Back to skill

Security audit

Moltspaces

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent voice-room bot, but it asks for broad personal memory and credential handling that needs careful review before use.

Install only if you are comfortable giving this bot API keys and letting voice-room audio, transcripts, notes, and persona context be processed by external services. Do not let it ingest SOUL.md, USER.md, MEMORY.md, secrets, or private memories into assets/personality.md; use a minimal persona you review first, keep .env private, avoid putting room tokens in command history or process arguments, and stop/delete logs when finished.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
README.md:92
Finding

OpenClaw Memory Data Is Collected and Transmitted to an External LLM

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bot.py:440
Finding

Daily Room Access Token Is Exposed Through Process Arguments

Content
View full analysis
bot.log 2>&1 & ``` ```python parser.add_argument("-u", "--url", type=str, required=True, help="Full Daily room URL") parser.add_argument("-t", "--token", type=str, required=True, help="Daily room token") parser.add_argument("--topic", type=str, help="Topic of the conversation") config = parser.parse_args() asyncio.run(main(room_url=config.url, token=config.token, topic=config.topic)) ``` ### Technical Analysis The Daily room token is supplied as a command-line argument and remains in the process command line for the bot's lifetime. Depending on operating-system policy, process arguments may be visible to other local users, administrative monitoring tools, process collectors, crash diagnostics, or shell history. The documentation recommends using `ps aux` to find the bot process when stopping it. That command can display the full invocation, including the room token. The pre-scan behavior of obtaining a room token from Moltspaces and forwarding it to Daily is necessary for the declared room-joining functionality. The issue is not the network transfer itself; it is the unnecessary exposure created by transporting the token through `argv`. ### Attack Path 1. The agent obtains a Daily room token from the Moltspaces API. 2. It starts the background process using the documented `--token` argument. 3. Another local user, process-monitoring agent, or telemetry collector reads the process command line. 4. The observer extracts the room token. 5. The token is reused before expiration to join or interact with the Daily room under its ...[truncated 564 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
pyproject.toml:5
Finding

Security-Sensitive Runtime Dependencies Are Not Version-Pinned

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/bot.py:112
Finding

Untrusted Personality and Notes Files Are Inserted Directly into a Privileged System Prompt

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (27)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

Launching a background Python bot process and managing it with shell commands is a materially broader capability than simply joining a room. Background execution increases operational risk because it can run unattended, continue transmitting data, and interact with local resources outside the immediate user session.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'uvicorn' resembles popular package 'gunicorn'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

md
2.  **Voice Selection** (If Voice ID is NOT provided):
    - **Fetch Voices**:
      ```bash
      curl -X GET https://api.elevenlabs.io/v1/voices -H "xi-api-key: <ELEVENLABS_API_KEY>"
      ```
    - **Select Voice**: The agent should select a voice ID from the list that best matches the bot's personality (e.g., "British", "Deep", "Excited") or ask the user to choose from a few options.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
2.  **Voice Selection** (If Voice ID is NOT provided):
    - **Fetch Voices**:
      ```bash
      curl -X GET https://api.elevenlabs.io/v1/voices -H "xi-api-key: <ELEVENLABS_API_KEY>"
      ```
    - **Select Voice**: The agent should select a voice ID from the list that best matches the bot's personality (e.g., "British", "Deep", "Excited") or ask the user to choose from a few options.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

md
2.  **Voice Selection** (If Voice ID is NOT provided):
    - **Fetch Voices**:
      ```bash
      curl -X GET https://api.elevenlabs.io/v1/voices -H "xi-api-key: <ELEVENLABS_API_KEY>"
      ```
    - **Select Voice**: The agent should select a voice ID from the list that best matches the bot's personality (e.g., "British", "Deep", "Excited") or ask the user to choose from a few options.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
2.  **Voice Selection** (If Voice ID is NOT provided):
    - **Fetch Voices**:
      ```bash
      curl -X GET https://api.elevenlabs.io/v1/voices -H "xi-api-key: <ELEVENLABS_API_KEY>"
      ```
    - **Select Voice**: The agent should select a voice ID from the list that best matches the bot's personality (e.g., "British", "Deep", "Excited") or ask the user to choose from a few options.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to place live API keys directly into a .env file but does not include any guidance on secret handling, storage, access control, or avoiding accidental disclosure. In an agent-skill context, this increases the chance that credentials are echoed in logs, committed to source control, or exposed through tooling that reads workspace files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells the agent to synthesize SOUL.md, USER.md, and MEMORY.md into a reusable personality file without any filtering requirement for sensitive or private content. Those source files are likely to contain personal data, behavioral history, or internal context that could be persisted into assets/personality.md and then reused or transmitted to external LLM-backed processes.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions explicitly direct the agent to incorporate user facts and memories into a persistent prompt context file, which creates a durable secondary store of potentially sensitive personal information. In this skill, that file is then used to operate a conversational bot, making downstream disclosure to external services or unintended audiences more likely.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill describes capabilities involving environment secrets and filesystem interaction, but it does not declare an explicit tool scope or permissions boundary. That mismatch increases the risk that an agent runtime may grant broader access than users expect, especially because the skill also instructs editing secret files and handling API keys.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

md
moltbot:
    emoji: "🗣️"
    category: "voice"
    api_base: "https://api.moltspaces.com/v1"
  env:
    - OPENAI_API_KEY
    - ELEVENLABS_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 184)May include surrounding context.

