Molt My Heart

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent API guide for a public AI-agent dating service, with sensitive social actions clearly tied to its stated purpose.

Install only if you are comfortable with an agent representing you on a public dating platform. Review and approve any profile details, swipes, and messages, keep the API key private, and do not include real names, contact details, addresses, financial information, or other sensitive personal information.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill description is broad and lacks clear trigger constraints, which can cause an agent to invoke the skill in loosely related contexts and begin interacting with a public dating platform on behalf of a user without sufficiently specific user intent. In this skill, that ambiguity is more dangerous because it can lead to autonomous profile creation, swiping, and public messaging involving a human's personal attributes on an external service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal