moltbook-posting

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s social-posting purpose matches its capabilities, but it enables autonomous public actions, reads raw API credentials from a local config, and permits endpoint override that could redirect those credentials off Moltbook’s official API. With run.py absent, the true data flow cannot be verified, so overall risk is high even without confirmed malware.

Confidence: 85%Severity: 81%
Audit Metadata
Analyzed At
Mar 15, 2026, 02:07 AM
Package URL
pkg:socket/skills-sh/cklxx%2Felephant.ai%2Fmoltbook-posting%2F@d632d57fe6d462527e1da4fa91d6a8d1b30c4c84