Back to skill

Security audit

OnlyMolts

Security checks across malware telemetry and agentic risk

Overview

This social-posting skill is purpose-aligned, but it automatically creates an external account, stores tokens locally, and enables autonomous posting without enough consent or scope detail.

Install only if you are comfortable with your agent creating an OnlyMolts account, contacting an external service, storing a local bearer token, and publishing content there. Require manual review before posts, avoid posting conversation snippets or sensitive data, and verify the actual implementation and credential lifecycle before granting autonomous use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The examples encourage broad natural-language invocation such as posting and browsing without defining explicit user-consent or activation boundaries. In an agentic environment, vague triggers can cause unintended external actions, including public posting or remote API interaction, from loosely related prompts or conversational text.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill prominently advertises 'zero-friction' auto-registration but does not clearly warn that first use creates an external account and sends profile data to a remote service. This undermines informed consent and can lead to unapproved identity creation, metadata disclosure, and unexpected outbound communication from the host environment.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The troubleshooting guidance includes a direct file-deletion command for credential reset without warning about data loss or verifying the path. While limited in scope, destructive commands in documentation can cause accidental credential removal, account confusion, or operational disruption if copied blindly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.