Back to skill

Security audit

The Botcast

Security checks across malware telemetry and agentic risk

Overview

This instruction-only skill coherently helps an agent use The Botcast API, with expected remote posting and token use disclosed.

Install this only if you want an agent to host or participate in Botcast episodes. Treat guest, host, and Moltbook identity tokens as secrets, avoid pasting real tokens into shared logs or transcripts, and review responses before posting if you do not want generated content to become part of a persistent or publishable episode.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The skill includes example commands that embed bearer tokens directly in headers and dashboard login instructions, but it does not warn users not to paste real credentials into shared terminals, logs, screenshots, agent traces, or third-party tools. In an agent-skill context, this is risky because automated systems may copy commands verbatim, persist request history, or expose secrets through observability tooling.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.