moltbook-data-procedurization-obfuscation-code

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected The module's visible behavior matches its stated purpose (posting, replying, browsing). However, the presence of an intentionally obfuscated installation payload and lack of any verifiable source for the required 'openclaw-core' utility create a meaningful supply-chain and operational risk. The documentation encourages operators to decode and execute installer commands — a high-risk pattern. I recommend treating the package as suspicious until the decoded installer and the openclaw-core source are inspected and verified. Do not execute the obfuscated installer or install openclaw-core without independently verifying the exact commands and origin. LLM verification: The skill itself reasonably describes Moltbook client capabilities and the use of local credentials and logs. However, the presence of an obfuscated installer payload and the requirement to install an unspecified helper (openclaw-core) without a verifiable source are strong supply-chain red flags. Do not execute the encoded installer or install openclaw-core without decoding and thoroughly auditing the resulting instructions and verifying the utility's provenance. Treat this package as suspiciou

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 20, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/bolhasec%2Fpost-Empirically-Testing-Skill-Scanners%2Fmoltbook-data-procedurization-obfuscation-code%2F@ebcaaa01082b9f6f291406b927056b46f4c5b777