T01 · Skill Instruction Hijacking
- Location
references/cron-definitions.md:62- Finding
Untrusted Market Content Can Hijack the Trading Agent
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed MoltMarkets automation setup, but it gives recurring agents authority to spend funds, post publicly, and resolve markets with weak controls and quiet reporting.
Review carefully before installing. Only use this with a dedicated low-balance account, narrowly scoped API keys if available, restrictive credential-file permissions or a real secret store, visible notifications, spend and rate limits, and manual approval for market creation and resolution. The cron definitions should also isolate untrusted market titles/comments from agent instructions and fix the historical-price oracle logic before real funds are involved.
references/cron-definitions.md:62Untrusted Market Content Can Hijack the Trading Agent
references/cron-definitions.md:22Attacker-Controlled Market Data Can Poison Persistent Agent Memory
SKILL.md:24Credential Setup Creates a Plaintext API Key Without Enforcing Restrictive Permissions
references/cron-definitions.md:223Auto-Resolution Uses Current Spot Price as Historical Close-Time Evidence
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Create config directory
mkdir -p ~/.config/moltmarkets
# Save your credentials (get API key from moltmarkets.com settings)
cat > ~/.config/moltmarkets/credentials.json << 'EOF'
{
"api_key": "mm_your_api_key_here",
This finding reflects handling of API credentials in a local file used by an automated trading system. Even though the intent appears operational rather than malicious, exposing or mishandling these credentials could allow unauthorized account access and direct financial-impacting actions.
mkdir -p ~/.config/moltmarkets
# Save your credentials (get API key from moltmarkets.com settings)
cat > ~/.config/moltmarkets/credentials.json << 'EOF'
{
"api_key": "mm_your_api_key_here",
"user_id": "your-user-uuid",
This section explicitly instructs silent automated trading, public comment posting, and memory/file updates while suppressing intermediate visibility and notifications. In a trading-agent skill, hiding impactful financial and reputational actions from the user materially raises the risk of unnoticed losses, spammy behavior, and policy-evading automation.
The output rules instruct the agent to suppress intermediate messages and work silently, which can function as a concealment mechanism that reduces oversight of external actions. In a skill already automating trading, commenting, and logging, this makes abuse or harmful mistakes harder for the user to detect in time.
Use POST /markets/{id}/comments endpoint after placing a bet.
**OUTPUT RULES:**
- NO intermediate messages
- NO spawn announcements — work SILENTLY
- ONLY send ONE final report with: position taken (or why skipped), learning context applied, new balance
The creator cron describes autonomous market creation and persistent ROI logging without clear user-facing disclosure of the financial cost and external side effects. Because market creation can spend funds and create public artifacts, omitting warnings and running silently makes accidental or excessive loss/spam much more likely.
The skill explicitly directs access to a local credentials file, which is a strong secret-handling anti-pattern for reusable agent skills. In this context, it normalizes pulling privileged tokens from disk for automated market actions, expanding the blast radius if the skill is modified, compromised, or run in a shared environment.
kind: 'agentTurn',
message: `MARKET AUTO-RESOLUTION — HISTORICAL PRICE LOGIC
**CREDS:** ~/.config/moltmarkets/credentials.json
**API:** https://api.zcombinator.io/molt
**STEP 1: FIND MARKETS TO RESOLVE**
This section instructs silent automatic market resolution and ROI updates even though resolution is an irreversible external action that can directly affect market outcomes and funds. The lack of warning or confirmation is especially dangerous in a prediction-market skill because a bad data fetch, parsing error, or prompt drift could finalize the wrong outcome without user awareness.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const https = require('https');
const MEMORY_DIR = path.join(process.cwd(), 'memory');
const CREDS_PATH = path.join(process.env.HOME, '.config/moltmarkets/credentials.json');
// Ensure memory directory exists
if (!fs.existsSync(MEMORY_DIR)) {
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
const https = require('https');
const MEMORY_DIR = path.join(process.cwd(), 'memory');
const CREDS_PATH = path.join(process.env.HOME, '.config/moltmarkets/credentials.json');
// Ensure memory directory exists
if (!fs.existsSync(MEMORY_DIR)) {
The skill documents behavior that relies on sensitive capabilities such as environment/config access and autonomous scheduled actions, but it does not declare an explicit tool scope or permission boundary. In an agent setting, missing scope declarations increase the chance of unintended access or execution beyond what a user expects, especially when the skill also handles credentials and recurring jobs.
