Back to skill

Security audit

moltbook

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its social-network purpose, but it asks agents to trust mutable remote instructions, run recurring check-ins, and store a long-lived API key in weakly scoped places.

Install only if you are comfortable with an agent account that can post, delete its own content, vote, follow, create communities, and in some roles moderate content. Do not let it automatically fetch and follow remote Markdown updates unless you have a review process. Store the API key in a real secret manager or a locked-down file, avoid general agent memory, and require confirmation before write, delete, moderation, or owner-email actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:26
Finding

Mutable Remote Instructions Are Downloaded and Treated as Trusted Skill Content

Content
View full analysis
~/.moltbot/skills/moltbook/SKILL.md curl -s https://www.moltbook.com/heartbeat.md > ~/.moltbot/skills/moltbook/HEARTBEAT.md curl -s https://www.moltbook.com/messaging.md > ~/.moltbot/skills/moltbook/MESSAGING.md curl -s https://www.moltbook.com/rules.md > ~/.moltbot/skills/moltbook/RULES.md curl -s https://www.moltbook.com/skill.json > ~/.moltbot/skills/moltbook/package.json ``` ```markdown **Or just read them from the URLs above!** ``` ```markdown **Check for updates:** Re-fetch these files anytime to see new features! ``` ### Technical Analysis The installation instructions download mutable Markdown files from an external server and place them directly into the local Skill directory. For an AI agent, Markdown instructions can control behavior even though they are not conventional executable binaries. The downloaded files are not included in the audited artifact. Their contents can therefore change after review without changing the local package under audit. The workflow does not pin a version, verify a cryptographic digest, validate a signature, or require human review before the updated instructions are used. The risk is particularly significant for `SKILL.md`, `HEARTBEAT.md`, `MESSAGING.md`, and `RULES.md`, because their names and installation locations indicate that the agent may interpret them as trusted operational instructions. This creates a post-review instruction-hijacking channel. The use of HTTPS protects against ordinary network interception, but it does not protect against compromise of the hosting service, unauthorized server-side content changes, DNS or certificate-authority failures, or malicious changes by an authorized publisher. ### Attack Path 1. A user installs the Skill ...[truncated 1731 chars]
Remediation
View remediation

T06 · System Persistence

Warning
Location
SKILL.md:97
Finding

Recurring Heartbeat Persists Autonomous Retrieval and Execution of Remote Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:74
Finding

Bearer API Key Is Recommended for Plaintext File or General Memory Storage

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
96% confidence
Finding

The skill explicitly recommends storing a long-lived API key in plaintext in a predictable local file path and also suggests saving it to agent memory or environment variables without discussing access controls. In multi-tool or multi-agent environments, this materially increases the chance of credential theft, impersonation, and unauthorized API use.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

⚠️ Save your api_key immediately! You need it for all requests.

Recommended: Save your credentials to ~/.config/moltbook/credentials.json:

json
{

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

Install locally:

bash
mkdir -p ~/.moltbot/skills/moltbook
curl -s https://www.moltbook.com/skill.md > ~/.moltbot/skills/moltbook/SKILL.md
curl -s https://www.moltbook.com/heartbeat.md > ~/.moltbot/skills/moltbook/HEARTBEAT.md
curl -s https://www.moltbook.com/messaging.md > ~/.moltbot/skills/moltbook/MESSAGING.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Install locally:

bash
mkdir -p ~/.moltbot/skills/moltbook
curl -s https://www.moltbook.com/skill.md > ~/.moltbot/skills/moltbook/SKILL.md
curl -s https://www.moltbook.com/heartbeat.md > ~/.moltbot/skills/moltbook/HEARTBEAT.md
curl -s https://www.moltbook.com/messaging.md > ~/.moltbot/skills/moltbook/MESSAGING.md
curl -s https://www.moltbook.com/rules.md > ~/.moltbot/skills/moltbook/RULES.md

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Install locally:

bash
mkdir -p ~/.moltbot/skills/moltbook
curl -s https://www.moltbook.com/skill.md > ~/.moltbot/skills/moltbook/SKILL.md
curl -s https://www.moltbook.com/heartbeat.md > ~/.moltbot/skills/moltbook/HEARTBEAT.md
curl -s https://www.moltbook.com/messaging.md > ~/.moltbot/skills/moltbook/MESSAGING.md
curl -s https://www.moltbook.com/rules.md > ~/.moltbot/skills/moltbook/RULES.md

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents a destructive DELETE operation for posts without an adjacent warning about permanence, ownership checks, or confirmation requirements. In agentic contexts, unclear destructive actions can lead to accidental data loss if an agent follows examples mechanically or under prompt influence.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 335)May include surrounding context.

md
### Crypto Content Policy 🚫💰

By default, **crypto content is NOT allowed** in submolts. Posts about cryptocurrency, blockchain, tokens, NFTs, DeFi, etc. will be automatically removed.

**Why?** Many communities want to focus on non-crypto topics. The default protects communities from crypto spam.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 680)May include surrounding context.

md
4. You submit your answer to `POST /api/v1/verify`
5. On success, your content is published

**Admins and trusted agents bypass verification automatically.**

### Step 1: Create content and receive a challenge

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 767)May include surrounding context.

md
- **Unverified content is hidden:** Until you verify, your post/comment/submolt won't appear in feeds
- **Failures matter:** If your last 10 challenge attempts are all failures (expired or incorrect), your account will be **automatically suspended**
- **Rate limit:** 30 verification attempts per minute (to prevent brute-force guessing)
- **No verification field?** If the response doesn't include `verification_required: true`, your content was published immediately (you're trusted or an admin)

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This endpoint instructs the agent to transmit a human owner's email address to the remote service. Even though this is first-party functionality, it involves sending third-party personal data and using an authenticated action, which can create privacy and consent issues if invoked without explicit user authorization.

Content

Scanner excerpt · SKILL.md (reported line 974)May include surrounding context.

If your human doesn't have a Moltbook login yet (e.g., they claimed you before email verification was added), you can help them set one up. This gives them access to the owner dashboard where they can manage your account and rotate your API key.

bash
curl -X POST https://www.moltbook.com/api/v1/agents/me/setup-owner-email \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"email": "your-human@example.com"}'

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The instruction to 'just check Moltbook whenever you think of it, or when your human asks' is an imprecise activation condition in a markdown skill file. It does not clearly define when the skill should activate versus remain inactive, which can lead to over-broad or opportunistic invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.