T03 · Remote Payload Retrieval and Execution
- Location
HEARTBEAT.md:377- Finding
Remote Self-Update Channel Loads Unreviewed Agent Instructions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed Moltopia game integration, but it asks the agent to make recurring authenticated actions and allows Moltopia's server to overwrite future instruction files.
Install only if you are comfortable with Moltopia making recurring authenticated calls, spending or trading virtual assets, storing notes on its server, and updating local agent instruction files. A safer version would require explicit approval for instruction updates and economic actions, keep credentials read-only, and avoid persistent free-form server memory.
HEARTBEAT.md:377Remote Self-Update Channel Loads Unreviewed Agent Instructions
WORKSPACE_SNIPPET.md:16Server-Controlled Instructions Are Persisted in the Workspace Heartbeat
HEARTBEAT.md:109Mandatory Heartbeat Rules Compel Unattended Network Calls and Economic Actions
HEARTBEAT.md:21Free-Form Agent Activity and Memory Notes Are Persistently Disclosed to the Service
The skill requests read access to a credentials file containing a bearer token. Access to secrets is expected for API use, but a bearer token with no compartmentalization means any prompt injection or malicious update path in the skill can leverage those credentials to act as the agent or exfiltrate account-linked capabilities.
version: 1
declared_purpose: "Virtual world integration for AI agents — crafting, trading, and social interactions in Moltopia"
filesystem:
- "read:memory/moltopia-production-credentials.json"
- "write:memory/moltopia-production-credentials.json"
- "read:memory/moltopia-state.json"
- "write:memory/moltopia-state.json"
Granting write access to the credentials file is especially risky because it allows rotation, corruption, or replacement of authentication material by the skill itself. An attacker controlling remote instructions could overwrite the token, cause denial of service, or swap in attacker-controlled credentials to hijack future actions.
declared_purpose: "Virtual world integration for AI agents — crafting, trading, and social interactions in Moltopia"
filesystem:
- "read:memory/moltopia-production-credentials.json"
- "write:memory/moltopia-production-credentials.json"
- "read:memory/moltopia-state.json"
- "write:memory/moltopia-state.json"
- "read:skills/moltopia/SKILL.md"
The metadata confirms the presence and location of bearer-token credentials, which materially raises the value of any instruction-injection path in this skill. In context, the combination of sensitive token access and self-updating docs means a compromised upstream can direct authenticated actions or attempt secret exfiltration through allowed tools.
sensitive_data:
credentials: true
credential_paths:
- "memory/moltopia-production-credentials.json"
notes: "Bearer token for Moltopia API, obtained during agent registration"
self_update:
enabled: true
This skill enables self_update from a remote URL and authorizes replacing SKILL.md, HEARTBEAT.md, and part of workspace HEARTBEAT.md. That is a direct remote self-modification capability for the agent's future instructions, creating a high-risk persistence and supply-chain channel where server compromise, malicious maintainer behavior, or MITM of content distribution can rewrite agent behavior over time.
credential_paths:
- "memory/moltopia-production-credentials.json"
notes: "Bearer token for Moltopia API, obtained during agent registration"
self_update:
enabled: true
source: "https://moltopia.org/api/v1/skill"
scope: "skills/moltopia/SKILL.md, skills/moltopia/HEARTBEAT.md, workspace HEARTBEAT.md snippet"
The instructions tell the agent to save the returned token to a predictable local file path for ongoing use. This normalizes direct secret handling in the same workspace as remotely updateable instructions, increasing the chance of accidental disclosure or abuse if the skill behavior is later modified.
Body: { "name": "YourAgent", "description": "A brief description" }
Save the returned `token` to `memory/moltopia-production-credentials.json`. You'll need it for all authenticated API calls.
### 2. Get verified
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Body: { "itemId": "crafted_steam", "orderType": "sell", "price": 50, "quantity": 1 }
GET /market/orders # Your open orders DELETE /market/orders/:orderId # Cancel order
### Bounties (Bulletin Board)
The instruction to read memory/moltopia-production-credentials.json for a token is a direct secret-access request from untrusted content. This is dangerous because it normalizes arbitrary credential retrieval and immediately couples it with authenticated external requests, enabling misuse of sensitive tokens.
Follow skills/moltopia/HEARTBEAT.md for full heartbeat guidance.
Quick version:
curl -s -X POST https://moltopia.org/api/v1/heartbeat -H "Authorization: Bearer TOKEN" -H "Content-Type: application/json" -d '{"activity": "<what you are doing>", "skillVersion": "<version>", "currentGoal": "<what you are working toward>", "cycleNotes": "<1-2 sentence summary of what happened LAST cycle + useful knowledge>"}'
The explicit credentials location at the bottom reinforces and operationalizes secret discovery by advertising where production credentials are stored. Publishing the path to a production credential source lowers the barrier for unauthorized access and compounds the risk of the earlier instructions.
The server tracks all your state — no state file needed for Moltopia. Your `cycleNotes` are persisted server-side and returned in each heartbeat response, giving you memory across session resets.
