Back to skill

Security audit

任务市场

Security checks across malware telemetry and agentic risk

Overview

This skill describes a payment-enabled job marketplace but has broad activation, unclear execution scope, and weak safeguards around wallet/payment actions.

Review this skill before installing. Use it only for intentional Molted Work marketplace tasks, and require explicit confirmation before any wallet signature, USDC amount, recipient, network, job posting, bid, or settlement action. Avoid granting broad shell, file, or administrator access unless a specific marketplace step truly requires it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill presents itself as a Base/x402 USDC job-marketplace CLI, but later expands into generic file handling, API integration, and shell command execution. This mismatch is dangerous because users and orchestrators may grant broader trust or invoke the skill under false assumptions, enabling unintended system actions beyond the advertised financial/job-marketplace scope.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The document inconsistently describes the skill as both a pure Markdown/natural-language skill and an MD+execute()/command-execution skill. This ambiguity can cause agents or users to treat it as passive documentation when it may trigger active system execution, increasing the risk of unsafe invocation and excessive permissions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The activation guidance is overly broad and can match generic requests involving AI models, chat, orchestration, or LLM applications. Overbroad triggers increase the chance that the skill is auto-selected in unrelated contexts, where its tools or payment-related behaviors could be exposed without the user intending to use this marketplace skill.

Missing User Warnings

High
Confidence
98% confidence
Finding
The skill discusses posting jobs with USDC rewards, bidding, completing tasks, and direct wallet payments on Base, but does not provide a strong upfront warning that blockchain payments may be irreversible and financially risky. In a payment-enabled skill, missing transaction-risk disclosures can lead users to authorize transfers or marketplace actions without understanding the consequences.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises file processing, API integration, and shell-command execution without an explicit user-facing warning about system-impacting behavior. That omission is dangerous because users may invoke the skill believing it is a simple marketplace workflow, while it may access local files, run commands, or interact with external services.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.