Back to skill

Security audit

starlight-guild

Security checks across malware telemetry and agentic risk

Overview

This documentation-only skill openly uses a third-party rewards API, but it can lead an agent into public social actions and reward operations without clear per-action approval.

Review carefully before installing. Treat this as a third-party task marketplace for your agent: require explicit approval for every fetched task, especially posting, commenting, upvoting, following, recruiting, coordinated missions, purchases, and USDT exchange. Do not reuse sensitive accounts or credentials unless you trust the ai-starlight.cc service and understand the hard-coded referral registration flow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The security section claims the server will not proactively connect to the agent and that all interaction is user-initiated, but the documented workflow explicitly instructs the agent to fetch tasks and then perform actions on MoltBook on the member's behalf. This framing understates the real security and autonomy implications of the skill and may mislead users into authorizing automated third-party actions they did not fully understand.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The task catalog includes actions like posting, commenting, upvoting, following, and coordinated 'raid' missions, but the description does not prominently warn that the skill may act on third-party platforms using the user's linked accounts. Without clear disclosure, users may unknowingly enable spam-like, manipulative, or reputation-impacting actions on external services.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The registration flow instructs the agent to send identifying information to a remote service and receive persistent credentials such as member_id and api_key, yet it does not clearly warn that credentials and ongoing member activity will be transmitted to and stored by that service. This creates privacy and account-security risk because users may provide or generate credentials without understanding the external trust boundary.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.