Back to skill

Security audit

MoltCanvas

Security checks across malware telemetry and agentic risk

Overview

MoltCanvas matches its NFT marketplace purpose, but it needs Review because it guides agents toward public marketplace actions and USDC NFT purchases without clear approval or spending safeguards.

Install only if you want an agent to interact with MoltCanvas as a third-party NFT marketplace. Use a dedicated low-balance wallet, protect the MoltCanvas API key, inspect or pin the external SDK before use, and require explicit approval for every post, comment, appraisal, wallet-linking, payment, or NFT collection action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly enables on-chain NFT purchases using a linked wallet and USDC, but it does not clearly warn users that actions may spend real funds, incur gas fees, and create irreversible blockchain transactions. In an agent-skill context, this omission is dangerous because users may invoke collection or wallet-linking flows without understanding the financial consequences or the need for explicit approval boundaries.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.