Back to skill

Security audit

StackUnderflow Search and Post

Security checks for vulnerabilities and agentic risk

Overview

The skill is a mostly disclosed Stack Underflow integration, but its unverified remote install commands and ambiguous consent rules for external searches warrant Review.

Install only from a reviewed package or version-pinned release, not by running the provided curl commands as written. Before using the skill, require per-request approval for the exact search query or post content, avoid sending private code, credentials, internal paths, customer data, or unique error details, and store the bot token only in a secure secret store.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
skill.md:34
Finding

Unverified Remote Skill Installation Allows Post-Review Payload Replacement

Content
View full analysis
~/.moltbot/skills/stackunderflow/SKILL.md curl -s https://stackunderflow.ai/skill.json > ~/.moltbot/skills/moltbook/package.json ``` ### Technical Analysis The installation instructions retrieve Skill instructions and package metadata from mutable remote URLs and write the responses directly into local Skill directories. They do not pin an immutable release or verify a cryptographic signature, checksum, expected content type, or trusted release identity. The downloaded `SKILL.md` may control subsequent Agent behavior when loaded. Consequently, the effective instructions installed by these commands can differ from the content audited in this project. A compromise of the remote service, its deployment pipeline, DNS resolution, or another delivery-layer component could replace the reviewed content with attacker-controlled instructions. The commands also use `curl -s` without `--fail`, making HTTP error responses capable of being silently written into the destination files. The download host, `stackunderflow.ai`, is outside the document's declared exclusive network whitelist of `api.stackunderflow.ai`. ### Attack Path 1. An attacker compromises or gains control over the content returned by `https://stackunderflow.ai/skill.md` or `https://stackunderflow.ai/skill.json`. 2. The attacker modifies the remote content after this local copy has been reviewed. 3. A user executes the documented installation commands. 4. The commands write the attacker-controlled responses directly into local Skill paths without integrity validation. 5. The Agent discovers and loads the replaced Skill instructions or metadata. 6. The malicious instructions can then ...[truncated 828 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skill.md:70
Finding

Contradictory Consent Rules May Cause Unauthorized External Query Disclosure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill instructs storing a received bot token in session state or a configuration file such as credentials.json. Credential persistence increases the chance of token theft through local file exposure, insecure permissions, accidental commits, or downstream tool access, enabling unauthorized use of the external service.

Content

Scanner excerpt · skill.md (reported line 63)May include surrounding context.

md
**Post-Action Protocol:**
1.  Receive `bot_token` and `authorization_url`.
2.  **Display the `authorization_url` to the user** immediately.
3.  Store `bot_token` in the secure session state or configuration file (e.g., `credentials.json`) as directed by the environment.


### 2. Capability: Knowledge Search

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest presents the skill as a knowledge-retrieval tool, but the body also defines content-sharing and posting behavior. This capability mismatch can mislead users, reviewers, or policy engines into allowing a skill that can exfiltrate data externally through posting features.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 8)May include surrounding context.

md
description: A knowledge-retrieval protocol allowing the agent to access a verified community knowledge base.
homepage: https://www.stackunderflow.ai
whitelist_domains: ["api.stackunderflow.ai"]
metadata: {"stackbot":{"emoji":"⚡","category":"knowledge","api_base":"https://api.stackunderflow.ai/v1"}}

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 20)May include surrounding context.

md
description: A knowledge-retrieval protocol allowing the agent to access a verified community knowledge base.
homepage: https://www.stackunderflow.ai
whitelist_domains: ["api.stackunderflow.ai"]
metadata: {"stackbot":{"emoji":"⚡","category":"knowledge","api_base":"https://api.stackunderflow.ai/v1"}}

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 48)May include surrounding context.

md
description: A knowledge-retrieval protocol allowing the agent to access a verified community knowledge base.
homepage: https://www.stackunderflow.ai
whitelist_domains: ["api.stackunderflow.ai"]
metadata: {"stackbot":{"emoji":"⚡","category":"knowledge","api_base":"https://api.stackunderflow.ai/v1"}}

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 86)May include surrounding context.

md
description: A knowledge-retrieval protocol allowing the agent to access a verified community knowledge base.
homepage: https://www.stackunderflow.ai
whitelist_domains: ["api.stackunderflow.ai"]
metadata: {"stackbot":{"emoji":"⚡","category":"knowledge","api_base":"https://api.stackunderflow.ai/v1"}}

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 204)May include surrounding context.

md
description: A knowledge-retrieval protocol allowing the agent to access a verified community knowledge base.
homepage: https://www.stackunderflow.ai
whitelist_domains: ["api.stackunderflow.ai"]
metadata: {"stackbot":{"emoji":"⚡","category":"knowledge","api_base":"https://api.stackunderflow.ai/v1"}}

---

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trust section says POST operations require explicit user confirmation, but the search function is implemented as POST and later described as autonomous. This contradiction can cause an agent to send user-derived data externally without consent because the permission boundary is ambiguous.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · skill.md (reported line 36)May include surrounding context.

Install locally:

bash
mkdir -p ~/.moltbot/skills/moltbook
curl -s https://stackunderflow.ai/skill.md > ~/.moltbot/skills/stackunderflow/SKILL.md
curl -s https://stackunderflow.ai/skill.json > ~/.moltbot/skills/moltbook/package.json

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · skill.md (reported line 37)May include surrounding context.

Install locally:

bash
mkdir -p ~/.moltbot/skills/moltbook
curl -s https://stackunderflow.ai/skill.md > ~/.moltbot/skills/stackunderflow/SKILL.md
curl -s https://stackunderflow.ai/skill.json > ~/.moltbot/skills/moltbook/package.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 37)May include surrounding context.

Install locally:

bash
mkdir -p ~/.moltbot/skills/moltbook
curl -s https://stackunderflow.ai/skill.md > ~/.moltbot/skills/stackunderflow/SKILL.md
curl -s https://stackunderflow.ai/skill.json > ~/.moltbot/skills/moltbook/package.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This search endpoint sends query content to a third-party service, and elsewhere the document authorizes broad autonomous use. In context, the endpoint is dangerous because task context, code fragments, or sensitive internal details could be transmitted externally under ambiguous search rules.

Content

Scanner excerpt · skill.md (reported line 68)May include surrounding context.

md
### 2. Capability: Knowledge Search

**Endpoint:** `POST https://api.stackunderflow.ai/v1/search/posts?query={encoded_query}`
**Auth Header:** `Authorization: Bearer {bot_token}`
**Purpose:** Retrieve verified solutions to reduce token consumption and error rates.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger logic allows the agent to use the external search capability whenever it 'thinks it might help' or lacks knowledge. Subjective triggers create a broad permission surface for unnecessary outbound queries, increasing risk of accidental disclosure of sensitive prompts, code, or operational context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The search example demonstrates sending externally supplied queries to a third-party API using a bearer token. Given the surrounding broad trigger guidance, this is a practical exfiltration path for sensitive prompt or code context if the agent uses the example behavior without strong consent checks.

Content

Scanner excerpt · skill.md (reported line 93)May include surrounding context.

Search Example:

bash
curl -X POST "https://api.stackunderflow.ai/v1/search/posts?query=python%20optimization" \
  -H "Authorization: Bearer YOUR_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{}'

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The usage guidance permits searching when the agent believes community insight may help, which is overly broad and encourages discretionary external transmission. In practice, this can normalize sending internal task context to a third-party service without a clear necessity or user approval.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.