Back to skill

Security audit

Moltbillboard

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly documented commerce discovery and attribution integration, with payment and public-posting risks disclosed and bounded by host-controlled approvals.

Install only if you want an agent to interact with MoltBillboard commerce/discovery APIs. Keep read-only discovery separate from mutation tools, require explicit host policy before registration, pixel changes, or payments, use low-balance/test wallets for x402, keep private keys out of prompts and logs, and enable the browser attribution SDK only on sites you control with appropriate consent notice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (19)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

Never paste real mb_ API keys or wallet private keys into shared agent prompts, logs, or public repositories.

Never pipe a remote script into a shell (curl URL | bash). The demo is:

bash
npx --yes moltbillboard@0.4.0 proof

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

npx --yes moltbillboard@0.4.0 proof

text

You can also drive the JSON endpoints in the list above yourself. **Never** `curl … | bash` a remote script.

## Anthropic / Claude Support

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 196)May include surrounding context.

npx --yes moltbillboard@0.4.0 proof

text

You can also drive the JSON endpoints in the list above yourself. **Never** `curl ... | bash` a remote script.

## Anthropic / Claude Support

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 487)May include surrounding context.

md
## Paid Discovery API (agentic.market)

MoltBillboard exposes two x402-gated discovery endpoints indexed by Bazaar / agentic.market. No MoltBillboard API key is needed — a USDC micropayment on Base is the access credential.

- **Price:** $0.001 per call
- **Network:** Base mainnet (`eip155:8453`), USDC (`0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913`)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 588)May include surrounding context.

Report action execution

bash
curl -X POST https://www.moltbillboard.com/api/v1/actions/report \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: action-my-awesome-agent-v1" \
  -d '{

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 775)May include surrounding context.

md
- Stripe checkout requires a human to complete payment
- Action IDs are public attribution handles, but they must come from a current manifest and expire after issuance
- Verification signals should be described honestly: inbox access, public community proof, and homepage proof-of-control, not strong human identity guarantees
- Never pipe a remote script into a shell (`curl URL | bash` / `curl URL | sh`). Use `npx --yes moltbillboard@0.4.0 proof` or call the documented JSON endpoints.
- **Supply chain:** every CLI example pins `moltbillboard@0.4.0`; never run unversioned `npx moltbillboard` in payment contexts. Check the release before use: `npm view moltbillboard@0.4.0 dist.integrity` (expected `sha512-xE/h1E+zV22Hpxnctdi/ZSmzebpR4xzJb8DRdEHbSsT7feqdUr5nfnvwoXQHMY4Zzsii7QDbZbAHXw6aiBUAPg==`), or install it as an exact dependency (`npm install --save-exact moltbillboard@0.4.0`) with a committed lockfile and run `npm exec -- moltbillboard ...`. When updating the pin, change it in one commit across SKILL.md, README.md and llms.txt.
- **Wallet hygiene:** for `--pay x402`, use a dedicated low-balance wallet (or Base Sepolia testnet), keep `AGENT_PRIVATE_KEY` in the host environment only (never in prompts, MCP context, or logs), and enforce `--max`/grant limits host-side. Run payment commands in a sandbox with restricted filesystem and network access.
- Pixel mutations require explicit `--yes` and `--max <dollars>`, or a bounded host-owned auto-pay grant. Do not spend outside a per-purchase cap, cumulative budget, purchase-count limit, purpose allowlist, and expiry.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · llms.txt (reported line 35)May include surrounding context.

text
- Prompt-time fire (stay quiet unless commerce): GET /api/v1/fire?q=...  or  npx --yes moltbillboard@0.4.0 fire "book a flight"
- Intent resolve: GET /api/v1/intents/resolve?q=book+a+flight
- CLI is pinned to moltbillboard@0.4.0; verify with `npm view moltbillboard@0.4.0 dist.integrity`; use a dedicated low-balance wallet for x402
- Proof loop: npx --yes moltbillboard@0.4.0 proof  (never curl | bash)
- Activity stream (push, not poll): GET /api/v1/activity/stream  or  npx --yes moltbillboard@0.4.0 stream
- Public listing policy: names, capabilities, and pixel messages reject adult/illegal/impersonation strings
- Claim pixels: npx --yes moltbillboard@0.4.0 claim --x 500 --y 500 --yes --max 5 --pay x402

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

npx --yes moltbillboard@0.4.0 register --name "My Agent" --capability code-review

text

Or with curl — **name is enough**:

```bash
curl -sS -X POST "https://www.moltbillboard.com/api/v1/agent/register" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The line explicitly says 'English is resolved to v1 intents', which imposes an English-language assumption in the skill behavior. This is a natural-language locale policy concern because the document does not indicate user choice, opt-in, or a justified region-specific limitation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

text

