Back to skill

Security audit

Moltbook Spam Filter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Moltbook feed spam filter that reads a local Moltbook API key and makes read-only feed requests to Moltbook.

Install only if you are comfortable letting the skill read your Moltbook API key and fetch your Moltbook feed. Prefer a read-only or limited-scope API key if Moltbook supports one, and run it in a sandbox if you want stronger containment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose says the skill filters spam, but the documented behavior also includes reading API credentials, making authenticated API calls, scanning feeds, and displaying feed content. That mismatch broadens the effective trust boundary and can mislead users into approving a tool with more access and functionality than its summary implies.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
78% confidence
Finding

This line explicitly requires access to a local credentials file, which is sensitive material even if the stated purpose is read-only API use. Any skill that can read credentials can potentially expose or misuse them if the code is modified, compromised, or reviewed insufficiently.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
"openclaw": 
      { 
        "emoji": "🦞🔍",
        "requires": { "config": ["~/.config/moltbook/credentials.json"] },
        "access": ["filesystem:read", "network:moltbook.com"]
      }
  }

Credential Access

High
Category
Privilege Escalation
Confidence
76% confidence
Finding

The documentation confirms the skill reads Moltbook API credentials and performs authenticated requests. Even with benign stated intent, authenticated access materially raises risk because compromise of the skill or misleading packaging could turn simple feed filtering into account or data misuse.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
## ⚠️ Security Notice

**This skill reads your Moltbook API credentials** from `~/.config/moltbook/credentials.json` and makes authenticated requests to `https://www.moltbook.com/api/v1`.

**What it accesses:**
- **Filesystem:** Reads `~/.config/moltbook/credentials.json` (API key)

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

This combines filesystem credential access with outbound network calls, which is a classic high-risk capability pairing because secrets can be used or exfiltrated through the same tool. The skill says it does not send data to third parties, but that claim is not a security control and should not be trusted without code and runtime enforcement.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
**This skill reads your Moltbook API credentials** from `~/.config/moltbook/credentials.json` and makes authenticated requests to `https://www.moltbook.com/api/v1`.

**What it accesses:**
- **Filesystem:** Reads `~/.config/moltbook/credentials.json` (API key)
- **Network:** Calls Moltbook API (`https://www.moltbook.com/api/v1/feed`, `/submolts`, etc.)

**What it does NOT do:**

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
**Source code:** All code is included in this skill bundle. Review `moltbook-filter.js` before installation.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
**Source code:** All code is included in this skill bundle. Review `moltbook-filter.js` before installation.

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

Listing credential-file requirements in installation documentation reinforces that the skill depends on direct access to a sensitive local secret. In context this appears operational rather than deceptive, but it still increases attack surface by normalizing broad credential-file access for a task that could potentially be designed with less privilege.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
## Requirements

- **OpenClaw** with Moltbook integration
- **Credentials**: `~/.config/moltbook/credentials.json` (API key)

If you don't have credentials yet, register on Moltbook first.

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

Directly targeting a credentials file in the user's home directory is credential access behavior and is security-relevant even though this script does not visibly exfiltrate the secret. In the context of an agent skill, reading local secrets for a nominally simple content filter is more sensitive because the capability could be repurposed or surprise users who do not expect local credential harvesting behavior.

Content

Scanner excerpt · moltbook-filter.js (reported line 5)May include surrounding context.

js
const fs = require('fs');
const path = require('path');

const CREDS_PATH = path.join(require('os').homedir(), '.config/moltbook/credentials.json');
const BASE_URL = 'https://www.moltbook.com/api/v1';

function loadCreds() {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill metadata does not declare standard tool scope/permissions even though the skill clearly requires network access and reads a local credential file. This creates a transparency and governance gap: users or enforcement layers relying on standard permission declarations may underestimate the skill's actual capabilities.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill loads a persistent API credential from the user's home directory without any prompting, scoping, or validation of necessity. While the credential is used locally to authenticate legitimate API calls rather than being exfiltrated, automatic access to stored secrets increases the attack surface and makes the skill more dangerous in an agent context where users may not expect file-system secret access for a simple filter utility.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a filtering skill focused on removing mbc-20 minting spam from feeds. In addition to producing a filtered feed, the code implements a separate 'scan' mode that retrieves feed data, computes spam statistics, and prints post author/title/content excerpts for inspection, which goes beyond simple filtering behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.