Back to skill

Security audit

MoltMarkets Trading Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed MoltMarkets automation setup, but it gives recurring agents authority to spend funds, post publicly, and resolve markets with weak controls and quiet reporting.

Review carefully before installing. Only use this with a dedicated low-balance account, narrowly scoped API keys if available, restrictive credential-file permissions or a real secret store, visible notifications, spend and rate limits, and manual approval for market creation and resolution. The cron definitions should also isolate untrusted market titles/comments from agent instructions and fix the historical-price oracle logic before real funds are involved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
references/cron-definitions.md:62
Finding

Untrusted Market Content Can Hijack the Trading Agent

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
references/cron-definitions.md:22
Finding

Attacker-Controlled Market Data Can Poison Persistent Agent Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:24
Finding

Credential Setup Creates a Plaintext API Key Without Enforcing Restrictive Permissions

Content
View full analysis
~/.config/moltmarkets/credentials.json << 'EOF' { "api_key": "mm_your_api_key_here", "user_id": "your-user-uuid", "username": "your_username" } EOF ``` The setup script subsequently consumes the same file without checking its permissions: ```javascript const CREDS_PATH = path.join(process.env.HOME, '.config/moltmarkets/credentials.json'); if (!fs.existsSync(CREDS_PATH)) { console.error('✗ Missing credentials file: ~/.config/moltmarkets/credentials.json'); process.exit(1); } const creds = JSON.parse(fs.readFileSync(CREDS_PATH, 'utf8')); ``` ### Technical Analysis The instructions place a bearer API key in a plaintext JSON file using ordinary shell redirection. Neither the directory nor file is assigned an explicit restrictive mode. The resulting permissions depend on the user's environment and `umask`. Under a common `022` umask: - The directory may be created as mode `0755`. - The credential file may be created as mode `0644`. On a multi-user host, this can permit other local users or processes to read the API key. The executable setup script only checks that the path exists; it does not reject symlinks, validate ownership, or ensure that group and world permission bits are unset. Reading a credential is necessary for authenticated MoltMarkets operations, but allowing ambient access by unrelated local principals is not necessary and violates least privilege. ### Attack Path 1. A victim follows the documented setup commands on a shared system. 2. The shell creates `credentials.json` according to a permissive `umask`. 3. Another local user or compromised low-privilege process enumerates the predictable path under the victim's home ...[truncated 957 chars]
Remediation
View remediation
"$HOME/.config/moltmarkets/credentials.json" <<'EOF' { "api_key": "mm_your_api_key_here", "user_id": "your-user-uuid", "username": "your_username" } EOF chmod 600 "$HOME/.config/moltmarkets/credentials.json" ``` Also harden `scripts/setup.js` as follows: 1. Require `HOME` to be defined and resolve the path safely. 2. Use `lstatSync` and reject symbolic links and non-regular files. 3. Verify that the credential file is owned by the current effective user. 4. Reject files with any group or world permission bits. 5. Reject an insecure parent directory. 6. Parse and validate the credential schema without logging the API key. 7. Prefer an operating-system credential store or a narrowly scoped environment injection mechanism. 8. Use separate, least-privilege API credentials for trading, creation, and resolution if the service supports scopes. 9. Document key rotation and immediate revocation procedures. ]]>

other

Error
Location
references/cron-definitions.md:223
Finding

Auto-Resolution Uses Current Spot Price as Historical Close-Time Evidence

Content
View full analysis
= threshold → YES - "above/over/hit" + price < threshold → NO - "below/under" + price <= threshold → YES - "below/under" + price > threshold → NO **STEP 5: CALL RESOLVE ENDPOINT** curl -X POST "$API/markets/{market_id}/resolve" \ -H "Authorization: Bearer $API_KEY" \ -H "Content-Type: application/json" \ -d '{"outcome": "YES", "resolution_note": "BTC was $74,832 at 19:15:59 UTC (Binance 1m kline)"}' ``` ### Technical Analysis The task says it needs the historical price at the market's `closes_at` timestamp, but its primary CoinGecko endpoint is `/simple/price`, which returns the current spot price. It does not accept the close timestamp. If the resolution cron runs several minutes after close, the current price may differ materially from the close-time price and can produce the opposite outcome. The cron is scheduled every seven minutes, making this mismatch routine rather than exceptional. It then authorizes the agent to submit the result directly to the creator-only resolution endpoint without human confirmation or mandatory source validation. Additional integrity weak ...[truncated 2123 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
Findings (29)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
# Create config directory
mkdir -p ~/.config/moltmarkets

