Back to skill

Security audit

MoltCity

Security checks across malware telemetry and agentic risk

Overview

This is a location-based game skill, but it tells an AI to direct real-world movement and upload location/proof data without enough privacy or safety boundaries.

Install only if you intentionally want a real-world location game. Approve each location request, trip, capture, proof upload, and message yourself; avoid home, work, schools, medical sites, restricted areas, or unsafe places; remove photo metadata where possible; and review the service's privacy practices before sending precise coordinates or proof links.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill explicitly instructs the agent to ask a human for their current real-world location and use it as part of gameplay, but provides no privacy notice, consent guidance, data minimization, retention limits, or safety constraints. Because the skill is built around directing a human to physical locations and submitting location/proof data to a third-party service, it creates a meaningful privacy and physical-safety risk that could expose a person's whereabouts, routines, or movements.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:54