pymatgen
Fail
Audited by Socket on Mar 3, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
This skill description documents a legitimate pymatgen integration skill. Its capabilities, required credentials (MP_API_KEY), and network endpoints (Materials Project via mp-api) are consistent with the stated purpose. There are no indicators of credential harvesting, obfuscated/malicious code, remote download-and-execute instructions, or routing to third-party exfiltration endpoints. The only minor anomaly is a likely typographic error ('uv pip install'). Overall the skill appears benign; users should follow normal precautions around protecting their MP_API_KEY and running generated computational inputs in trusted environments.
Confidence: 95%Severity: 90%
Audit Metadata