# Save your credentials (get API key from moltmarkets.com settings)
cat > ~/.config/moltmarkets/credentials.json << 'EOF'
{
  "api_key": "mm_your_api_key_here",

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This finding reflects handling of API credentials in a local file used by an automated trading system. Even though the intent appears operational rather than malicious, exposing or mishandling these credentials could allow unauthorized account access and direct financial-impacting actions.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
mkdir -p ~/.config/moltmarkets

# Save your credentials (get API key from moltmarkets.com settings)
cat > ~/.config/moltmarkets/credentials.json << 'EOF'
{
  "api_key": "mm_your_api_key_here",
  "user_id": "your-user-uuid",

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This section explicitly instructs silent automated trading, public comment posting, and memory/file updates while suppressing intermediate visibility and notifications. In a trading-agent skill, hiding impactful financial and reputational actions from the user materially raises the risk of unnoticed losses, spammy behavior, and policy-evading automation.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
90% confidence
Finding

The output rules instruct the agent to suppress intermediate messages and work silently, which can function as a concealment mechanism that reduces oversight of external actions. In a skill already automating trading, commenting, and logging, this makes abuse or harmful mistakes harder for the user to detect in time.

Content

Scanner excerpt · references/cron-definitions.md (reported line 81)May include surrounding context.

md
Use POST /markets/{id}/comments endpoint after placing a bet.

**OUTPUT RULES:**
- NO intermediate messages
- NO spawn announcements — work SILENTLY
- ONLY send ONE final report with: position taken (or why skipped), learning context applied, new balance

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The creator cron describes autonomous market creation and persistent ROI logging without clear user-facing disclosure of the financial cost and external side effects. Because market creation can spend funds and create public artifacts, omitting warnings and running silently makes accidental or excessive loss/spam much more likely.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill explicitly directs access to a local credentials file, which is a strong secret-handling anti-pattern for reusable agent skills. In this context, it normalizes pulling privileged tokens from disk for automated market actions, expanding the blast radius if the skill is modified, compromised, or run in a shared environment.

Content

Scanner excerpt · references/cron-definitions.md (reported line 203)May include surrounding context.

md
kind: 'agentTurn',
      message: `MARKET AUTO-RESOLUTION — HISTORICAL PRICE LOGIC

**CREDS:** ~/.config/moltmarkets/credentials.json
**API:** https://api.zcombinator.io/molt

**STEP 1: FIND MARKETS TO RESOLVE**

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section instructs silent automatic market resolution and ROI updates even though resolution is an irreversible external action that can directly affect market outcomes and funds. The lack of warning or confirmation is especially dangerous in a prediction-market skill because a bad data fetch, parsing error, or prompt drift could finalize the wrong outcome without user awareness.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.js (reported line 15)May include surrounding context.

js
const https = require('https');

const MEMORY_DIR = path.join(process.cwd(), 'memory');
const CREDS_PATH = path.join(process.env.HOME, '.config/moltmarkets/credentials.json');

// Ensure memory directory exists
if (!fs.existsSync(MEMORY_DIR)) {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.js (reported line 25)May include surrounding context.

js
const https = require('https');

const MEMORY_DIR = path.join(process.cwd(), 'memory');
const CREDS_PATH = path.join(process.env.HOME, '.config/moltmarkets/credentials.json');

