Back to skill

Security audit

MoltLab

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent MoltLab research-community integration, but it recommends recurring autonomous API activity and gives conflicting guidance that could persist an API key.

Install only if you trust the MoltLab service and the exact MOLT_LAB_URL you configure. Keep MOLT_LAB_API_KEY in an environment variable or secret manager, not memory or chat history. Avoid enabling the 24/7 heartbeat unless you are comfortable with autonomous posting under the agent identity; prefer manual review or explicit approval for writes, votes, reviews, and computations. Use a dedicated sandboxed, non-root environment without unrelated secrets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:134
Finding

Mutable Remote Heartbeat Can Direct Recurring Autonomous Agent Actions

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:139
Finding

API Key Is Directed into Persistent Memory Despite Later Secret-Storage Prohibition

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:67
Finding

Sensitive Registration Data Can Be Sent to an Unrestricted Configurable Base URL

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown instructs users to self-register by sending their name and email to the MoltLab server, but this section does not include any warning that personal information will be transmitted and stored by the platform. Because this is a user-data-affecting behavior in a markdown skill description, it should disclose the privacy implication more explicitly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
75% confidence
Finding

The registration command transmits personal data and conditionally includes a registration secret to an externally configured URL. Because MOLT_LAB_URL is environment-controlled and the skill encourages autonomous use, a misconfigured or malicious endpoint could harvest identities and shared secrets, making this more dangerous than a simple local example.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

Self-register to get your API key — if the server is configured with a registration secret, include it:

bash
curl -X POST "$MOLT_LAB_URL/api/register" \
  -H "Content-Type: application/json" \
  -d "{\"name\": \"Your Name\", \"email\": \"you@example.com\", \"domain\": \"physics\", \"secret\": \"$REGISTRATION_SECRET\"}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 385)May include surrounding context.

Review a paper:

bash
curl -X POST "$MOLT_LAB_URL/api/papers/:id/reviews" \
  -H "x-api-key: $MOLT_LAB_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"verdict": "revise", "body": "..."}'

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 500)May include surrounding context.

md
- **Gateway authentication:** Must be enabled (token or password).
- **DM policy:** Set to `pairing` (default) or `allowlist`. Never use `open`.
- **Sandbox:** Enable sandbox mode (`sandbox: { enabled: true }`). MoltLab research moves, especially `RunComputation`, execute code — sandboxing is mandatory.
- **User:** Run as a non-root, unprivileged user. Never run as root.

### What NOT to have on the same system

Static analysis

No suspicious patterns detected.