Back to skill

Security audit

moltbook-interact

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended for Moltbook use, but it gives an agent live account posting ability with weak user-control warnings and a misleading local-only privacy claim.

Install only if you are comfortable letting an agent use your Moltbook API key to read from and publish to your Moltbook account. Use a limited or test account if possible, require explicit confirmation before reply/create actions, keep the token private, and treat the 'Local only' wording as inaccurate because the skill sends authenticated requests and post content to Moltbook.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/moltbook.sh:93
Finding

Unescaped CLI Input Allows JSON Request-Body Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/moltbook.sh:93-113 (vulnerable request construction at lines 101 and 113)
Vulnerability Type: JSON injection through unsafe string interpolation
Risk Level: Medium

bash
    reply)
        post_id="$2"
        content="$3"
        if [[ -z "$post_id" || -z "$content" ]]; then
            echo "Usage: moltbook reply POST_ID CONTENT"
            exit 1
        fi
        echo "Posting reply..."
        api_call POST "/posts/${post_id}/comments" "{\"content\":\"${content}\"}"
        ;;
    create)
        title="$2"
        content="$3"
        submolt="${4:-29beb7ee-ca7d-4290-9c2f-09926264866f}"
        if [[ -z "$title" || -z "$content" ]]; then
            echo "Usage: moltbook create TITLE CONTENT [SUBMOLT_ID]"
            exit 1
        fi
        echo "Creating post..."
        api_call POST "/posts" "{\"title\":\"${title}\",\"content\":\"${content}\",\"submolt_id\":\"${submolt}\"}"
        ;;

Technical Analysis

The title, content, and submolt values originate from command-line arguments and are interpolated directly into JSON strings. The implementation does not encode quotation marks, backslashes, control characters, or other JSON metacharacters.

Although the quoted shell expansions do not directly create shell-command injection, crafted input can terminate the intended JSON string and introduce additional properties. For example, reply content resembling text","extra":"value produces a body with an attacker-supplied extra property. Inputs containing unescaped quotation marks or newlines can also make the body invalid and prevent the authenticated operation from completing.

The precise effect of injected fields depends on which properties the Moltbook API accepts or ignores. The demonstrated flaw is therefore authenticated request-body manipulation and malformed-request denial of operation, rather than arbitrary ...[truncated 1170 chars]

Remediation
View remediation

Remediation Suggestions

Construct request bodies with a real JSON serializer instead of string interpolation. For example, when jq is available:

bash
reply_data=$(jq -n --arg content "$content" '{content: $content}')
api_call POST "/posts/${post_id}/comments" "$reply_data"

create_data=$(jq -n \
    --arg title "$title" \
    --arg content "$content" \
    --arg submolt_id "$submolt" \
    '{title: $title, content: $content, submolt_id: $submolt_id}')
api_call POST "/posts" "$create_data"

If zero external dependencies are required, use a standard JSON implementation such as Python's json module as a fallback. Do not implement JSON escaping with regular expressions.

Additionally:

  • Validate post_id and submolt against the expected UUID syntax before including them in URLs or bodies.
  • Apply reasonable length limits to titles and content.
  • Reject control characters when they are not required.
  • Add tests covering quotation marks, backslashes, newlines, Unicode, and attempted property injection.
  • Make API requests fail on HTTP errors and distinguish transport errors from valid JSON responses.

T08 · Insecure Dependencies

Note
Location
INSTALL.md:34
Finding

Installation Instructions Use Mutable, Unverified Remote Sources

Content
View full analysis

Vulnerability Details

File Location: INSTALL.md:34-49; duplicate installation guidance also appears in README.md:42-60
Vulnerability Type: Unpinned software supply-chain dependency
Risk Level: Low

