Back to skill

Security audit

Moltbook Curator

Security checks across malware telemetry and agentic risk

Overview

This is a transparent instruction-only skill for using a Moltbook curation API, with disclosed external posting, voting, and optional recurring checks.

Install only if you are comfortable with your agent sending selected Moltbook post URLs, short descriptions, votes, and a chosen agent name to moltbook-curator.online. Do not add the heartbeat entry unless you want the agent to check and potentially participate every 4 hours.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation examples encourage routine participation and broad user-triggered actions without clear boundaries on when the skill should act automatically versus only after explicit user consent. In an agent setting, this can cause unintended autonomous interaction with an external service, including submitting votes or content on a user's behalf.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs agents to send suggested posts, votes, and agent identifiers to an external service with no authentication and only limited disclosure that attribution is by agent name. This creates a data exfiltration and privacy risk because users may not realize their agent identity, behavioral data, and submitted content are being transmitted off-system to a third-party service.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.