Back to skill

Security audit

PJ Moltbook Interact

Security checks for vulnerabilities and agentic risk

Overview

This skill is built for Moltbook posting and voting, but it ships an embedded bearer credential and exposes broader authenticated actions than the description clearly covers.

Review before installing. This skill can act on Moltbook with bearer authentication, create public posts/comments/upvotes, auto-submit verification, and includes an exposed token that should be treated as compromised and rotated. Install only if the credential handling is fixed and you are comfortable with explicit user-controlled posting and voting workflows.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/moltbook-client.js:13
Finding

Hard-Coded Reusable Moltbook API Credential

Content
View full analysis

Vulnerability Details

File Location: scripts/moltbook-client.js:13
Vulnerability Type: Hard-coded bearer credential
Risk Level: High

Vulnerable Code

javascript
const MOLTBOOK_API_KEY = "moltbook_sk_oOyURnwFc5RbKKpraIUW9h0BAgM_vNI0";

The credential is subsequently attached to every API request:

javascript
async function mbReq(method, endpoint, body) {
  const opts = { method, headers: { Authorization: `Bearer ${MOLTBOOK_API_KEY}`, "Content-Type": "application/json" } };
  if (body) opts.body = JSON.stringify(body);
  const res = await fetch(`${BASE}${endpoint}`, opts);
  return res.json();
}

Technical Analysis

A reusable Moltbook bearer credential is embedded directly in distributed source code. Anyone who can download, inspect, log, or otherwise access the Skill package can recover the credential without needing to defeat authentication controls.

The mbReq function uses this credential for all supported endpoints. The exposed client provides authenticated capabilities to publish posts, comment, upvote, edit posts, complete anti-spam verification, read the feed, access the dashboard, and retrieve agent information. Because bearer authentication proves possession rather than caller identity, copying the token is sufficient to impersonate the associated Moltbook agent.

This secret exceeds secure minimum-privilege handling requirements because it is shared with every recipient and execution environment that receives the package. Although authenticated network transmission to the declared Moltbook API is necessary for the Skill’s functionality, embedding the credential itself is unnecessary and unsafe.

Attack Path

  1. An attacker downloads or otherwise obtains access to the Skill package.
  2. The attacker inspects scripts/moltbook-client.js.
  3. The attacker copies the bearer credential declared on line 13.
  4. The attacker sends independent requests to https://www.moltbook.com/api/v1 with the copied value in th ...[truncated 979 chars]
Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed credential. Treat it as compromised because it has been distributed in plaintext.
  2. Remove the credential from source code and repository history. Rewriting only the current file is insufficient if prior revisions or published archives remain accessible.
  3. Inject the credential at runtime through a dedicated secret manager or a narrowly scoped environment variable that is not committed, packaged, logged, or returned to users.
  4. Avoid storing credentials in broadly loaded agent memory or TOOLS.md. Use a credential facility that exposes secrets only to the component and operation requiring them.
  5. Issue a least-privilege token. Restrict the replacement credential to the minimum endpoints and actions required by the declared publish, comment, and upvote workflow. Separate read, edit, and account-information capabilities where the platform supports scoped tokens.
  6. Restrict the request destination. Preserve a fixed HTTPS origin and validate endpoints before attaching the Authorization header.
  7. Reduce browser-context exposure. Prefer a dedicated authenticated API client over arbitrary browser-page evaluation where possible, as page scripts, extensions, debugging facilities, or logs may expose runtime credentials.
  8. Add secret scanning and commit-time controls to reject Moltbook keys and similar bearer credentials before packaging or publication.
  9. Review Moltbook activity logs for unauthorized posts, edits, comments, votes, account reads, and unusual rate-limit usage associated with the exposed key.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest describes basic posting/commenting/upvoting, but the documentation indicates broader capabilities including feed reading, account information access, and references to undeclared credential use. Description-behavior mismatch is dangerous because reviewers and users may approve the skill under false assumptions while it performs additional authenticated actions and data access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file contains a hardcoded Moltbook bearer API key directly in client-side JavaScript. Anyone with access to the skill source can extract and reuse this credential to impersonate the agent account, perform authenticated actions, and potentially abuse or drain the associated account without the user's knowledge.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The hardcoded bearer token is immediately used for authenticated network requests, with no disclosure to the user that the skill carries embedded account credentials. This creates a hidden trust boundary: the skill can act as a privileged principal independent of the user's own authentication, enabling silent unauthorized actions if copied, triggered, or misused.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill provides direct authenticated POST and PATCH functions for publishing, commenting, upvoting, batch upvoting, and editing content, but includes no built-in confirmation, warning, or approval guardrails. In an agent setting, this is dangerous because a prompt injection, misunderstanding, or accidental invocation could immediately perform irreversible or reputation-impacting actions on behalf of the account.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill uses network-capable behavior via browser-based fetch calls but does not declare any explicit tool scope or allowed-tools boundary. This weakens least-privilege controls and makes it easier for a consuming agent to invoke broader capabilities than the manifest transparently communicates.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is designed to publish posts, comments, and votes to a public external platform but does not clearly warn that these actions may be public and hard to reverse. In this context, omission of that warning raises the risk of accidental reputational harm, unwanted publication, and unintended account activity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to retrieve a bearer token from local memory or TOOLS, which expands the skill from content automation into credential discovery and use. That is risky because it normalizes secret access by prompt instructions and can cause unintended authenticated actions or secret exposure if the agent logs, echoes, or misuses the key.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to send an API key to an external service without any user-facing notice or consent boundary around credential use. This is dangerous because users and reviewers may not realize the skill performs authenticated external operations on their behalf, increasing the chance of silent account actions and secret misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The fetch template performs external transmission to a third-party API, including authenticated headers and request bodies. External transmission is expected for this skill's purpose, but it still constitutes a real security-sensitive behavior because any included content, identifiers, or credentials leave the local trust boundary.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

javascript
// Template for browser evaluate
async () => {
  const res = await fetch("https://www.moltbook.com/api/v1/ENDPOINT", {
    method: "POST", // or GET
    headers: {
      "Authorization": "Bearer API_KEY",

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The skill encourages autonomous engagement actions such as upvoting in batches with only small delays and no additional verification. While lower severity than credential issues, this can enable non-user-reviewed account activity at scale, creating abuse, policy, or reputation risks on the external platform.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

POST /api/v1/posts/{post_id}/upvote

text

No verification needed. Has rate limits — batch with small delays if doing many.

### 4. Anti-Spam Verification (Required)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code automatically solves and submits anti-spam verification challenges to a remote endpoint without user notice. This bypasses an intended friction/control mechanism and makes mass automated posting or interaction easier, which increases abuse potential when combined with the embedded credential and batch interaction functions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The implementation exposes authenticated capabilities beyond the manifest description, including feed/home/profile reads and post editing. This expands the effective permission surface and can enable undisclosed data access or content modification that users and reviewers would not expect from a posting/comment/upvote skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Several prominent comments and usage notes are presented in Chinese, which imposes a language expectation on readers without any indication of language choice. This may violate a language/locale policy when users are not given an option or justification for the locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.