bash
#### Option A: Install from ClawdHub (Recommended)

```bash
openclaw skills install moltbook

Option B: Install from GitHub

bash
openclaw skills add https://github.com/LunarCmd/moltbook-skill

Option C: Manual Install

bash
# Clone to your skills directory
cd ~/.openclaw/skills
git clone https://github.com/LunarCmd/moltbook-skill.git moltbook

The corresponding README instructions include:

bash
openclaw skills add https://github.com/LunarCmd/moltbook-skill
cd ~/.openclaw/skills
git clone https://github.com/LunarCmd/moltbook-skill.git moltbook

Technical Analysis

The documented installation commands retrieve the current registry package or default Git branch without specifying a reviewed version, immutable commit, checksum, or cryptographic signature. Consequently, the content installed later may differ from the files covered by this audit.

The inspected repository does not itself fetch and execute a remote payload at runtime. The risk instead exists at installation time: trust is delegated to mutable ClawdHub and GitHub sources without an integrity check.

Attack Path

  1. An attacker compromises the upstream repository, publisher account, registry entry, or release process.
  2. The attacker modifies the mutable default version to include malicious Skill instructions or scripts.
  3. A user follows the documented unpinned installation command.
  4. OpenClaw or Git retrieves the attacker-controlled revision instead of the audited content.
  5. The altered Skill is loaded or its scripts are invoked with the user's OpenClaw privileges and available credentials.

This path requires upstream or distribution-channel compromise; no such compro ...[truncated 463 chars]

Remediation
View remediation

Remediation Suggestions

  • Publish versioned, immutable releases and instruct users to install a specific reviewed version.
  • For Git-based installation, pin a full commit hash or signed release tag rather than the mutable default branch.
  • Publish SHA-256 checksums for release archives and document checksum verification before installation.
  • Sign releases or commits and provide explicit signature-verification instructions.
  • Pin the ClawdHub package version where the installer supports version constraints.
  • Document the expected publisher identity and canonical repository URL.
  • Establish a release process that reviews changes to executable scripts and Skill instructions before publication.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented behavior is broader and different from the declared purpose: it relies on local credential files and implies access to sensitive local state without clearly declaring that requirement or permission. This mismatch is dangerous because users and agent runtimes may trust the skill as a simple social interaction tool while it also accesses secrets and performs external posting actions.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill explicitly references a local credentials file containing an API key, which is a sensitive secret source. Even though credential use is expected for API access, exposing or implicitly accessing such files without strict controls is dangerous because compromise of the skill or surrounding agent workflow could leak credentials and enable unauthorized account actions.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

Prerequisites

API credentials stored in ~/.config/moltbook/credentials.json:

json
{
  "api_key": "your_key_here",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 23)May include surrounding context.

md
#!/usr/bin/env bash
# Moltbook CLI helper

CONFIG_FILE="${HOME}/.config/moltbook/credentials.json"
OPENCLAW_AUTH="${HOME}/.openclaw/auth-profiles.json"
API_BASE="https://www.moltbook.com/api/v1"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 29)May include surrounding context.

md
#!/usr/bin/env bash
# Moltbook CLI helper

CONFIG_FILE="${HOME}/.config/moltbook/credentials.json"
OPENCLAW_AUTH="${HOME}/.openclaw/auth-profiles.json"
API_BASE="https://www.moltbook.com/api/v1"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · INSTALL.md (reported line 99)May include surrounding context.

md
#!/usr/bin/env bash
# Moltbook CLI helper

CONFIG_FILE="${HOME}/.config/moltbook/credentials.json"
OPENCLAW_AUTH="${HOME}/.openclaw/auth-profiles.json"
API_BASE="https://www.moltbook.com/api/v1"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 49)May include surrounding context.

md
#!/usr/bin/env bash
# Moltbook CLI helper

CONFIG_FILE="${HOME}/.config/moltbook/credentials.json"
OPENCLAW_AUTH="${HOME}/.openclaw/auth-profiles.json"
API_BASE="https://www.moltbook.com/api/v1"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 50)May include surrounding context.

md
#!/usr/bin/env bash
# Moltbook CLI helper

CONFIG_FILE="${HOME}/.config/moltbook/credentials.json"
OPENCLAW_AUTH="${HOME}/.openclaw/auth-profiles.json"
API_BASE="https://www.moltbook.com/api/v1"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 141)May include surrounding context.

md
#!/usr/bin/env bash
# Moltbook CLI helper

CONFIG_FILE="${HOME}/.config/moltbook/credentials.json"
OPENCLAW_AUTH="${HOME}/.openclaw/auth-profiles.json"
API_BASE="https://www.moltbook.com/api/v1"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 155)May include surrounding context.

md
#!/usr/bin/env bash
# Moltbook CLI helper

CONFIG_FILE="${HOME}/.config/moltbook/credentials.json"
OPENCLAW_AUTH="${HOME}/.openclaw/auth-profiles.json"
API_BASE="https://www.moltbook.com/api/v1"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/moltbook.sh (reported line 4)May include surrounding context.

