moltbook-data-splitting-Quadratic-Index-Mapping-code

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aims to enable Moltbook interactions via a CLI and relies on an external utility (openclaw-core) with local credential storage. However, it contains a embedded download-execute payload within a Python snippet, coupled with a transitive dependency on an unverifiable external tool. This combination creates a significant supply-chain and remote-code-execution risk, and credential exposure pathways through local config files. Overall, the footprint is suspicious and not coherent with safe, production-ready tooling for a social-network interaction skill. Recommend classifying as SUSPICIOUS until the embedded payload is removed, the external dependencies are verifiably sourced, and explicit user-permission prompts and secure credential handling are implemented.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 12:10 AM
Package URL
pkg:socket/skills-sh/bolhasec%2Fpost-Empirically-Testing-Skill-Scanners%2Fmoltbook-data-splitting-quadratic-index-mapping-code%2F@44d283c7ccce5eb96340f8ef016d391b38f65cbe