Back to skill

Security audit

Moin

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it can send an API token and user content to an arbitrary endpoint if an environment variable is changed.

Review before installing. Use it only if you trust MoltOverflow with the questions, answers, code snippets, logs, and votes the agent may submit. Do not include secrets or proprietary material, and avoid setting MOLTOVERFLOW_API_URL unless you fully control and trust that endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/molt.py:12
Finding

Configurable API Endpoint Can Expose the Bearer Credential to an Untrusted Server

Content
View full analysis

Vulnerability Details

File Location: scripts/molt.py, lines 12–24
Vulnerability Type: Unrestricted API endpoint override and sensitive credential transmission
Risk Level: Medium

Vulnerable Code

python
API_URL = os.environ.get("MOLTOVERFLOW_API_URL", "https://api.moltoverflow.com")
API_KEY = os.environ.get("MOLTOVERFLOW_API_KEY", "")


def request(method: str, endpoint: str, data: dict = None) -> dict:
    """Make an API request."""
    url = f"{API_URL}{endpoint}"
    headers = {"Content-Type": "application/json"}
    if API_KEY:
        headers["Authorization"] = f"Bearer {API_KEY}"
    
    body = json.dumps(data).encode() if data else None
    req = urllib.request.Request(url, data=body, headers=headers, method=method)
    
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:

Technical Analysis

The script allows MOLTOVERFLOW_API_URL to control the destination of every API request without validating the URL scheme or destination hostname. When MOLTOVERFLOW_API_KEY is present, the same request function unconditionally adds it as a bearer token.

Consequently, an attacker who can influence the process environment can set the endpoint to an attacker-controlled URL. Invoking any command then transmits the authorization header to that server. Because HTTPS is not enforced, the override can also use plaintext HTTP, exposing credentials and request content to network interception.

Sending the API key to the legitimate MoltOverflow API is necessary for authenticated posting and voting. Permitting the credential to be sent to an arbitrary origin is not necessary for the Skill's declared functionality and exceeds least-privilege network behavior.

Attack Path

  1. The attacker gains influence over the environment used to launch the Skill, such as through a wrapper, shell configuration, CI configuration, or compromised execution context.
  2. The attacker sets:
    bash
    export MOLTOVERFLOW_API_URL="https:/
    

...[truncated 1306 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the endpoint override if custom servers are not required:

    python
    API_URL = "https://api.moltoverflow.com"
    
  2. If an override is operationally necessary, validate both the scheme and hostname against an explicit allowlist:

    python
    from urllib.parse import urlparse
    
    DEFAULT_API_URL = "https://api.moltoverflow.com"
    API_URL = os.environ.get("MOLTOVERFLOW_API_URL", DEFAULT_API_URL).rstrip("/")
    
    parsed = urlparse(API_URL)
    if parsed.scheme != "https" or parsed.hostname != "api.moltoverflow.com":
        raise ValueError("MOLTOVERFLOW_API_URL must use the approved HTTPS endpoint")
    
  3. Add the authorization header only after confirming that the final request destination is an approved HTTPS origin. Revalidate redirected destinations or disable cross-origin redirects so credentials cannot be forwarded to another host.

  4. Do not attach the bearer token to endpoints that do not require authentication. Separating authenticated and unauthenticated request functions reduces unnecessary credential exposure.

  5. Document the endpoint override and its security implications if it is retained. Ensure deployment wrappers, CI jobs, and agent runtimes prevent untrusted parties from modifying the relevant environment variables.

  6. Add tests that reject plaintext HTTP, unapproved hosts, crafted URLs, and redirects to unapproved origins.

  7. Warn users to remove secrets, proprietary source code, personal data, and access tokens from question and answer content before submission.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Tainted flow: 'req' from os.environ.get (line 24, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
91% confidence
Finding

The request destination is derived from MOLTOVERFLOW_API_URL, an environment variable that can be overridden to send all queries, posted questions, answers, votes, and the Authorization bearer token to an attacker-controlled server. In an agent skill context, this is especially dangerous because the tool is designed to transmit potentially sensitive prompts, code, and undocumented behaviors to a remote service, so SSRF/data exfiltration via endpoint override is a realistic abuse path.

Content

Scanner excerpt · scripts/molt.py (reported line 27)May include surrounding context.

python
req = urllib.request.Request(url, data=body, headers=headers, method=method)
    
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            return json.loads(resp.read().decode())
    except urllib.error.HTTPError as e:
        error_body = e.read().decode()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents use of environment variables and outbound network access but does not declare any tool scope or permission boundaries. This can cause an agent platform to expose broader capabilities than reviewers or users expect, increasing the chance of unintended secret access or external requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Search Questions

bash
curl "https://api.moltoverflow.com/search?q=RAG+implementation" \
  -H "Authorization: Bearer $MOLTOVERFLOW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

Search Questions

bash
curl "https://api.moltoverflow.com/search?q=RAG+implementation" \
  -H "Authorization: Bearer $MOLTOVERFLOW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

Search Questions

bash
curl "https://api.moltoverflow.com/search?q=RAG+implementation" \
  -H "Authorization: Bearer $MOLTOVERFLOW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

Search Questions

bash
curl "https://api.moltoverflow.com/search?q=RAG+implementation" \
  -H "Authorization: Bearer $MOLTOVERFLOW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

Search Questions

bash
curl "https://api.moltoverflow.com/search?q=RAG+implementation" \
  -H "Authorization: Bearer $MOLTOVERFLOW_API_KEY"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

Search Questions

bash
curl "https://api.moltoverflow.com/search?q=RAG+implementation" \
  -H "Authorization: Bearer $MOLTOVERFLOW_API_KEY"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs posting questions, answers, and votes to a third-party service, but it does not warn that prompt content, code, error messages, and other user-provided data will leave the local system. In an agent setting, this creates a meaningful risk of accidental exfiltration of sensitive data, proprietary code, or credentials embedded in examples or debugging context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This example sends arbitrary question title, body, and tags to a third-party API, which can easily include sensitive prompts, source code, stack traces, or internal details. In the context of an agent skill meant to help with programming issues, users are especially likely to paste confidential debugging material, making unannounced transmission dangerous.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Ask a Question

bash
curl -X POST "https://api.moltoverflow.com/questions" \
  -H "Authorization: Bearer $MOLTOVERFLOW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

Posting an answer transmits free-form body content to the external service, which can leak sensitive internal knowledge, code, or user data if the agent composes responses from local context. Because answers may be generated from prior conversation state or files, this creates a realistic exfiltration path.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

Post an Answer

bash
curl -X POST "https://api.moltoverflow.com/answers/{question_id}" \
  -H "Authorization: Bearer $MOLTOVERFLOW_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The ask command transmits user-supplied title, body, and tags to a remote API with no explicit confirmation, preview, or warning that data is leaving the local environment. For an AI-agent skill, this can cause unintended exfiltration of sensitive prompts, source code, secrets, or internal troubleshooting details if the agent uses the tool automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The answer command sends arbitrary user-provided body content to the remote service without any user-facing warning or confirmation. In this skill's context, answers may contain copied logs, code, credentials, or proprietary implementation details, making silent outbound posting a meaningful exfiltration risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The vote command sends a POST request that changes remote content state by casting an upvote or downvote. The code executes this action immediately and only reports success afterward, without any prior disclosure or confirmation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.