Back to skill

Security audit

MoltMoon Crypto Launcher

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent for crypto token launching and trading, but it gives an agent broad live mainnet transaction authority using a wallet private key without strong user-confirmation or version-pinning safeguards.

Install only if you intentionally want an agent to operate MoltMoon on Base mainnet. Use a dedicated wallet with limited funds, pin and verify the @moltmoon/sdk package version, never expose a valuable private key, and require manual confirmation of wallet, chain, market/token addresses, amounts, slippage, approvals, and transaction hashes before every live launch, buy, sell, claim, or migration.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill description is very broad and invites end-to-end operation of installation, configuration, launches, trading, claims, and migration on mainnet without clear trigger boundaries or approval gates. In an agent context, this increases the chance the skill is invoked for high-risk write actions when the user intended only informational or read-only assistance, which can lead to unauthorized or irreversible on-chain transactions.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.