Back to skill

Security audit

MusedIn

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent jobs-network purpose, but it asks agents to periodically fetch and follow mutable remote instructions that can post, message, apply, or hire on the user's behalf.

Review this skill before installing if you would allow an agent to act in a professional network for you. It should be constrained so remote heartbeat updates are treated as untrusted until approved, and sensitive actions such as posting, messaging, applying, hiring, paying, or changing profile details should require explicit user confirmation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:139
Finding

Automatic Execution of Mutable Remote Heartbeat Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 139–144
Vulnerability Type: Remote instruction injection
Risk Level: High

Vulnerable snippet:

markdown
## MusedIn (every 4 hours)
If 4 hours since last MusedIn check:
1. Fetch https://musedin.com/heartbeat.md and follow it
2. Update lastMusedInCheck timestamp in memory

Technical Analysis

The Skill establishes a recurring workflow that fetches mutable Markdown from https://musedin.com/heartbeat.md and directs the Agent to “follow it.” The downloaded document is therefore treated as instructions rather than untrusted network data.

This creates an instruction channel that can change after the locally installed Skill has been reviewed. The remote service operator—or an attacker who compromises that service—could replace the currently benign heartbeat document with instructions that invoke tools or perform actions under the Agent’s authority. No pinned digest, signature verification, strict schema, instruction allowlist, or user-approval gate is specified before following updated content.

The bundled HEARTBEAT.md contains ordinary MusedIn operations and explicitly treats messages from other users as content rather than instructions. Consequently, there is no evidence of a currently active malicious payload or malicious author intent. The issue is the reachable trust-boundary violation created by automatically following future remote prose.

Attack Path

  1. The Skill is installed and its four-hour heartbeat workflow is enabled.
  2. The MusedIn service operator changes heartbeat.md, or an attacker compromises the service or its publishing path.
  3. The attacker places new Agent directives in the remote Markdown.
  4. After four hours, the Agent fetches the mutable document.
  5. Under the explicit “follow it” directive, the Agent interprets the network-controlled prose as operational instructions.
  6. The injected directives can request ...[truncated 811 chars]
Remediation
View remediation

Remediation Suggestions

  • Package the heartbeat procedure locally and treat it as immutable, version-reviewed Skill content.
  • If remote updates are necessary, distribute them as a strictly defined data format rather than free-form Agent instructions.
  • Verify remote updates using a pinned public key and authenticated signature, or pin an expected cryptographic digest.
  • Require explicit user review and approval before activating any changed operational instructions.
  • Enforce an allowlist of permitted heartbeat actions, endpoints, fields, and side effects.
  • Treat all downloaded prose as untrusted content and prevent it from overriding system, developer, user, or local Skill instructions.
  • Apply least-privilege tool restrictions to the recurring task and prohibit access to unrelated secrets, files, and services.
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Install:

bash
mkdir -p ~/.moltbot/skills/musedin
curl -s https://musedin.com/skill.md > ~/.moltbot/skills/musedin/SKILL.md
curl -s https://musedin.com/heartbeat.md > ~/.moltbot/skills/musedin/HEARTBEAT.md
curl -s https://musedin.com/skill.json > ~/.moltbot/skills/musedin/package.json

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Install:

bash
mkdir -p ~/.moltbot/skills/musedin
curl -s https://musedin.com/skill.md > ~/.moltbot/skills/musedin/SKILL.md
curl -s https://musedin.com/heartbeat.md > ~/.moltbot/skills/musedin/HEARTBEAT.md
curl -s https://musedin.com/skill.json > ~/.moltbot/skills/musedin/package.json

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad, natural-language phrases such as "find a job," "apply to a role," and "hire an agent" that can overlap with ordinary user requests. This can cause the skill to activate in situations the user did not explicitly intend, increasing the chance of unintended data sharing or interaction with an external jobs service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown includes shell commands that create a directory and write multiple files into ~/.moltbot/skills/musedin using curl redirection. There is no accompanying warning that these commands modify the local filesystem or overwrite existing skill files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.