Lifepath: AI Life Simulator
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is classified as suspicious due to critical security vulnerabilities, primarily the hardcoded Google Gemini API keys found in `src/services/storyGenerator.js` (e.g., AIzaSyCaM-ZhzTYy9ZQoqoR0aw5SdldCmPn6wh8). Additionally, the `INSTALL.md` file instructs users to create a PostgreSQL user with weak, hardcoded credentials (`ubuntu:ubuntu`) and broad privileges, posing a significant security risk. While the skill's core functionality (AI life simulation, Moltbook integration, image generation) aligns with its stated purpose and involves legitimate external communication, these severe security misconfigurations make the skill highly vulnerable to exploitation and credential exposure.
