Moltext
PassAudited by VirusTotal on May 15, 2026.
Findings (1)
The skill is classified as suspicious due to its reliance on a global `npm install` for the `moltext` package, which introduces a supply chain risk by executing arbitrary code from an external source. Additionally, the skill explicitly handles API keys for external services (OpenAI) and connects to local inference servers, representing risky capabilities involving network access and sensitive credential management, even though these are for the stated purpose of compiling documentation.