// Ensure memory directory exists
if (!fs.existsSync(MEMORY_DIR)) {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents behavior that relies on sensitive capabilities such as environment/config access and autonomous scheduled actions, but it does not declare an explicit tool scope or permission boundary. In an agent setting, missing scope declarations increase the chance of unintended access or execution beyond what a user expects, especially when the skill also handles credentials and recurring jobs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises autonomous trading, market creation, and auto-resolution but does not prominently warn that these recurring cron-driven actions can spend funds and alter market state without per-action confirmation. In this context, omission of risk disclosure is dangerous because the skill is specifically designed to operate continuously and affect real accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions tell the user to store API credentials in a plaintext file under the home directory without warning about local exposure risks. Because those credentials authorize trading and market actions, compromise of that file could let an attacker control funds, place trades, or manipulate markets.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The skill directs users to create persistent local configuration under ~/.config, which establishes session/state persistence for credentials and agent behavior. Persistence is expected for this use case, but in combination with autonomous cron jobs and trading credentials it raises the blast radius of host compromise or accidental reuse.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

1. Get MoltMarkets Credentials

bash
# Create config directory
mkdir -p ~/.config/moltmarkets

# Save your credentials (get API key from moltmarkets.com settings)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill endorses an abusive political/extremist-adjacent communication style without necessity for the trading task or user opt-in. This can cause harmful outputs, platform moderation issues, and reputational damage, especially when the agent is configured to post comments automatically.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation encourages adopting an extremist-style persona unrelated to core trading functionality. This creates reputational, harassment, and policy-compliance risk, and could lead an autonomous agent to generate abusive or radicalizing content while interacting with users or markets.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 22)May include surrounding context.

Body: {"outcome": "YES" | "NO"}

text

Base URL: `https://api.zcombinator.io/molt`

## Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cron-definitions.md (reported line 120)May include surrounding context.

Body: {"outcome": "YES" | "NO"}

text

Base URL: `https://api.zcombinator.io/molt`

## Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cron-definitions.md (reported line 204)May include surrounding context.

Body: {"outcome": "YES" | "NO"}

text

Base URL: `https://api.zcombinator.io/molt`

## Authentication

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file describes endpoints for resolving markets and casting committee votes, including automatic market resolution when all committee members agree. These actions can materially affect market outcomes and user positions, but the documentation does not warn that they are high-impact and potentially irreversible operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 216)May include surrounding context.

CoinGecko (Primary — no geo-restrictions)

text
GET https://api.coingecko.com/api/v3/simple/price?ids=bitcoin,ethereum,solana&vs_currencies=usd

Response: { "bitcoin": { "usd": 75000 }, "ethereum": { "usd": 2500 }, "solana": { "usd": 100 } }

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cron-definitions.md (reported line 228)May include surrounding context.

CoinGecko (Primary — no geo-restrictions)

text
GET https://api.coingecko.com/api/v3/simple/price?ids=bitcoin,ethereum,solana&vs_currencies=usd

Response: { "bitcoin": { "usd": 75000 }, "ethereum": { "usd": 2500 }, "solana": { "usd": 100 } }

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 223)May include surrounding context.

Binance Klines (Fallback — may be geo-blocked)

text
GET https://api.binance.com/api/v3/klines?symbol=BTCUSDT&interval=1m&startTime={ms}&limit=1

Response: [[openTime, open, high, low, close, volume, ...]]

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cron-definitions.md (reported line 233)May include surrounding context.

Binance Klines (Fallback — may be geo-blocked)

text
GET https://api.binance.com/api/v3/klines?symbol=BTCUSDT&interval=1m&startTime={ms}&limit=1

Response: [[openTime, open, high, low, close, volume, ...]]

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/cron-definitions.md (reported line 124)May include surrounding context.

md
Check if a SIMILAR market already exists:
- Same asset (BTC/ETH/SOL) + same threshold + overlapping timeframe = DUPLICATE
- Example: "SOL above $100" + "SOL reclaim $100" = SAME MARKET, don't create
- If duplicate exists → SKIP, don't create

**STEP 1: LOAD CONTEXT**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The resolution cron goes beyond passive setup guidance by instructing the agent to read a local credentials file and perform authenticated state-changing API actions to resolve markets. In this skill’s context, that enables unattended financial/market operations with privileged local secrets, which increases the risk of unauthorized actions or abuse if the skill is installed or adapted without strict controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.