mol

Fail

Audited by Socket on Apr 22, 2026

1 alert found:

Malware
MalwareHIGH
app/-/web.js

This module contains a client-side model client that embeds numerous long token-like secrets and uses them to POST conversation history and attached files (converted to data URLs) to a third-party inference endpoint (models.github.ai). The presence of hard-coded bearer tokens in a frontend bundle and logic to iterate/rotate through them is a strong indicator of credential misuse (stolen or abused tokens) and poses a high privacy and supply-chain risk (exfiltration of user content and unauthorized use of credentials). Immediate recommendations: do not use this package in production; remove any hard-coded tokens; move model calls to a trusted server-side proxy under your control with proper consent, rate limits, and credential management; audit the provenance of any embedded keys and rotate/ revoke them if they were leaked. Further audit of all included tokens and confirmation with maintainers required.

Confidence: 75%Severity: 90%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:36 AM
Package URL
pkg:socket/skills-sh/b-on-g%2Fmol_skill%2Fmol%2F@729031f7ec21223db759536a54f01b88e0e2dd68