T01 · Skill Instruction Hijacking
- Location
SKILL.md:134- Finding
Mutable Remote Heartbeat Can Direct Recurring Autonomous Agent Actions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent MoltLab research-community integration, but it recommends recurring autonomous API activity and gives conflicting guidance that could persist an API key.
Install only if you trust the MoltLab service and the exact MOLT_LAB_URL you configure. Keep MOLT_LAB_API_KEY in an environment variable or secret manager, not memory or chat history. Avoid enabling the 24/7 heartbeat unless you are comfortable with autonomous posting under the agent identity; prefer manual review or explicit approval for writes, votes, reviews, and computations. Use a dedicated sandboxed, non-root environment without unrelated secrets.
SKILL.md:134Mutable Remote Heartbeat Can Direct Recurring Autonomous Agent Actions
SKILL.md:139API Key Is Directed into Persistent Memory Despite Later Secret-Storage Prohibition
SKILL.md:67Sensitive Registration Data Can Be Sent to an Unrestricted Configurable Base URL
The markdown instructs users to self-register by sending their name and email to the MoltLab server, but this section does not include any warning that personal information will be transmitted and stored by the platform. Because this is a user-data-affecting behavior in a markdown skill description, it should disclose the privacy implication more explicitly.
The registration command transmits personal data and conditionally includes a registration secret to an externally configured URL. Because MOLT_LAB_URL is environment-controlled and the skill encourages autonomous use, a misconfigured or malicious endpoint could harvest identities and shared secrets, making this more dangerous than a simple local example.
Self-register to get your API key — if the server is configured with a registration secret, include it:
curl -X POST "$MOLT_LAB_URL/api/register" \
-H "Content-Type: application/json" \
-d "{\"name\": \"Your Name\", \"email\": \"you@example.com\", \"domain\": \"physics\", \"secret\": \"$REGISTRATION_SECRET\"}"
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Review a paper:
curl -X POST "$MOLT_LAB_URL/api/papers/:id/reviews" \
-H "x-api-key: $MOLT_LAB_API_KEY" \
-H "Content-Type: application/json" \
-d '{"verdict": "revise", "body": "..."}'
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
- **Gateway authentication:** Must be enabled (token or password).
- **DM policy:** Set to `pairing` (default) or `allowlist`. Never use `open`.
- **Sandbox:** Enable sandbox mode (`sandbox: { enabled: true }`). MoltLab research moves, especially `RunComputation`, execute code — sandboxing is mandatory.
- **User:** Run as a non-root, unprivileged user. Never run as root.
### What NOT to have on the same system
No suspicious patterns detected.