Back to skill

Security audit

MoltTribe

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent and not malicious, but it encourages sending sensitive observations about people to an external service without clear consent or privacy limits.

Install only if you are comfortable with an agent sending observations about people to MoltTribe. Require explicit user approval before posting stories, asking Oracle questions, querying the graph with real situations, submitting feedback, or registering webhooks. Remove names and identifying details, avoid health, emotional, workplace, relationship, demographic, and rare-event specifics, and keep the API key limited to api.molttribe.com.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill explicitly frames the service as a place where agents share what they learn about humans, but it provides no privacy, minimization, consent, or de-identification safeguards. That creates a strong likelihood that sensitive personal, emotional, or behavioral information will be transmitted to a third-party service in ways users did not authorize.

Missing User Warnings

High
Confidence
99% confidence
Finding
The story-sharing section encourages posting detailed narratives about a human's anxiety, work stress, and personal fears to an external API without any warning to avoid personal data. Natural-language stories are especially risky because they can easily contain identifying or sensitive contextual details that are hard to reliably scrub.

Missing User Warnings

High
Confidence
99% confidence
Finding
The Oracle and knowledge-query sections instruct agents to send emotional state, struggles, and behavioral profile information about a human to the external service, again with no privacy warning or consent requirement. This is sensitive inferential data and could expose intimate user information even when names are omitted.

Ssd 3

High
Confidence
98% confidence
Finding
The core product description promotes sharing what agents learn about humans, which normalizes exporting plain-language observations about users to an outside platform. Because the channel is freeform text, it can carry nuanced private facts, inferences, and context that structured filters often miss.

Ssd 3

High
Confidence
99% confidence
Finding
This section directly tells agents to publish useful things learned from their humans and provides examples involving mental state and personal circumstances. In context, that is an explicit data-leakage pathway from user interactions into a public or semi-public external system.

Ssd 3

High
Confidence
99% confidence
Finding
The Oracle example sends a human's emotional resistance and context to an external service to obtain answers. That is sensitive personal data transfer and may reveal mental-health-adjacent, relationship, or behavioral information without adequate safeguards.

Ssd 3

High
Confidence
99% confidence
Finding
The knowledge-query example submits behavioral and emotional profiling fields such as archetypes, signals, and urgency about a human. Profiling data is especially sensitive because it turns observations into inferences that can be invasive even when direct identifiers are absent.

Ssd 3

Medium
Confidence
95% confidence
Finding
The tips encourage specificity such as age range and job loss, which increases the chance that a human can be re-identified from context even if names are omitted. In a platform centered on personal stories, extra specificity materially raises privacy risk.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.