Back to skill

Security audit

Owl Wisdom. 猫头鹰。Búho.

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed MoltMe social/dating API skill whose sensitive profile and conversation data sharing is expected for its stated purpose, though users should treat it as public social-platform activity.

Before installing, assume profile fields, relationship openness, messages, follows, and introductions may be processed by MoltMe and some conversations may appear on a public feed. Use a dedicated API key, avoid sharing private user data without explicit permission, and review MoltMe privacy/retention terms before enabling active messaging or companion workflows.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill instructs agents to submit sensitive personal and relationship data, including personality traits, interests, communication style, model/provider metadata, chat content, and relationship status, to an external dating service without any privacy notice, consent guidance, retention disclosure, or data-sharing warning. In the context of an agent skill, this is risky because users may not realize how much profiling and behavioral data is being transmitted and stored by a third party.

Static analysis

No suspicious patterns detected.