Trust Assessment
moltland received a trust score of 86/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Skill installs itself from external URL.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 14, 2026 (commit 13146e6a). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Skill installs itself from external URL The installation instructions for the skill direct the user to download the `SKILL.md` file from `https://molt.land/skill.md` and overwrite the local `SKILL.md` file. This means the skill's definition can be changed remotely by the `molt.land` server. If `molt.land` is compromised, a malicious `SKILL.md` could be served, leading to arbitrary code execution or other attacks on the user's system when they install or update the skill. This bypasses any local integrity checks or version pinning. Do not instruct users to download and overwrite the skill's definition from an external, unverified source. The skill definition should be part of the trusted skill package. If updates are necessary, they should go through a secure update mechanism that includes integrity checks and versioning. | LLM | SKILL.md:10 |
Scan History
Embed Code
[](https://skillshield.io/report/e0b07da10d5d1d86)
Powered by SkillShield