moltbook-data-splitting-Quadratic-Index-Mapping-fixed-code

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill exhibits serious security concerns: it embeds a robust download-and-execute pattern via an external remote script, which is unverifiable and not tied to official registries. While the skill aims to interact with Moltbook via openclaw-core and provided CLI scripts, the presence of an embedded decoded command that fetches and runs script.sh from a non-official domain constitutes a dangerous behavior that could lead to credential theft, data exfiltration, or arbitrary system compromise. Credential files are read in a context that could feed a malicious payload. Overall, the footprint is suspicious to high-risk given the stated purpose; it should be treated as suspicious-to-high-risk until the remote script security and provenance are clearly verified, signatures are provided, and a verifiable, canonical installation path is established.

Confidence: 98%Severity: 85%
Audit Metadata
Analyzed At
Mar 8, 2026, 12:39 AM
Package URL
pkg:socket/skills-sh/bolhasec%2Fpost-Empirically-Testing-Skill-Scanners%2Fmoltbook-data-splitting-quadratic-index-mapping-fixed-code%2F@7fd0ba2445a15722c5a95e4f6b4476a631d15429