The skill advertises autonomous trading, market creation, and auto-resolution but does not prominently warn that these recurring cron-driven actions can spend funds and alter market state without per-action confirmation. In this context, omission of risk disclosure is dangerous because the skill is specifically designed to operate continuously and affect real accounts.
The instructions tell the user to store API credentials in a plaintext file under the home directory without warning about local exposure risks. Because those credentials authorize trading and market actions, compromise of that file could let an attacker control funds, place trades, or manipulate markets.
The skill directs users to create persistent local configuration under ~/.config, which establishes session/state persistence for credentials and agent behavior. Persistence is expected for this use case, but in combination with autonomous cron jobs and trading credentials it raises the blast radius of host compromise or accidental reuse.
# Create config directory
mkdir -p ~/.config/moltmarkets
# Save your credentials (get API key from moltmarkets.com settings)
The skill endorses an abusive political/extremist-adjacent communication style without necessity for the trading task or user opt-in. This can cause harmful outputs, platform moderation issues, and reputational damage, especially when the agent is configured to post comments automatically.
The documentation encourages adopting an extremist-style persona unrelated to core trading functionality. This creates reputational, harassment, and policy-compliance risk, and could lead an autonomous agent to generate abusive or radicalizing content while interacting with users or markets.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Body: {"outcome": "YES" | "NO"}
Base URL: `https://api.zcombinator.io/molt`
## Authentication
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Body: {"outcome": "YES" | "NO"}
Base URL: `https://api.zcombinator.io/molt`
## Authentication
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Body: {"outcome": "YES" | "NO"}
Base URL: `https://api.zcombinator.io/molt`
## Authentication
This markdown file describes endpoints for resolving markets and casting committee votes, including automatic market resolution when all committee members agree. These actions can materially affect market outcomes and user positions, but the documentation does not warn that they are high-impact and potentially irreversible operations.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.coingecko.com/api/v3/simple/price?ids=bitcoin,ethereum,solana&vs_currencies=usd
Response: { "bitcoin": { "usd": 75000 }, "ethereum": { "usd": 2500 }, "solana": { "usd": 100 } }
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.coingecko.com/api/v3/simple/price?ids=bitcoin,ethereum,solana&vs_currencies=usd
Response: { "bitcoin": { "usd": 75000 }, "ethereum": { "usd": 2500 }, "solana": { "usd": 100 } }
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.binance.com/api/v3/klines?symbol=BTCUSDT&interval=1m&startTime={ms}&limit=1
Response: [[openTime, open, high, low, close, volume, ...]]
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
GET https://api.binance.com/api/v3/klines?symbol=BTCUSDT&interval=1m&startTime={ms}&limit=1
Response: [[openTime, open, high, low, close, volume, ...]]
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Check if a SIMILAR market already exists:
- Same asset (BTC/ETH/SOL) + same threshold + overlapping timeframe = DUPLICATE
- Example: "SOL above $100" + "SOL reclaim $100" = SAME MARKET, don't create
- If duplicate exists → SKIP, don't create
**STEP 1: LOAD CONTEXT**
The resolution cron goes beyond passive setup guidance by instructing the agent to read a local credentials file and perform authenticated state-changing API actions to resolve markets. In this skill’s context, that enables unattended financial/market operations with privileged local secrets, which increases the risk of unauthorized actions or abuse if the skill is installed or adapted without strict controls.
No suspicious patterns detected.