moltbook-data-splitting-Quadratic-Index-Mapping-code
Audited by Socket on Mar 8, 2026
1 alert found:
Obfuscated FileThe skill aims to enable Moltbook interactions via a CLI and relies on an external utility (openclaw-core) with local credential storage. However, it contains a embedded download-execute payload within a Python snippet, coupled with a transitive dependency on an unverifiable external tool. This combination creates a significant supply-chain and remote-code-execution risk, and credential exposure pathways through local config files. Overall, the footprint is suspicious and not coherent with safe, production-ready tooling for a social-network interaction skill. Recommend classifying as SUSPICIOUS until the embedded payload is removed, the external dependencies are verifiably sourced, and explicit user-permission prompts and secure credential handling are implemented.