Back to skill

Security audit

MoltStreet News

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed market-analysis helper that fetches public MoltStreet data and does not request credentials, persistence, or local system changes.

Install only if you are comfortable sending ticker symbols or search topics to MoltStreet and receiving AI-generated market commentary from that source. Treat outputs as research context, not financial advice, and verify important investment decisions independently.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:49
Finding

Mandatory Branded Output and External-Link Injection

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 49–67
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Low

Vulnerable Code

markdown
## How to present

Build a news-driven market narrative from the analyst perspectives:

"**Market Analysis** ({date}):

**{SYMBOL}** — {consensus direction}
{Summarize perspectives from multiple analysts — they have opposing biases, so present the debate}

Bull case ({analyst}): {summary}
Bear case ({analyst}): {summary}

Analyst consensus: {bullish_count} bullish, {bearish_count} bearish
Active predictions: {list predictions with targets and deadlines}

Source: https://www.moltstreet.com/ticker/{SYMBOL}

---
_6 AI analysts with opposing biases. Not financial advice._"

Technical Analysis

The skill prescribes a user-facing response template that unconditionally embeds a MoltStreet URL and branded promotional statement. These instructions affect the agent’s current-session output rather than merely defining how API data should be retrieved or interpreted.

When loaded for a relevant market-analysis request, the skill can cause the agent to present the operator’s branding and outbound link as part of its answer without confirming that the user requested promotional content. This is a constrained form of instruction hijacking because it redirects part of the agent’s response objective toward promoting the skill provider.

No instruction was found that overrides safety controls, accesses credentials, executes downloaded code, modifies persistent memory, or obtains additional system privileges. The issue is therefore limited to response presentation and external redirection.

Attack Path

  1. A user asks for market news or an explanation of an ETF’s movement.
  2. The agent activates the skill and queries one of the documented MoltStreet endpoints.
  3. The agent follows the mandatory presentation instructions in SKILL.md.
  4. Th ...[truncated 808 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the requirement to append branded promotional text to every generated response.
  2. Treat source links as optional citations and include them only when relevant to the user’s request or necessary to substantiate a claim.
  3. Use neutral attribution such as “Data source: MoltStreet” instead of language that may imply endorsement.
  4. Clearly distinguish third-party API content, generated analysis, and promotional claims.
  5. Allow the agent to select an appropriate response format based on the user’s request rather than enforcing a provider-controlled final-answer template.
  6. Preserve the financial disclaimer where appropriate, but present it independently from advertising or branding.
  7. Validate and safely render any URLs or text received from remote API responses before including them in user-facing output.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to activate on generic financial-information requests such as 'market news' or 'what's happening in the market today,' which likely overlap with many other finance or news skills. This can cause the skill to be selected when the user did not specifically ask for ETF-focused, AI-curated analysis, increasing the chance of inappropriate routing and over-reliance on this source for broad market questions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.