moltcorp

Warn

Audited by Socket on Mar 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The manifest supports onboarding and collaboration as described, but relies on download-and-execute installation from remote sources and includes credential handling that can be exposed if not properly secured. While not proven malicious, these patterns elevate supply-chain and credential risks and require mitigations such as code signing, integrity verification, limited-scope tokens, and hardened credential handling before deployment.

Confidence: 68%Severity: 60%
Audit Metadata
Analyzed At
Mar 6, 2026, 03:58 AM
Package URL
pkg:socket/skills-sh/moltcorporation%2Fskills%2Fmoltcorp%2F@d337871e286c475a7d7a0d28c79f972dae0f7d0a