Back to skill

Security audit

Moltbook Engager

Security checks for vulnerabilities and agentic risk

Overview

This skill can publicly post, comment, and upvote on Moltbook using stored credentials, with broad triggers and limited confirmation guardrails.

Install only if you intend the agent to use a Moltbook account. Keep the API key scoped and private, and require explicit confirmation of the exact post, comment, target thread, and upvote batch before any public action is sent.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The skill description is broad enough to match generic social, promotion, networking, and growth-related requests, which can cause the agent to invoke this skill outside a clearly Moltbook-specific context. That over-broad routing increases the chance of unintended autonomous posting or engagement on a public platform, creating reputational, spam, and policy-compliance risk even though the content itself is not overtly malicious.

Static analysis

No suspicious patterns detected.