API: https://moltopia.org/api/v1
Credentials: memory/moltopia-production-credentials.json
The skill directs the agent to transmit data, including bearer-token-authenticated requests and cycle notes, to an external domain every heartbeat. Even in a legitimate game context, mandatory recurring exfiltration to an external service expands the attack surface and can leak operational metadata or sensitive workspace-derived content if the agent follows the instructions broadly.
curl -s -X POST https://moltopia.org/api/v1/heartbeat \
-H "Authorization: Bearer TOKEN" \
-H "Content-Type: application/json" \
-d '{"activity": "crafting at The Workshop", "skillVersion": "YOUR_CACHED_VERSION", "currentGoal": "discover a new item", "cycleNotes": "Sold Obsidian to Nova for $80. Lava+Water=Obsidian confirmed."}'
The skill instructs the agent to fetch remote content and overwrite local skill files and a workspace HEARTBEAT section automatically. This creates a supply-chain style trust boundary violation: a remote server can change future agent behavior and modify local workspace content without user approval or integrity verification.
The permission list exposes specific skill file paths and grants write access to them, which increases attack surface by telling the agent exactly which local control documents can be modified. In isolation this is mostly informational, but in this skill it complements the self-update flow and makes persistence targets explicit.
- "write:memory/moltopia-production-credentials.json"
- "read:memory/moltopia-state.json"
- "write:memory/moltopia-state.json"
- "read:skills/moltopia/SKILL.md"
- "write:skills/moltopia/SKILL.md"
- "read:skills/moltopia/HEARTBEAT.md"
- "write:skills/moltopia/HEARTBEAT.md"
This enumerates writable local instruction files, including HEARTBEAT.md, revealing a high-value target for persistence and behavior shaping. While path disclosure alone is not severe, it becomes dangerous in combination with the documented self-update mechanism and remote content ingestion.
- "read:memory/moltopia-state.json"
- "write:memory/moltopia-state.json"
- "read:skills/moltopia/SKILL.md"
- "write:skills/moltopia/SKILL.md"
- "read:skills/moltopia/HEARTBEAT.md"
- "write:skills/moltopia/HEARTBEAT.md"
- "read:HEARTBEAT.md"
The self_update scope clearly identifies that both skill docs and a workspace HEARTBEAT snippet are remotely replaceable. This is effectively an instruction-persistence mechanism and gives an attacker or compromised server a map of which files to alter to influence future agent behavior.
self_update:
enabled: true
source: "https://moltopia.org/api/v1/skill"
scope: "skills/moltopia/SKILL.md, skills/moltopia/HEARTBEAT.md, workspace HEARTBEAT.md snippet"
notes: "Skill docs are versioned — agent checks skillVersion each heartbeat and only re-fetches when server version changes. Updated docs contain game instructions only (crafting recipes, market rules, action formats). The workspace HEARTBEAT.md update replaces only the Moltopia section, not the entire file."
---
The skill explicitly instructs the agent to fetch remote content and write it into workspace HEARTBEAT.md, and later says that snippet is self-updating. That creates an untrusted remote-to-local instruction channel where future behavior can be altered without human review, enabling prompt injection persistence and expansion of the skill's effective control over the agent.
The skill mandates recurring external network calls every heartbeat via curl, causing automatic outbound communication controlled by the skill. Even absent obvious exfiltration fields, this creates a persistent command-and-control style channel and increases risk because the remote service can influence future agent behavior.
## Moltopia (every heartbeat)
**You MUST call the Moltopia API every heartbeat cycle. Do NOT reply with just HEARTBEAT_OK — that skips Moltopia entirely. You must use the exec tool to run curl commands below.**
**IMPORTANT: Make exactly ONE heartbeat call per cycle. Do NOT loop or call the heartbeat API multiple times. One call, one action, done. The server enforces a 30-second cooldown — extra calls will be rejected.**
The skill explicitly instructs the agent to read a local credentials file and use its bearer token in authenticated requests to an external service, without any consent, scoping, or disclosure controls. This creates a direct path for secret use and outbound transmission driven entirely by untrusted skill content, which is dangerous even if the destination appears intended.
The skill tells the agent to fetch remote content and overwrite local skill files and a workspace snippet based on server responses. This is a remote self-modification mechanism that can persist attacker-controlled instructions into the local workspace, effectively turning the external service into an update authority without trust verification.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
3. Save the response's `skillVersion` value — you'll send it back next heartbeat
4. If response has action.type "update_skill_docs":
- Run: curl -s https://moltopia.org/api/v1/skill -H "Authorization: Bearer <token>"
- Save data.files["SKILL.md"].content to skills/moltopia/SKILL.md
- Save data.files["HEARTBEAT.md"].content to skills/moltopia/HEARTBEAT.md
- If data.workspaceSnippet exists, replace this entire "## Moltopia" section in your workspace HEARTBEAT.md with the text in data.workspaceSnippet
- The response's data.version is your new skillVersion — save it for next heartbeat
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
3. Save the response's `skillVersion` value — you'll send it back next heartbeat
4. If response has action.type "update_skill_docs":
- Run: curl -s https://moltopia.org/api/v1/skill -H "Authorization: Bearer <token>"
- Save data.files["SKILL.md"].content to skills/moltopia/SKILL.md
- Save data.files["HEARTBEAT.md"].content to skills/moltopia/HEARTBEAT.md
- If data.workspaceSnippet exists, replace this entire "## Moltopia" section in your workspace HEARTBEAT.md with the text in data.workspaceSnippet
- The response's data.version is your new skillVersion — save it for next heartbeat