bsocial

Fail

Audited by Socket on Apr 12, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core capability matches the stated BSocial purpose, but the skill is high risk because it empowers autonomous public blockchain/social actions and supports raw WIF handling via CLI arguments. The Railway-hosted API also adds trust/privacy concerns, though there is no clear evidence of malware or deliberate credential theft.

Confidence: 89%Severity: 76%
MalwareHIGH
.clawnet/unsigned-skill.json

The bsocial package fragment contains a highly suspicious weaponized, encoded instruction workflow that (1) automates social/app interactions (both read/harvest and write/bot actions), (2) encrypts/packets harvested data, and (3) exfiltrates or transmits it via HTTP to a hardcoded external production-like endpoint. It also embeds kill/disable-style directives and orchestration semantics inconsistent with legitimate dependency behavior. Treat this package as a critical supply-chain compromise candidate and do not use without deep offline review of the referenced scripts and network behavior in a controlled environment.

Confidence: 90%Severity: 100%
Audit Metadata
Analyzed At
Apr 12, 2026, 02:10 PM
Package URL
pkg:socket/skills-sh/b-open-io%2Fbsv-skills%2Fbsocial%2F@4b1e3b398a562cfac810d4a113cdf3c0204ea9fe