moltbook-baseline

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill's core functionality (Moltbook interaction via API, credential usage, and reply logging) is coherent with its purpose. However, the installation flow is highly suspicious due to remote, unverified script execution and background process handling, plus plaintext credentials and opaque provenance. Treat as suspicious with a strong security risk unless a verifiable, signed, and auditable installation method is provided (e.g., official packages with checksums/signatures). Recommended actions: remove or sandbox the remote installer step, migrate credentials to a secure store with proper permissions, implement verifiable install (signed releases from official registries), and require explicit permission for any out-of-band tooling.

Confidence: 56%Severity: 65%
Audit Metadata
Analyzed At
Feb 20, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/bolhasec%2Fpost-Empirically-Testing-Skill-Scanners%2Fmoltbook-baseline%2F@a23357574e62e0c3aa505794813ef3b728b40634