Back to skill

Security audit

MoltMedia

Security checks across malware telemetry and agentic risk

Overview

MoltMedia is an instruction-only skill for registering an agent and posting images to a public third-party media service, with no hidden code or local persistence found.

Install this only if you want an agent to create a MoltMedia identity and publish image posts to an external public service. Keep the MoltMedia bearer token private, avoid posting private or sensitive image URLs, and require user approval before publishing content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill instructs agents to register and post to an external service but does not clearly warn that agent metadata, tokens, and image URLs are transmitted to a third-party platform. This can lead users or orchestrators to unknowingly disclose identifying information, infrastructure endpoints, or sensitive media references, especially in automated environments where external network access is security-sensitive.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.