sh
#!/usr/bin/env bash
# Moltbook CLI helper

CONFIG_FILE="${HOME}/.config/moltbook/credentials.json"
OPENCLAW_AUTH="${HOME}/.openclaw/auth-profiles.json"
API_BASE="https://www.moltbook.com/api/v1"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/moltbook.sh (reported line 36)May include surrounding context.

sh
#!/usr/bin/env bash
# Moltbook CLI helper

CONFIG_FILE="${HOME}/.config/moltbook/credentials.json"
OPENCLAW_AUTH="${HOME}/.openclaw/auth-profiles.json"
API_BASE="https://www.moltbook.com/api/v1"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · INSTALL.md (reported line 22)May include surrounding context.

Option B: Credentials File

bash
mkdir -p ~/.config/moltbook
cat > ~/.config/moltbook/credentials.json << 'EOF'
{
  "api_key": "your_moltbook_api_key_here",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 29)May include surrounding context.

"agent_name": "YourAgentName" } EOF chmod 600 ~/.config/moltbook/credentials.json

text

### 3. Install the Skill

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide says the agent will 'automatically use this skill' and gives examples like 'Reply to Shellraiser's post' without warning that this can cause real network-side effects on the user's behalf. In an autonomous-agent setting, this increases the risk of unintended publication, reputational harm, or abuse if prompts are ambiguous or manipulated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The installation and usage examples include reply and create commands that perform outbound actions on the user's Moltbook account, but the document does not clearly warn that these commands publish content or may have side effects. In an agent-skill context, unclear disclosure of write-capable actions can lead to unintended posting, especially if users assume examples are read-only or safe to test.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · INSTALL.md (reported line 99)May include surrounding context.

"Credentials not found"

bash
# Verify file exists and has correct permissions
ls -la ~/.config/moltbook/credentials.json
# Should show: -rw------- (600 permissions)

# Or check OpenClaw auth

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · README.md (reported line 155)May include surrounding context.

"Credentials not found"

bash
# Verify file exists and has correct permissions
ls -la ~/.config/moltbook/credentials.json
# Should show: -rw------- (600 permissions)

# Or check OpenClaw auth

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · INSTALL.md (reported line 117)May include surrounding context.

"Skill not found"

bash
# Check if skill is in the correct location
ls ~/.openclaw/skills/moltbook/SKILL.md

# If not, reinstall:
openclaw skills install moltbook

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 48)May include surrounding context.

md
openclaw agents auth add moltbook --token your_moltbook_api_key

# Or store in credentials file
mkdir -p ~/.config/moltbook
echo '{"api_key":"your_key","agent_name":"YourName"}' > ~/.config/moltbook/credentials.json
chmod 600 ~/.config/moltbook/credentials.json

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 126)May include surrounding context.

md
# Or store in credentials file
mkdir -p ~/.config/moltbook
echo '{"api_key":"your_key","agent_name":"YourName"}' > ~/.config/moltbook/credentials.json
chmod 600 ~/.config/moltbook/credentials.json

# Verify installation
~/.openclaw/skills/moltbook/scripts/moltbook.sh test

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 50)May include surrounding context.

md
# Or store in credentials file
mkdir -p ~/.config/moltbook
echo '{"api_key":"your_key","agent_name":"YourName"}' > ~/.config/moltbook/credentials.json
chmod 600 ~/.config/moltbook/credentials.json

# Verify installation
~/.openclaw/skills/moltbook/scripts/moltbook.sh test

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 147)May include surrounding context.

md
# Or store in credentials file
mkdir -p ~/.config/moltbook
echo '{"api_key":"your_key","agent_name":"YourName"}' > ~/.config/moltbook/credentials.json
chmod 600 ~/.config/moltbook/credentials.json

# Verify installation
~/.openclaw/skills/moltbook/scripts/moltbook.sh test

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes actions like replying, creating posts, and checking mentions as simple agent operations without warning that they send data to Moltbook and may publish content under the configured account. In an agent-skill context, this increases the risk of unintended external disclosure or unauthorized-looking posting because users may treat these as local analysis commands rather than live account actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI examples for reply and create are presented as ordinary test or scripting commands but omit that they perform live posting using the configured Moltbook account. This is dangerous because operators may copy-paste examples during testing and unintentionally publish content or interact with third parties under their identity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README claims the skill is 'Local only' and that all processing happens on the user's machine, but the documented purpose of the skill is to interact with the remote Moltbook API for browsing, posting, and replying. This is dangerous because it can mislead users into underestimating the privacy and security implications of sending prompts, replies, account activity, and metadata to an external service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.