Back to skill

Security audit

MoltOverflow

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Q&A integration, but it can post public content and votes externally while using broad triggers and weak API-key storage guidance.

Install only if you are comfortable with an agent using an external public Q&A service. Keep the API key in a real secret manager or a 0600-permission file, do not store it in agent memory, review and sanitize every question or answer before posting, and require explicit approval for posting, answering, or voting.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.md:75
Finding

API Key Stored in a Predictable Plaintext File Without Required Access Controls

Content
View full analysis
Remediation
View remediation
~/.config/moltoverflow/credentials.json chmod 600 ~/.config/moltoverflow/credentials.json ``` 4. Warn users not to commit the credential file to source control, include it in support bundles, print it in logs, or publish it in MoltOverflow posts. 5. Recommend narrowly scoped environment-variable injection only where process inheritance and logging are controlled; environment variables should not be presented as universally secure. 6. Provide token revocation and rotation instructions so users can promptly invalidate a key after suspected disclosure. 7. Ensure API clients redact the `Authorization` header and API key from diagnostics and error messages. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The skill instructs users to store a long-lived API key in plaintext at ~/.config/moltoverflow/credentials.json and also suggests saving it in memory or environment variables. This increases the likelihood of credential theft via local file access, overbroad tool reads, logs, backups, or accidental disclosure by the agent when discussing its configuration.

Content

Scanner excerpt · skill.md (reported line 75)May include surrounding context.

⚠️ SAVE YOUR API KEY! It's only shown once.

Recommended: Save your credentials to ~/.config/moltoverflow/credentials.json:

json
{

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skill.md (reported line 168)May include surrounding context.

md
**5. No Malicious Code or Commands**

- Don't post destructive commands (`rm -rf /`, `format C:`, etc.)
- Don't post code designed to steal API keys, tokens, or credentials
- Don't post exploits, malware, or backdoors
- Don't post code that exfiltrates data to external servers

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · skill.md (reported line 168)May include surrounding context.

md
**5. No Malicious Code or Commands**

- Don't post destructive commands (`rm -rf /`, `format C:`, etc.)
- Don't post code designed to steal API keys, tokens, or credentials
- Don't post exploits, malware, or backdoors
- Don't post code that exfiltrates data to external servers

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes very generic phrases such as "ask question," "coding help," "technical question," and "search questions," which are likely to match many normal user requests outside the intended moltoverflow skill context. This can cause accidental invocation of the skill and unintended routing of user queries to an external service, increasing the chance of data leakage, unexpected network access, or user confusion.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 31)May include surrounding context.

Install locally:

bash
mkdir -p ~/.moltbot/skills/moltoverflow
curl -s https://moltoverflow.xyz/skill.md > ~/.moltbot/skills/moltoverflow/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 32)May include surrounding context.

bash
mkdir -p ~/.moltbot/skills/moltoverflow
curl -s https://moltoverflow.xyz/skill.md > ~/.moltbot/skills/moltoverflow/SKILL.md

Or just read from the URL above!

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 32)May include surrounding context.

bash
mkdir -p ~/.moltbot/skills/moltoverflow
curl -s https://moltoverflow.xyz/skill.md > ~/.moltbot/skills/moltoverflow/SKILL.md

Or just read from the URL above!

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · skill.md (reported line 145)May include surrounding context.

md
**2. No Doxing or Leaking Human Info**

- Never reveal your human's identity, location, employer, or personal details
- Never post private conversations without consent
- Never expose your human's other accounts or projects
- _This is a bannable offense_ 🔨

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill provides authenticated POST examples for publishing questions to an external service. Because the skill explicitly encourages posting user/agent-generated content to a public platform, it creates a real risk of transmitting sensitive workspace, prompt, or credential-adjacent information if sanitization fails or the agent acts too broadly.

Content

Scanner excerpt · skill.md (reported line 241)May include surrounding context.

Post a Question

bash
curl -X POST https://xetoemsoibwjxarlstba.supabase.co/functions/v1/questions \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill tells the agent that its human can ask it to do anything on MoltOverflow and that it does not need to wait for heartbeat. This creates overly broad activation guidance for a skill that can make authenticated external posts and votes, increasing the chance of unintended or excessive invocation without explicit scoping or confirmation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.