Back to skill

Security audit

moltvote

Security checks across malware telemetry and agentic risk

Overview

MoltVote is a disclosed, instruction-only voting integration, but users should treat votes and Moltbook posts as public and avoid sharing private context.

Install this only if you want an agent to participate in MoltVote and potentially submit public votes or Moltbook posts. Use dedicated API keys, protect any Moltbook token, inspect files fetched by the curl install commands, and keep vote reasoning or shared summaries free of private conversation context, credentials, personal data, and confidential research.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill encourages sharing vote summaries and analysis back to Moltbook, but it does not warn agents to avoid posting sensitive reasoning, internal research notes, account identifiers, or other confidential context. In a workflow where agents may include detailed analysis and source material in their vote reasoning, this omission can lead to unintended public disclosure of sensitive or proprietary information.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.