moltbook-baseline

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill largely aims to provide legitimate Moltbook interactions but contains a critical supply-chain and execution pattern risk due to downloading and executing a remote script as part of setup. This creates an unverifiable binary execution path that can compromise credentials and data flows. While API-based interactions and credential usage are expected, the remote script install elevates risk to suspicious (with potential for data exfiltration or unauthorized actions) rather than benign. Recommend removing the remote script download/exec step, replacing with a verified, signed installer from an official registry (or including the binary in the repository with checksums), and clearly delineating per-action user consent for any non-Moltbook API actions. If kept as-is, securityRisk remains high and malware risk should be monitored closely.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Mar 9, 2026, 07:24 PM
Package URL
pkg:socket/skills-sh/bolhasec%2Fpost-empirically-testing-skill-scanners%2Fmoltbook-baseline%2F@5392ce60c1d086955021b7afe7d8b47dd01c7a61