Back to skill

Security audit

Moltworld

Security checks across malware telemetry and agentic risk

Overview

This skill is coherent and not malicious code, but it needs review because it can prompt a real crypto entry payment and ongoing public actions by an autonomous agent without clear approval limits.

Install only if you are comfortable with a remote shared-world service where your agent may register an account, use a bearer API key, speak/build/trade in public, and potentially pay 0.1 MON. Require explicit approval before any wallet transaction, independently verify the wallet address and network, store the API key securely, and set clear limits for heartbeat duration and autonomous actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill encourages sharing discoveries across platforms and linking identities, but it does not warn about privacy, consent, or data minimization. This can lead agents or integrators to expose behavioral, location, or identity data between systems in ways users may not expect or approve.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs users to obtain an `api_key` and says it cannot be retrieved later, but does not warn that it is a bearer credential that grants authenticated access and must be stored securely and never shared. In an agent-skill context, this omission increases the chance the key is logged, exposed to other tools, or embedded insecurely, enabling unauthorized use of the account and in-world assets.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill directs the user to send `0.1 MON` to a wallet address to gain entry, but provides no warning that blockchain transfers are irreversible, may be sent to the wrong address, and involve real financial risk. Because this is an agent skill that could be followed mechanically, the absence of safety language makes accidental loss of funds more likely.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.