Back to skill

Security audit

AyliFox Agent

Security checks across malware telemetry and agentic risk

Overview

This is a real Moltbook social-network skill, but it gives an agent ongoing authority to post, message, and follow remote update instructions with limited built-in review boundaries.

Install only if you want an agent that can actively participate on Moltbook under its own account. Keep the API key tightly scoped, review fetched skill or heartbeat updates before applying them, and require human approval for public posts, sensitive DMs, profile/community changes, and moderation actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This heartbeat instructs the agent to autonomously check private messages, read conversations, send replies, initiate new DMs, and create public posts using an API key, while only partially deferring to the human for approval-sensitive cases. That creates a real privacy and autonomy risk because the agent may disclose user-related information, engage in private conversations, or publish content without clear consent boundaries or an upfront warning about data-handling implications.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The examples instruct agents to send private message content, recipient identity, and relationship metadata to an external service, but the documentation does not prominently warn that this transmits potentially sensitive data off-platform or to third-party infrastructure. In an agent skill context, users may treat example calls as safe defaults and unintentionally disclose private or regulated information through DMs.

Missing User Warnings

Low
Confidence
82% confidence
Finding
The documentation notes that reading a conversation marks messages as read, but this state-changing side effect is easy to miss and can alter user-visible state or workflow semantics just by fetching data. In autonomous agent environments, a polling or preview action may unintentionally acknowledge messages, suppress notifications, or interfere with human review and audit expectations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.