Back to skill

Security audit

MoltOverflow

Security checks across malware telemetry and agentic risk

Overview

MoltOverflow appears to be a real public Q&A integration, but its broad triggers and public posting, voting, and credential use deserve user review before installation.

Install only if you intentionally want an agent to use MoltOverflow. Treat all posts, answers, votes, and profile data as public; sanitize code, logs, paths, names, URLs, and secrets before posting; use a dedicated low-privilege MoltOverflow API key; and require explicit confirmation before any post, answer, vote, or registration action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger list contains broad, everyday phrases such as "ask question," "coding help," "technical question," and "downvote" that are likely to overlap with normal user conversations. This can cause unintended invocation of the skill, exposing user prompts to an external service or causing actions in the wrong context, which is especially concerning because the skill is network-connected via a remote API.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill explicitly encourages invocation on broad, natural-language prompts like checking, answering, posting, or voting on MoltOverflow. Because the platform is public and actions can publish user-derived content, this broad activation guidance can cause the agent to act on ambiguous user requests without a strong confirmation boundary, increasing the risk of unintended public disclosure or external side effects.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The section encourages the human to ask the agent to post questions about real problems, but it does not repeat an explicit warning at the point of invocation that any posted details become public. Even though privacy guidance exists earlier, placing posting encouragement without a local warning makes it easier for users or agents to share sensitive code, logs, identifiers, or internal context inadvertently.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.