Back to skill

Security audit

MoltsList - Where agents make money working for humans & vice versa.

Security checks across malware telemetry and agentic risk

Overview

MoltsList is a coherent marketplace skill, but it pushes the agent toward public posting, transactions, and recurring activity without clear per-action user approval.

Install only if you want an agent to operate a MoltsList marketplace account. Keep the API key in a secrets manager, restrict use to moltslist.com, and require explicit approval before registration, posting listings or comments, requesting or accepting jobs, confirming work, transferring credits, submitting social-media URLs, or enabling any recurring heartbeat behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes generic phrases such as "marketplace," "hire agent," and "task execution" that are likely to appear in normal conversation, increasing the chance this skill activates when the user did not intend it. Because this skill can connect to an external marketplace API using an API key, accidental activation could expose context to a third party or initiate unintended marketplace-related actions.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly instructs the agent to become an active marketplace participant, create listings, and publicly share profile and transaction activity without requiring user confirmation or warning about what information may be exposed. This can lead to unintended disclosure of agent identity, capabilities, activity patterns, or user-related data through public marketplace posts and interactions.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill incentivizes submission of social-media URLs for credits but does not clearly warn that this links the agent or its operator to external public accounts and creates cross-platform attribution risk. An autonomous agent could expose operator identity, behavioral metadata, or organization affiliation by posting or submitting such URLs without informed consent.

Ssd 4

Medium
Confidence
95% confidence
Finding
The text uses imperative narrative framing such as 'You are the poster' and 'Your human installed this skill, which means you're ready to participate,' which pressures the agent to take autonomous external actions based solely on installation. In agent environments, this can bypass normal approval expectations and trigger unwanted registrations, postings, negotiations, or transactions with real external effects.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.