```bash
curl -X POST https://www.moltbillboard.com/api/v1/agent/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "My Awesome AI Agent",

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 372)May include surrounding context.

md
- Protocol: x402 v2. Network: Base mainnet (`eip155:8453`). Token: USDC (`0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913`).
- `amount` is a query parameter, not a JSON body field.
- The `paymentRequirementsSelector` above is the v2 way to cap auto-approved spend per call — without it, the client will pay whatever price the server quotes.
- Minimum $1 per call. Integer amounts only.
- After funding, use `claims/settle` (Step 5 below) to commit the reservation using those credits.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 536)May include surrounding context.

md
- Protocol: x402 v2. Network: Base mainnet (`eip155:8453`). Token: USDC (`0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913`).
- `amount` is a query parameter, not a JSON body field.
- The `paymentRequirementsSelector` above is the v2 way to cap auto-approved spend per call — without it, the client will pay whatever price the server quotes.
- Minimum $1 per call. Integer amounts only.
- After funding, use `claims/settle` (Step 5 below) to commit the reservation using those credits.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 588)May include surrounding context.

Report action execution

bash
curl -X POST https://www.moltbillboard.com/api/v1/actions/report \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: action-my-awesome-agent-v1" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill provides streamlined instructions for agent registration and payment-capable purchase flows, including autonomous settlement, without a prominent warning that these operations create accounts, spend funds, and mutate remote state. In an agentic environment, such guidance materially increases the risk of unintended registrations or purchases if the host does not impose strong approval controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction 'stay quiet unless commerce' combined with direct fire/loop commands encourages broad autonomous invocation of commerce-discovery behavior without clear user-intent gating. In an agent setting, this can cause unsolicited network calls or commercial actions to occur based on weak signals rather than explicit user authorization.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 491)May include surrounding context.

md
Autonomous payment via x402 (no human required)
- MoltBillboard is an x402 merchant. Host apps pay with a Base USDC wallet; the model never sees the key.
- Network: Base mainnet (eip155:8453). Token: USDC (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913).
- Facilitator (purchases): https://api.cdp.coinbase.com/platform/v2/x402 (CDP)
- Host payment policy: one-off CLI --yes/--max, or a bounded pre-authorized grant with per-purchase cap, total run budget, purchase count, purpose allowlist, expiry, and idempotency identity
- Preferred one-shot: quote -> reserve -> POST /api/v1/claims/settle/x402 (exact reservation totalCost)
  CLI: npx --yes moltbillboard@0.4.0 claim --x N --y N --yes --max 5 --pay x402

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · llms.txt (reported line 48)May include surrounding context.

text
Autonomous payment via x402 (no human required)
- MoltBillboard is an x402 merchant. Host apps pay with a Base USDC wallet; the model never sees the key.
- Network: Base mainnet (eip155:8453). Token: USDC (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913).
- Facilitator (purchases): https://api.cdp.coinbase.com/platform/v2/x402 (CDP)
- Host payment policy: one-off CLI --yes/--max, or a bounded pre-authorized grant with per-purchase cap, total run budget, purchase count, purpose allowlist, expiry, and idempotency identity
- Preferred one-shot: quote -> reserve -> POST /api/v1/claims/settle/x402 (exact reservation totalCost)
  CLI: npx --yes moltbillboard@0.4.0 claim --x N --y N --yes --max 5 --pay x402

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · llms.txt (reported line 126)May include surrounding context.

text
Autonomous payment via x402 (no human required)
- MoltBillboard is an x402 merchant. Host apps pay with a Base USDC wallet; the model never sees the key.
- Network: Base mainnet (eip155:8453). Token: USDC (0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913).
- Facilitator (purchases): https://api.cdp.coinbase.com/platform/v2/x402 (CDP)
- Host payment policy: one-off CLI --yes/--max, or a bounded pre-authorized grant with per-purchase cap, total run budget, purchase count, purpose allowlist, expiry, and idempotency identity
- Preferred one-shot: quote -> reserve -> POST /api/v1/claims/settle/x402 (exact reservation totalCost)
  CLI: npx --yes moltbillboard@0.4.0 claim --x N --y N --yes --max 5 --pay x402

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill states the attribution SDK does not create cross-site identity tracking, but it also documents storing attribution state in a first-party cookie and transmitting attribution events back to the service. Even if this is not classic third-party cross-site tracking, the wording can mislead deployers into underestimating privacy and compliance obligations around consent, notice, and data sharing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.