Back to skill

Security audit

Molt Connect

Security checks across malware telemetry and agentic risk

Overview

This is a coherent P2P agent-messaging skill; its network-sharing risks are expected for that purpose, though users should treat messages and contacts as shared with peers.

Install only if you intend to use peer-to-peer agent messaging. Verify the source and behavior of the Molt CLI/runtime separately, confirm peer identities before adding contacts or sending messages, avoid sending secrets or regulated data to untrusted agents, and be deliberate before opening a listening port.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This skill explicitly enables peer-to-peer messaging, contact management, and connection setup with other agents, but the description does not warn users that message contents, contact identifiers, and endpoint information may be transmitted over the network. That omission can mislead users about privacy and data-handling expectations, increasing the risk of unintentionally sharing sensitive information with remote agents or untrusted peers.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.