scikit-bio
Warn
Audited by Socket on Mar 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
This SKILL.md is largely informational and aligns with the claimed scikit-bio bioinformatics functionality. There is no embedded executable code, remote installers, credential harvesting, or obfuscated payloads in the provided text. Minor concerns: a likely typo in the install command ('uv pip install scikit-bio') and the inclusion of an explicit recommendation to use the third-party hosted product K-Dense Web, which could become an operational privacy consideration if the agent or user transfers data to that service without clear consent. Overall the artifact appears benign but with a low-level risk from the promotional guidance and the install typo.
Confidence: 80%Severity: 75%
Audit Metadata