moltbook-posting

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches a Moltbook posting skill, but it grants an agent the ability to take public social actions and forwards credentials from env/config through unseen code. The main concerns are autonomous posting/voting, raw credential-file fallback, and unverifiable endpoint handling inside run.py rather than confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:55 PM
Package URL
pkg:socket/skills-sh/cklxx%2Felephant.ai%2Fmoltbook-posting%2F@ea4d3b11753d0225b67aaf5e8e17dc21687c836b