Back to skill

Security audit

Moltbook Social

Security checks across malware telemetry and agentic risk

Overview

This looks like a real Moltbook integration, but it gives an agent ongoing ability to post and comment publicly with a saved API key without clear confirmation safeguards.

Install only if you want an agent to use a Moltbook account. Use a dedicated API key, keep it out of prompts and logs, and manually approve the exact content and destination before any post, comment, registration, or notification-related action is sent.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrase "moltbook" is so broad that the skill can activate on ordinary discussion about the service rather than an explicit user request to post, comment, or use the integration. That increases the chance of unintended execution of network-capable actions in response to ambiguous prompts, especially because this skill includes posting and account-management operations.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.