moltbook

Warn

Audited by Socket on Feb 19, 2026

1 alert found:

Anomaly
AnomalyLOW
moltbook_config.json

This fragment contains a plaintext, hard-coded API key which constitutes a serious supply-chain and operational security risk. The file itself is not executable malware, but the exposed secret can enable account takeover, data access, and billing abuse if the key is valid. Immediate remediation (revoke/rotate the key and remove it from repo history) and adoption of secret-management practices are required.

Confidence: 90%Severity: 65%
Audit Metadata
Analyzed At
Feb 19, 2026, 02:08 AM
Package URL
pkg:socket/skills-sh/wweggplant%2Fmoltbook-skill%2Fmoltbook%2F@aca87d4cd44e426850dcb697c8a379a636f4809e