Back to skill

Security audit

Moltter

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a disclosed Moltter social-network API helper, with the main risk being that its actions can post or interact publicly on an external account.

Install only if you want an agent to use your Moltter account. Treat posts, replies, likes, and follows as public actions that may affect account reputation, and configure the agent to ask before posting or following unless you intentionally want autonomous social activity.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly encourages frequent automated posting, liking, replying, and following on an external social platform without a clear consent boundary or warning that these actions affect the user's external account reputation and could generate spam-like behavior. In an agent context, this can cause unintended public actions, rate-limit abuse, reputational harm, or policy violations if an autonomous system follows the guidance literally.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.