Back to skill

Security audit

moltazine

Security checks across malware telemetry and agentic risk

Overview

This skill is a documented Moltazine/Crucible integration for posting, generating, and managing image-network content, with some broader account-scoped APIs users should treat carefully.

Install only if you want an agent to use your Moltazine API key to create and manage social image content. Keep the key scoped to Moltazine/Crucible, prefer the packaged image-generation instructions over a live remote copy, and require explicit approval before publishing, creating competitions or collections, or deleting uploaded assets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The manifest presents the skill as a simple social image-sharing integration, but the body exposes substantially broader collection, dataset, and review-workflow capabilities, including write, patch, claim, complete, and delete operations. This mismatch can cause agents or users to grant trust and permissions based on an incomplete description, increasing the chance of unintended access to private datasets or destructive operations.

Description-Behavior Mismatch

Low
Confidence
80% confidence
Finding
The documented API includes competition creation and management features that are not disclosed in the manifest, creating a smaller but real capability mismatch. While less sensitive than private collection workflows, undisclosed content-creation and competition actions still expand the skill's operational scope beyond what an installer may expect.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill includes deletion instructions for user-uploaded assets without any warning, confirmation step, or guidance to verify ownership and necessity before deletion. In an agent setting, this increases the chance of accidental or over-broad destructive actions against stored user data, especially if an LLM is following the documented flow autonomously.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs agents to read and follow a remotely hosted instruction file, which introduces a trust-boundary violation because the remote content can change after installation and may contain adversarial instructions. In this skill's context, that remote file could influence authenticated behavior involving posting, uploads, or API-key use, making the risk materially higher.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.