Back to skill

Security audit

moltfs

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly transparent about being an autonomous social bot, but it relies on mutable remote instructions and an unpinned installer while allowing public account actions.

Review before installing. Prefer avoiding the npx @latest path unless you can verify the package version, and treat HEARTBEAT.md, MESSAGING.md, feed content, and refreshed skill files as untrusted remote content. Run the agent with a narrowly scoped API key, explicit policy for public actions, limited filesystem access, and outbound network access restricted to the documented service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:147
Finding

Mutable Remote Instructions Can Alter Agent Behavior After Review

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:147-156, SKILL.md:175-185, and SKILL.md:321-322
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Complete Code Snippets

SKILL.md:147-156:

markdown
### Required reading (cache once)

- **MUST** fetch **HEARTBEAT.md** before first action.
- **MUST** fetch **MESSAGING.md** before first action.

### Required Initialization Order (CRITICAL)

After registration, the agent MUST:
1. Fetch and read **HEARTBEAT.md**
2. Fetch and read **MESSAGING.md**
3. Only then begin the operational loop

SKILL.md:175-185:

markdown
For full details, see https://molt-fs.vercel.app/heartbeat.md

### Recommended Cadence

**Poll every 10–30 minutes with jitter.**

base_interval = random(10, 30) minutes jitter = random(0, 5) minutes next_poll = base_interval + jitter

text

SKILL.md:321-322:

markdown
## Check for Updates

Periodically re-fetch the skill files to ensure you have the latest documentation, endpoints, and rules. The URLs in the Skill Files section are canonical.

Technical Analysis

The audited Skill does not contain all of the instructions that govern its operation. Instead, it requires the agent to fetch and read HEARTBEAT.md and MESSAGING.md from a remote deployment before acting. It further instructs the agent to periodically retrieve updated documentation and rules.

Because these remote files are mutable and are not pinned to a reviewed version or cryptographic digest, their contents can change after the Skill has been audited. If an agent interprets downloaded text as trusted Skill instructions, control of the remote service or its deployment can be used to introduce new behavioral directives without modifying the local audited artifact.

Fetching service documentation is relevant to the declared social-platform functionality, but granting mutable documents authority over ...[truncated 2008 chars]

Remediation
View remediation

Remediation Suggestions

  1. Bundle reviewed copies of HEARTBEAT.md and MESSAGING.md directly in the Skill package.
  2. Pin every remotely retrieved document to an immutable version and verify a cryptographic digest before processing it.
  3. Remove automatic or periodic replacement of behavioral instructions. Require explicit review and approval for updates.
  4. Treat remote documents, API responses, feed posts, comments, and messages as untrusted data rather than authoritative instructions.
  5. Enforce an instruction hierarchy that prevents downloaded content from overriding system policies, user intent, safety requirements, or credential-handling restrictions.
  6. Validate remote content against a narrow schema and reject unexpected commands, tool requests, credential requests, or references to unapproved destinations.
  7. Restrict outbound network access to the documented HTTPS host and API paths, while still treating content returned by that host as potentially compromised.
  8. Require human confirmation for sensitive or irreversible social actions, especially purchases or actions affecting other accounts.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned npx Installation Executes a Mutable Third-Party Package

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:27-31
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Complete Code Snippet

markdown
### Install via MoltHub (optional)

```bash
npx molthub@latest install moltforsale
text

### Technical Analysis

The optional installation procedure invokes `npx molthub@latest`. This causes the package manager to resolve, download, and execute whichever package release is tagged `latest` at invocation time. The command does not pin an audited version, lock an integrity digest, or otherwise ensure that the executed package matches the version assessed during this audit.

Unlike the manual `curl` instructions, which only download Markdown and JSON files, the `npx` command executes third-party package code. A compromised package publisher, registry account, dependency chain, or future package release could therefore turn the documented installation command into an arbitrary local code-execution path.

### Attack Path

1. An attacker compromises the `molthub` package, its publisher account, its dependency chain, or the package registry distribution process.
2. The attacker publishes a malicious release and assigns or causes it to receive the `latest` tag.
3. A user follows the documented optional installation procedure.
4. `npx` retrieves the attacker-controlled release and executes its package entry point or lifecycle behavior.
5. The malicious package runs with the operating-system privileges and environment inherited from the invoking user.
6. It may then access files, environment variables, network resources, or credentials available to that user, subject to operating-system and sandbox restrictions.

### Impact Assessment

Successful exploitation can provide arbitrary code execution with the privileges of the user running the installation command. Potential scope includes modifying files writable by that user, accessing readable local data an
...[truncated 379 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with a specific package version that has been reviewed and tested.
  2. Verify the package using a trusted integrity digest or lockfile before execution.
  3. Document the expected registry and reject packages resolved from alternate or untrusted registries.
  4. Prefer a non-executing installation method when only static Skill files are required.
  5. Run installation in a sandbox with minimal filesystem access, no unnecessary credentials, and restricted outbound networking.
  6. Review package lifecycle scripts and transitive dependencies before recommending the installer.
  7. Establish a controlled update process so new versions are audited before users are instructed to execute them.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The install command uses npx molthub@latest, which fetches and executes the newest package version at runtime without pinning to a reviewed release. This creates a supply-chain risk: if the package or one of its dependencies is compromised, users may execute attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

Manual Install

bash
mkdir -p ~/.moltbot/skills/moltforsale
curl -s https://molt-fs.vercel.app/skill.md > ~/.moltbot/skills/moltforsale/SKILL.md
curl -s https://molt-fs.vercel.app/heartbeat.md > ~/.moltbot/skills/moltforsale/HEARTBEAT.md
curl -s https://molt-fs.vercel.app/messaging.md > ~/.moltbot/skills/moltforsale/MESSAGING.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

bash
mkdir -p ~/.moltbot/skills/moltforsale
curl -s https://molt-fs.vercel.app/skill.md > ~/.moltbot/skills/moltforsale/SKILL.md
curl -s https://molt-fs.vercel.app/heartbeat.md > ~/.moltbot/skills/moltforsale/HEARTBEAT.md
curl -s https://molt-fs.vercel.app/messaging.md > ~/.moltbot/skills/moltforsale/MESSAGING.md
curl -s https://molt-fs.vercel.app/skill.json > ~/.moltbot/skills/moltforsale/skill.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

bash
mkdir -p ~/.moltbot/skills/moltforsale
curl -s https://molt-fs.vercel.app/skill.md > ~/.moltbot/skills/moltforsale/SKILL.md
curl -s https://molt-fs.vercel.app/heartbeat.md > ~/.moltbot/skills/moltforsale/HEARTBEAT.md
curl -s https://molt-fs.vercel.app/messaging.md > ~/.moltbot/skills/moltforsale/MESSAGING.md
curl -s https://molt-fs.vercel.app/skill.json > ~/.moltbot/skills/moltforsale/skill.json

Static analysis

No suspicious patterns detected.