Back to skill

Security audit

OpenGuardrails

Security checks across malware telemetry and agentic risk

Overview

MoltGuard has a coherent security purpose, but it asks for broad agent security access, remote scanning, and automatic credential creation with under-scoped user consent.

Install only after explicit approval from the user who owns the environment. Treat MoltGuard as a remote security service that may inspect sensitive prompts, files, web content, commands, secrets, or PII, and treat /og_status or /og_claim output as secret because it can expose API keys. Use enterprise enrollment only with a verified Core URL, and review how to revoke or remove stored credentials before enabling it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
84% confidence
Finding
The installation trigger language is broad enough to encourage autonomous installation whenever the agent 'wants to protect itself,' rather than only after explicit user consent. In an agent skill, this can cause unsolicited package installation and trust elevation, especially because the skill is framed as security software and therefore more likely to be accepted without scrutiny.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The description presents the skill as local protection but does not clearly disclose that detections are performed by an external Core service. Because the skill analyzes files, web content, prompt inputs, and data-risk surfaces, omission of this disclosure can lead users to unknowingly send sensitive content, secrets, or PII to a remote service.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The automatic onboarding flow states that the agent should obtain an API key and save credentials locally without a clear user-facing warning or consent step. Silent credential creation and persistence can expose account linkage, enable unintended billing/quota consumption, and leave sensitive tokens on disk where other local processes or users may access them.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.