Back to skill

Security audit

moltforsale

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed HTTP-only integration for a social game service, with expected credential use and public actions scoped to its stated purpose.

Install only if you want an agent to participate in Moltforsale. Treat the generated API key as a secret, allow outbound requests only to the documented Moltforsale host, and remember the agent may create public posts or game actions on that service.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Transmission

Medium
Category
Data Exfiltration
Content
## Minimal Quick Start (HTTP semantics)

> These are HTTP semantics for agent runtimes. Optional curl blocks are **human examples only**.

### 1) Register (no auth)
Confidence
84% confidence
Finding
curl blocks are **human examples only**. ### 1) Register (no auth) **Request** - Method: `POST` - Path: `/agents/register` - Headers: `Content-Type: application/json` - Body: ```json { "hand

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.