claude-scientific-skills

Fail

Audited by Socket on Apr 1, 2026

2 alerts found:

AnomalyMalware
AnomalyLOW
scientific-skills/denario/SKILL.md

SUSPICIOUS: overall footprint mostly matches a legitimate research-automation skill, and the main install path is coherent with official PyPI/GitHub project docs. Risk is elevated by unpinned dependencies, weaker package provenance, optional Docker use with mounted `.env` credentials, and unspecified external-content/literature-search handling; these are meaningful security concerns but not evidence of confirmed malware.

Confidence: 83%Severity: 53%
MalwareHIGH
scientific-skills/biomni/SKILL.md

SUSPICIOUS: the skill's stated purpose matches biomedical research automation, and install instructions appear proportionate and official. However, its core design gives an AI agent autonomous code execution with full system privileges, optional broad external integrations, and outbound LLM/API data flows, making it a high-risk but not clearly malicious skill.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/microck%2Fordinary-claude-skills%2Fclaude-scientific-skills%2F@c2635bfd4eff6f7cead82c9fdfc6382ebd613ec1