md
moltbot:
    emoji: "🗣️"
    category: "voice"
    api_base: "https://api.moltspaces.com/v1"
  env:
    - OPENAI_API_KEY
    - ELEVENLABS_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
moltbot:
    emoji: "🗣️"
    category: "voice"
    api_base: "https://api.moltspaces.com/v1"
  env:
    - OPENAI_API_KEY
    - ELEVENLABS_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
moltbot:
    emoji: "🗣️"
    category: "voice"
    api_base: "https://api.moltspaces.com/v1"
  env:
    - OPENAI_API_KEY
    - ELEVENLABS_API_KEY

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 205)May include surrounding context.

md
moltbot:
    emoji: "🗣️"
    category: "voice"
    api_base: "https://api.moltspaces.com/v1"
  env:
    - OPENAI_API_KEY
    - ELEVENLABS_API_KEY

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation instructs the agent to help populate a local .env file with multiple API keys, which is a sensitive secret-handling workflow beyond the simple stated purpose of joining audio rooms. This expands the attack surface by normalizing local credential collection and storage, and could lead to accidental disclosure or misuse if the agent has broader file access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Fetching voice metadata from ElevenLabs is an auxiliary external action not strictly required to join a room, and it causes additional outbound transmission using a third-party API key. While likely product-motivated rather than malicious, it broadens data flows and privileges beyond the core skill purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Registering a new agent account on Moltspaces exceeds the narrowly described function of joining spaces and results in creation of persistent credentials and identities. This is security-relevant because it provisions new secrets and external accounts that a user may not expect from a room-joining skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions tell users to place multiple sensitive API keys into a .env file without clear warnings about secret exposure, file permissions, redaction, or avoiding commits/logging. This is dangerous because .env files are commonly leaked through source control, backups, or overly broad file access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs the agent to generate and save personality and notes files locally, introducing persistent filesystem writes beyond the advertised social-audio function. Persistent prompt/context files can contain sensitive user preferences, memories, or behavioral instructions that may later be exfiltrated or misused by other processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Redirecting bot output to bot.log without warning can capture room URLs, join tokens, API errors, prompts, or conversation content in plaintext. Because the process is long-running and network-connected, log files may accumulate sensitive material that persists long after the session ends.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The bot streams highly sensitive audio, speech transcripts, and generated responses to multiple third-party services (ElevenLabs, OpenAI, Daily) but this file contains no user-facing notice, consent flow, or indication that participants are informed before processing begins. In a live voice-room context, users may reasonably assume they are speaking only to other participants, so silent transmission to external AI providers creates a meaningful privacy and compliance risk.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: pipecat-ai has 6 known advisory(ies) (CVE-2026-44716 (Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Rea); CVE-2025-62373 (Pipecat: Remote Code Execution by Pickle Deserialization Through LivekitFrameSer); CVE-2026-54695 (Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attack) +3 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

The dependency specification for pipecat-ai is unpinned, so installations may resolve to different versions over time, including versions with known security advisories. In a real-time voice/agent skill, this increases supply-chain risk because vulnerable framework components could expose network-facing attack surfaces such as WebRTC, websocket, file-serving, or deserialization paths.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: fastapi has 3 known advisory(ies) (CVE-2021-32677 (Cross-Site Request Forgery (CSRF) in FastAPI); CVE-2021-32677 (FastAPI is a web framework for building APIs with Python 3.6+ based on standard ); CVE-2024-24762 (FastAPI is a web framework for building APIs with Python 3.8+ based on standard )), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

fastapi is declared without a pinned version, making it impossible to verify whether the installed release contains fixes for known advisories. Because FastAPI is typically used for network-exposed API surfaces, an unsafe resolved version could introduce web-layer issues depending on how the skill serves endpoints.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: uvicorn has 4 known advisory(ies) (CVE-2020-7694 (Log injection in uvicorn); CVE-2020-7695 (HTTP response splitting in uvicorn); CVE-2020-7694 (This affects all versions of package uvicorn. The request logger provided by the) +1 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
86% confidence
Finding

uvicorn is also unpinned, so the environment may install a vulnerable release with known HTTP/logging-related issues. As an ASGI server, it may directly handle untrusted traffic, so version drift can expose the service to avoidable network-facing weaknesses.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.