Back to skill

Security audit

Moltbook Poster

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says by posting to Moltbook, but it ships and automatically uses a shared API key and can publish user content externally, so it needs review before installation.

Install only if you intend to let the agent publish posts to Moltbook. Do not rely on the bundled API key; it should be removed and rotated, and users should provide their own scoped credential. Confirm post content before sending, and treat the advertised comment/upvote support as unimplemented unless additional reviewed code is added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/post.py:22
Finding

Hardcoded Moltbook API Credential Used as an Automatic Fallback

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest claims support for commenting and upvoting, but the documented implementation and workflow only cover post creation. This mismatch can mislead users and reviewers about what the skill really does, weakening trust, approval decisions, and safety review of side-effecting actions on an external platform.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation explicitly allows use of an embedded fallback API key when no user environment variable is set. That encourages unauthorized use of someone else's credential, creates accountability and abuse risks, and may expose the key through distribution, logs, or reverse engineering.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script embeds a default API key directly in code and silently uses it when no environment variable is set. Hardcoded secrets are dangerous because anyone with code access can reuse the credential to impersonate the skill, post unauthorized content, and potentially consume or abuse the associated account or service quota.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises network access and use of environment secrets but does not declare any explicit tool scope such as permissions or allowed-tools. That increases the chance of overbroad execution in hosts that rely on manifest-level scoping, making unintended secret access or outbound requests harder to constrain or review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation broadly claims posting, commenting, and upvoting support while only naming scripts/post.py as the implementation path. In a skill that performs external side effects, incomplete or inflated capability claims reduce transparency and can cause operators to authorize behavior they cannot actually inspect or control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs use of an API key and mentions fallback to a built-in key without clearly warning that user-provided content will be transmitted to an external service. In a posting skill, that creates meaningful risk of users unknowingly sending private or sensitive data off-platform and obscures whose credentials are being used.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

技能清单描述声称支持“发文字帖、链接帖、评论、点赞”,但此文件中的唯一核心行为是向 /api/v1/posts 发送 POST 请求创建帖子,并且命令行参数也仅覆盖标题、正文、链接和版块。没有任何评论或点赞相关接口、参数或分支逻辑,说明实现范围比描述更窄。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script transmits user-provided title/content/URL to an external service without any explicit disclosure or confirmation step in the code path. In an agent skill context, this can cause unintended exfiltration of sensitive user data if the agent passes private notes, internal links, or confidential text to the remote API based on a natural-language trigger.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest description, usage instructions, and operational guidance are entirely in Chinese, and the documented trigger phrases are Chinese-only. This can constitute a language/locale policy issue because the skill does not indicate user opt-in, multilingual support, or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The prose in the file says the skill can '发帖、评论、点赞', and lists comment/upvote API endpoints, but the actionable implementation documentation only describes calling scripts/post.py and its post-related arguments. This is not merely incomplete API reference material; it presents the skill as operationally supporting actions that the documented code path does not perform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring, argparse description, and help messages are all written exclusively in Chinese, with no option to select another language or locale. Under the stated policy, forcing a single language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.