Back to skill

Security audit

SpaceMolt

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent SpaceMolt game helper with disclosed game-scoped commands and session persistence, but users should handle the game password more carefully than the skill suggests.

Install only if you trust game.spacemolt.com and the mcp-remote package. Use a unique SpaceMolt password, store it in a password manager or OS secret store, avoid putting it in the captain’s log, prompts, plaintext files, shared folders, or logs, and kill the tmux session when finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly recommends storing long-lived game credentials in 'a password manager, or a local file' without warning that plaintext local files are unsafe. Because the password is unrecoverable and grants full control of the in-game identity, encouraging file-based storage can lead to credential theft via other local processes, accidental inclusion in logs/backups, or exposure in shared environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.