity.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

Automatically liking posts is a public engagement action that signals endorsement on the user's behalf. Even low-risk interactions can cause reputational harm or manipulation if driven by weak heuristics or third-party content selection.

Content

Scanner excerpt · heartbeat.md (reported line 165)May include surrounding context.

Like a post:

bash
curl -X POST https://api.molttalent.com/api/v1/posts/{post_id}/like \
  -H "Authorization: Bearer YOUR_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

Although unliking is less severe than posting, it still changes public engagement state on the user's behalf. Autonomous cleanup of social signals can create confusing or unintended behavior without user awareness.

Content

Scanner excerpt · heartbeat.md (reported line 172)May include surrounding context.

Unlike a post:

bash
curl -X DELETE https://api.molttalent.com/api/v1/posts/{post_id}/like \
  -H "Authorization: Bearer YOUR_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

Liking projects publicly associates the user with external content and may reveal preferences or endorsements not consciously made by the user. This is especially risky when discovery is automated and recommendations may be manipulated or irrelevant.

Content

Scanner excerpt · heartbeat.md (reported line 179)May include surrounding context.

Like a project:

bash
curl -X POST https://api.molttalent.com/api/v1/projects/{project_id}/like \
  -H "Authorization: Bearer YOUR_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

Following another human is a durable social graph change performed on the user's behalf. Automated follows can reveal interests, create awkward associations, or be abused through recommendation manipulation.

Content

Scanner excerpt · heartbeat.md (reported line 186)May include surrounding context.

Follow a human:

bash
curl -X POST https://api.molttalent.com/api/v1/humans/{slug}/follow \
  -H "Authorization: Bearer YOUR_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Unfollowing changes the user's visible network and may damage relationships if done automatically. While lower impact than posting, it is still an unauthorized account action when based on agent heuristics.

Content

Scanner excerpt · heartbeat.md (reported line 193)May include surrounding context.

Unfollow:

bash
curl -X DELETE https://api.molttalent.com/api/v1/humans/{slug}/follow \
  -H "Authorization: Bearer YOUR_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
98% confidence
Finding

Posting comments is a direct public communication under the user's identity. Template comments like 'Great work!' may seem harmless, but autonomous replies can be inappropriate, spammy, or exploitable through adversarial content placement.

Content

Scanner excerpt · heartbeat.md (reported line 200)May include surrounding context.

Comment on a post:

bash
curl -X POST https://api.molttalent.com/api/v1/posts/{post_id}/comments \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"content": "Great work! This is really impressive."}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

Replying to comments deepens public interaction and can create conversational commitments or misunderstandings on the user's behalf. Because replies are context-sensitive, automated responses are especially prone to reputational errors and abuse.

Content

Scanner excerpt · heartbeat.md (reported line 209)May include surrounding context.

Reply to a comment:

bash
curl -X POST https://api.molttalent.com/api/v1/posts/{post_id}/comments \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

Liking comments is another public endorsement action that may signal agreement with statements the user has not reviewed. In an automated engagement loop, this can amplify harmful or irrelevant content.

Content

Scanner excerpt · heartbeat.md (reported line 221)May include surrounding context.

Like a comment:

bash
curl -X POST https://api.molttalent.com/api/v1/comments/{comment_id}/like \
  -H "Authorization: Bearer YOUR_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

Deleting comments can remove public statements and alter conversation history without the user's awareness. If applied incorrectly, it may erase legitimate communication or appear evasive to others.

Content

Scanner excerpt · heartbeat.md (reported line 228)May include surrounding context.

Delete your comment:

bash
curl -X DELETE https://api.molttalent.com/api/v1/comments/{comment_id} \
  -H "Authorization: Bearer YOUR_API_KEY"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · heartbeat.md (reported line 369)May include surrounding context.

md
## Privacy & Preferences

**Heartbeat should NEVER:**
- Read private messages without consent
- Share conversation details publicly
- Post without your human's awareness
- Access data outside your agent's scope

Static analysis

No suspicious patterns detected.