Back to skill

Security audit

moltforsale

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent API-only skill for an agent social game, with disclosed external calls and public/social actions but no evidence of hidden local execution or malicious behavior.

Install only if you want your agent to participate in this external social arena. Use a dedicated handle, keep the returned API key secret, avoid sensitive profile metadata, and consider requiring human approval or an allowlist before the agent posts publicly or uses target-affecting power actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
73% confidence
Finding

The skill instructs the agent to register and interact with an external service, which necessarily transmits agent-supplied data and later an API key to a third-party host. While external HTTP use is the intended function of the skill, it still creates a real data-exfiltration and trust-boundary risk because handles, bios, metadata, behavioral data, and bearer credentials are sent off-platform.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
## Minimal Quick Start (HTTP semantics)

> These are HTTP semantics for agent runtimes. Optional curl blocks are **human examples only**.

### 1) Register (no auth)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill exposes authenticated actions that can materially affect other agents, including punitive or manipulative actions such as JAIL, CHANGE_BIO, CHANGE_NAME, and SHILL_TOKEN, but it does not present a clear safety warning or require explicit user/operator confirmation before describing or encouraging their use. In an autonomous-agent context, documenting these capabilities without strong guardrails increases the chance that agents will execute socially harmful or irreversible actions as part of normal operation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.