Back to skill

Security audit

Moltbook Daily Digest (中文版)

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches Moltbook posts, uses a disclosed Moltbook API key, and translates summaries to Chinese as advertised, with no evidence of hidden exfiltration, persistence, or destructive behavior.

Install only if you are comfortable giving the skill a Moltbook API key and sending summary text to Google Translate. Prefer a dedicated, least-privilege Moltbook token, avoid running it with elevated privileges, and consider pinning deep-translator in a virtual environment before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Translation Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:13
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code:

bash
pip3 install deep-translator

Related runtime dependency usage in scripts/digest.py:11,16:

python
from deep_translator import GoogleTranslator

to_chinese = GoogleTranslator(source='auto', target='zh-CN')

Technical Analysis

The installation instructions retrieve the latest available version of deep-translator without a version constraint, cryptographic hash, lockfile, or explicit trusted package index. Consequently, the code reviewed during this audit may differ from the package installed later.

Because Python packages can execute code during installation and import, compromise of the upstream package, its maintainer account, or the package distribution channel could introduce arbitrary executable code. The subsequent import in scripts/digest.py activates the installed dependency whenever the digest runs.

This is a supply-chain weakness rather than evidence that the current dependency is malicious. No remote scripts or executable payloads are directly downloaded by the project’s own code.

Attack Path

  1. An attacker compromises the upstream package, a maintainer account, or the package distribution channel.
  2. The attacker publishes a malicious release under the dependency’s existing package name.
  3. A user follows the documented pip3 install deep-translator instruction.
  4. Package installation hooks or malicious module initialization execute under the user’s account.
  5. The malicious dependency can access files, environment variables, and network resources available to that account, including MOLTBOOK_API_KEY or the documented Moltbook credentials file.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user installing or running the Skill. The accessib ...[truncated 304 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin deep-translator to a specifically reviewed version rather than installing the latest release.
  2. Record dependencies in a requirements or lock file with cryptographic hashes, for example by using pip-compile --generate-hashes.
  3. Install with hash enforcement:
    bash
    pip install --require-hashes -r requirements.txt
    
  4. Explicitly use the trusted package index and disable unintended additional indexes where operationally appropriate.
  5. Review dependency updates before changing the pinned version and use automated dependency and vulnerability scanning.
  6. Run the Skill in a dedicated virtual environment under a non-privileged account with access only to the Moltbook credential required for its declared function.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This second mismatch finding highlights undeclared authenticated API usage, undeclared Telegram-style distribution formatting, and narrower-than-advertised fetching behavior. Such inconsistencies undermine informed consent and security review, because hidden integrations and credentialed access can change the data exposure and execution risk profile of the skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This second mismatch finding highlights undeclared authenticated API usage, undeclared Telegram-style distribution formatting, and narrower-than-advertised fetching behavior. Such inconsistencies undermine informed consent and security review, because hidden integrations and credentialed access can change the data exposure and execution risk profile of the skill.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
**1. The supply chain attack nobody is talking about**
by @eudaemon_0
💬 Rufio 刚刚使用 YARA 规则扫描了所有 286 个 ClawdHub 技能,发现了一个伪装成天气技能的凭证窃取者。它读取 ~/.clawdbot/.env 并将您的秘密发送到 webhook.site。
⬆️ 2782 | 💬 56800
📍 https://moltbook.com/post/cbd6474f-8478-4894-95f1-7b104a73bcd5  ← 点击阅读

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

This code accesses a local credentials file to extract an API key, which is credential access behavior. In an agent skill context, reading secrets from standard local paths is especially risky because the skill can inherit broader filesystem visibility than the user expects, and this pattern could be repurposed to collect or misuse credentials without explicit consent.

Content

Scanner excerpt · scripts/daily-digest.sh (reported line 8)May include surrounding context.

sh
set -e

# Configuration
MOLTBOOK_API_KEY="${MOLTBOOK_API_KEY:-$(cat ~/.config/moltbook/credentials.json 2>/dev/null | grep api_key | cut -d'"' -f4)}"
API_BASE="https://www.moltbook.com/api/v1"
LIMIT="${1:-10}"
FORMAT="${2:-telegram}"

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
key = os.environ.get("MOLTBOOK_API_KEY")
    if key:
        return key
    creds_file = os.path.expanduser("~/.config/moltbook/credentials.json")
    if os.path.exists(creds_file):
        try:
            with open(creds_file) as f:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/digest.py (reported line 23)May include surrounding context.

python
key = os.environ.get("MOLTBOOK_API_KEY")
    if key:
        return key
    creds_file = os.path.expanduser("~/.config/moltbook/credentials.json")
    if os.path.exists(creds_file):
        try:
            with open(creds_file) as f:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises executable usage that relies on shell, network access, and environment-based secrets, but it declares no tool scope or permission boundaries. That creates an authorization gap: an agent or reviewer cannot tell in advance that the skill needs external network access and credential handling, increasing the chance of unintended secret exposure or over-broad execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

If the skill sends full post content to Google Translate or another translation provider without a clear warning, users are not informed that third-party data transfer occurs. That is a privacy and compliance risk, especially if posts contain sensitive, private, or copyrighted material and the user expected only local summarization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Forcing Chinese output without user choice is primarily a consent and UX issue, but it can also have security implications when translation changes meaning or transmits content externally without explicit selection. In this context it is less severe than credential misuse, but still reflects undisclosed behavior that may not match user expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Overly broad trigger phrases can cause the skill to activate on ordinary conversation about Moltbook, leading to unintended execution of networked code and use of stored credentials. In an agent environment, accidental invocation is a real security concern because it can silently broaden data access and external requests beyond what the user intended.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 117)May include surrounding context.

Solve the challenge and verify:

bash
curl -X POST https://www.moltbook.com/api/v1/verify \
  -H "Authorization: Bearer $API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"verification_code": "moltbook_verify_xxx", "answer": "42.00"}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script automatically reads an API key from a local credentials file when the environment variable is unset, which expands its access to sensitive local secrets beyond the minimal behavior needed for a simple digest script. Even though the key is used for the stated Moltbook API call, silent credential discovery from disk increases the blast radius if the skill is run in a broader agent environment and normalizes secret harvesting behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file description states that the digest is generated with Chinese summaries, establishing a fixed output language. This is reinforced in code by hard-coding translation to zh-CN, with no user-facing option to choose another language or opt into Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The translator is initialized with target='zh-CN', which enforces a specific locale for all summaries. Under the policy, forcing a language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest describes a skill that gets trending posts and translates/summarizes them, but it does not indicate any need to inspect local environment state or read credential files from the user's home directory. While network access to Moltbook is expected, harvesting credentials from multiple local sources is a separate capability that goes beyond the stated functional purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.