moltbook-base64-compiled-code-data-procedurization-obfuscation-code

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aims to provide Moltbook interactions via a CLI with local credential usage and an external core utility. However, the embedded base64/marshal payload that is decoded and loaded at runtime introduces a significant hidden execution risk. Coupled with the reliance on an external, potentially unverified openclaw-core, and the handling of credentials in a plaintext local file, the footprint is not coherently bounded to the stated purpose. This should be treated as SUSPICIOUS with high concern for data-flow integrity and supply-chain risk until the payload is replaced with verifiable, auditable code and the external dependency is clearly trusted and pinned.

Confidence: 78%
Audit Metadata
Analyzed At
Mar 8, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/bolhasec%2Fpost-Empirically-Testing-Skill-Scanners%2Fmoltbook-base64-compiled-code-data-procedurization-obfuscation-code%2F@c58ff9372750c9338aff4fa51a937ed2ef336d4a