T09 · Insecure Skill Coding Practices
- Location
scripts/post.py:22- Finding
Hardcoded Moltbook API Credential Used as an Automatic Fallback
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill does what it says by posting to Moltbook, but it ships and automatically uses a shared API key and can publish user content externally, so it needs review before installation.
Install only if you intend to let the agent publish posts to Moltbook. Do not rely on the bundled API key; it should be removed and rotated, and users should provide their own scoped credential. Confirm post content before sending, and treat the advertised comment/upvote support as unimplemented unless additional reviewed code is added.
scripts/post.py:22Hardcoded Moltbook API Credential Used as an Automatic Fallback
The manifest claims support for commenting and upvoting, but the documented implementation and workflow only cover post creation. This mismatch can mislead users and reviewers about what the skill really does, weakening trust, approval decisions, and safety review of side-effecting actions on an external platform.
The documentation explicitly allows use of an embedded fallback API key when no user environment variable is set. That encourages unauthorized use of someone else's credential, creates accountability and abuse risks, and may expose the key through distribution, logs, or reverse engineering.
The script embeds a default API key directly in code and silently uses it when no environment variable is set. Hardcoded secrets are dangerous because anyone with code access can reuse the credential to impersonate the skill, post unauthorized content, and potentially consume or abuse the associated account or service quota.
The skill advertises network access and use of environment secrets but does not declare any explicit tool scope such as permissions or allowed-tools. That increases the chance of overbroad execution in hosts that rely on manifest-level scoping, making unintended secret access or outbound requests harder to constrain or review.
The documentation broadly claims posting, commenting, and upvoting support while only naming scripts/post.py as the implementation path. In a skill that performs external side effects, incomplete or inflated capability claims reduce transparency and can cause operators to authorize behavior they cannot actually inspect or control.
The skill instructs use of an API key and mentions fallback to a built-in key without clearly warning that user-provided content will be transmitted to an external service. In a posting skill, that creates meaningful risk of users unknowingly sending private or sensitive data off-platform and obscures whose credentials are being used.
技能清单描述声称支持“发文字帖、链接帖、评论、点赞”,但此文件中的唯一核心行为是向 /api/v1/posts 发送 POST 请求创建帖子,并且命令行参数也仅覆盖标题、正文、链接和版块。没有任何评论或点赞相关接口、参数或分支逻辑,说明实现范围比描述更窄。
The script transmits user-provided title/content/URL to an external service without any explicit disclosure or confirmation step in the code path. In an agent skill context, this can cause unintended exfiltration of sensitive user data if the agent passes private notes, internal links, or confidential text to the remote API based on a natural-language trigger.
The manifest description, usage instructions, and operational guidance are entirely in Chinese, and the documented trigger phrases are Chinese-only. This can constitute a language/locale policy issue because the skill does not indicate user opt-in, multilingual support, or a justified region-specific constraint.
The prose in the file says the skill can '发帖、评论、点赞', and lists comment/upvote API endpoints, but the actionable implementation documentation only describes calling scripts/post.py and its post-related arguments. This is not merely incomplete API reference material; it presents the skill as operationally supporting actions that the documented code path does not perform.
The docstring, argparse description, and help messages are all written exclusively in Chinese, with no option to select another language or locale. Under the stated policy, forcing a single language without opt-in is a natural-language policy concern.
No suspicious patterns detected.