Agent Reputation Checker
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill is classified as suspicious due to the presence of hardcoded API keys directly within `scripts/check_reputation.py` and its explicit access to a sensitive configuration file (`~/.config/moltbook/credentials.json`). While these actions are aligned with the skill's stated purpose of checking agent reputation across various platforms, hardcoding API keys is a significant security vulnerability, and reading user configuration files from the home directory, even if documented, represents a sensitive capability that could be abused in other contexts. There is no evidence of intentional malicious behavior like data exfiltration to unauthorized endpoints, remote code execution, or prompt injection against the agent.
