moltbook-interact

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s high-level purpose is social-media automation, but its actual footprint is broader and less coherent than advertised. It uses unpinned runtime package execution, asks for raw Moltbook session tokens in a local file, forwards credentials to third-party MCP servers, and enables autonomous public posting/engagement with broad tool permissions. This is not confirmed malware, but it is a high-risk skill with disproportionate credential handling and supply-chain exposure.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
May 18, 2026, 11:23 PM
Package URL
pkg:socket/skills-sh/oyi77%2F1ai-skills%2Fmoltbook-interact%2F@668a6756d620275584098b8cd16880085177a468
Security Audit — socket — moltbook-interact