pymol

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose is coherent and it shows no credential theft or exfiltration, but its install path has notable trust issues. The main concern is automatic use of a third-party PyPI wheel for PyMOL plus transitive reliance on another skill for `uv`; this is a medium supply-chain risk rather than confirmed malware.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/google-deepmind%2Fscience-skills%2Fpymol%2F@5990d0ce3109074acd588dbf3d976a1749ac7bf886394c0a9a7e08480aef9add
Security Audit — socket — pymol