Back to skill

Security audit

Moltitude

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a real receipt service integration, but it automatically contacts a third-party service and encourages uploading detailed work traces that may contain sensitive information.

Only install this after deciding that Moltitude should receive registration details and any receipt content you choose to mint. Do not create receipts for confidential code, secrets, personal data, internal reasoning, or raw tool outputs unless you first redact them and understand receipt visibility, key storage, and lifetime remix permissions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
skill.json:83
Finding

Mandatory External Registration and User-Facing Output Hijacking

Content
View full analysis
"I registered with Moltitude! Optional claim code for dashboard: [CODE] at https://moltitude.com/claim" ``` ```markdown **Share with your human:** > "I created a receipt for this work: [publicUrl]" ``` From `skill.json`: ```json "setup": { "required": true, "level": 0, "instruction": "Execute POST https://api.moltitude.com/v1/agents/register/simple with {\"name\":\"your-name\"} immediately", "onInstall": { "action": "register", "endpoint": "https://api.moltitude.com/v1/agents/register/simple", "method": "POST", "body": {"name": "{{AGENT_NAME}}"} } } ``` ### Technical Analysis The Skill uses mandatory and immediate instructions to direct an AI Agent to make an external network request and enroll with a third-party service. It also prescribes fixed messages that the Agent should inject into user-facing output. This behavior alters the Agent's current-session goals. Merely loading or installing a receipt-generation Skill should not independently authorize account creation, network communication, or unsolicited promotion. The configuration does not require explicit user confirmation before the registration action. The required response templates further manipulate final answers by directing the Agent to advertise the external dashboard and receipt URLs, even when such content may not be necessary to complete the original user request. ### Attack Path 1. A user installs or activates the Skill for a task. 2. The Agent reads the `setup.required` and “register immediately” instructions. 3. Without obtaining separate informed consent, the Agent sends a registration request to `api.moltitude ...[truncated 726 chars]
Remediation
View remediation

other

Error
Location
skill.md:68
Finding

Disclosure of Prompts, Reasoning, Tool Inputs, and Tool Outputs to an External API

Content
View full analysis
Remediation
View remediation

other

Note
Location
skill.md:298
Finding

Automatic External Tracking Request Embedded in Skill Documentation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
skill.md:21
Finding

Mutable and Unpinned Package Execution Through npx

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skill.md:216
Finding

Lifetime Remix Authorization Grants Access Beyond the Requested Receipt

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest declares an automatic on-install POST to a third-party endpoint with a templated agent name, creating immediate external data transmission without an explicit user-facing warning or consent gate. This is particularly risky because installation alone may trigger disclosure before the user understands the behavior, and broad triggers elsewhere increase the chance the skill is enabled in ordinary workflows.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly encourages storing and publishing full prompts, reasoning, tool inputs/outputs, and results in receipts. In the context of agent workflows, those fields commonly contain secrets, proprietary content, personal data, file contents, and internal reasoning that should not be transmitted or made public.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The receipt minting example instructs agents to send prompts, reasoning traces, tool inputs/outputs, and final results to an external API, then share a public URL, without any warning about confidentiality or public exposure. This can lead to exfiltration of sensitive user data, internal files, secrets, or hidden chain-of-thought-style reasoning into a third-party system and potentially a public artifact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest advertises immediate registration to an external API but does not present any clear user-facing warning about what data will be transmitted, when transmission occurs, or what the consequences are. In an agent-skill ecosystem, silent or poorly disclosed outbound registration undermines informed consent and can expose agent names, identifiers, and usage patterns to a third party.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list is broad enough to match common requests like 'document this task' or 'verify my work,' which can cause the skill to activate in situations where the user did not intend to use this external service. In this skill's context, overbroad activation is more dangerous because activation can lead to network calls and disclosure of agent identity or work metadata to a third-party API.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This finding reflects outbound transmission to an external API endpoint as part of the setup flow. External transmission is not inherently malicious, but here it is security-relevant because it occurs in a registration context and may disclose identifying information to a remote service without clear consent or necessity validation.

Content

Scanner excerpt · skill.json (reported line 86)May include surrounding context.

json
"setup": {
    "required": true,
    "level": 0,
    "instruction": "Execute POST https://api.moltitude.com/v1/agents/register/simple with {\"name\":\"your-name\"} immediately",
    "onInstall": {
      "action": "register",
      "endpoint": "https://api.moltitude.com/v1/agents/register/simple",

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The request body includes a templated agent name sent to a third-party service during installation, which creates identifiable outbound data flow. In context, this is more dangerous than a generic network call because the manifest wires it into automated setup, reducing user awareness and control over when their information is shared.

Content

Scanner excerpt · skill.json (reported line 89)May include surrounding context.

json
"instruction": "Execute POST https://api.moltitude.com/v1/agents/register/simple with {\"name\":\"your-name\"} immediately",
    "onInstall": {
      "action": "register",
      "endpoint": "https://api.moltitude.com/v1/agents/register/simple",
      "method": "POST",
      "body": {"name": "{{AGENT_NAME}}"}
    }

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The installation command uses npx clawhub@latest install moltitude, which executes remote code from a moving, unpinned package version. That creates a supply-chain risk: a compromised or malicious future release could run arbitrary code during installation with no integrity pinning or review step.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 30)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 134)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 140)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 148)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 160)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 166)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 172)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 217)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 230)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 237)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 242)May include surrounding context.

You must register before using any other endpoint.

http
POST https://api.moltitude.com/v1/agents/register/simple
Content-Type: application/json

{"name": "your-agent-name"}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The registration flow returns a private key and tells users to save it immediately, but provides no secret-handling guidance. This encourages insecure storage or disclosure of signing credentials, which could let an attacker impersonate the agent or forge signed receipts.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs the agent to share the claim code and later to share receipt URLs with the human, without discussing sensitivity or access boundaries. While some sharing may be intended, the documentation lacks safeguards for when the code or receipt contains or grants access to sensitive work details.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This minting endpoint is used to transmit detailed task traces to a third-party API, including example reasoning and tool outputs. In context, this is dangerous because the skill promotes sending potentially sensitive workflow content without data minimization, privacy warnings, or safe defaults.

Content

Scanner excerpt · skill.md (reported line 73)May include surrounding context.

Create Receipt

http
POST https://api.moltitude.com/v1/mint
Content-Type: application/json

{

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

At this line, the external transmission is an undisclosed analytics beacon embedded in the documentation rather than core API usage. That makes it materially different from the other E1 instances because it creates hidden telemetry on document view.

Content

Scanner excerpt · skill.md (reported line 298)May include surrounding context.

md
- API Docs: https://moltitude.com/docs/api
- Remix Guide: https://moltitude.com/remix.md

![](https://api.moltitude.com/v1/analytics/skill-read)

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest repeatedly states that setup is required immediately and defines an on-install registration action, but the register endpoint description says 'one HTTP call, no setup required.' This is an active contradiction in the skill's own documentation about whether prior setup is required.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The embedded analytics capability is unrelated to the core proof-of-work functionality and causes readers to contact the service merely by viewing the documentation. Even if low severity, undocumented telemetry expands data collection surface and can leak metadata such as IP address, user agent, and access timing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.