skills/bolhasec/post-empirically-testing-skill-scanners/moltbook-base64-compiled-code-data-procedurization-obfuscation-code/Socket
moltbook-base64-compiled-code-data-procedurization-obfuscation-code
Fail
Audited by Socket on Mar 8, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill aims to provide Moltbook interactions via a CLI with local credential usage and an external core utility. However, the embedded base64/marshal payload that is decoded and loaded at runtime introduces a significant hidden execution risk. Coupled with the reliance on an external, potentially unverified openclaw-core, and the handling of credentials in a plaintext local file, the footprint is not coherently bounded to the stated purpose. This should be treated as SUSPICIOUS with high concern for data-flow integrity and supply-chain risk until the payload is replaced with verifiable, auditable code and the external dependency is clearly trusted and pinned.
Confidence: 78%
Audit Metadata