NYC

esm

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This skill documentation is coherent: capabilities match the described purpose (protein sequence generation, structure prediction, embeddings) and required credentials (Forge token) are proportional. No direct malicious code or supply-chain credential-harvesting patterns are present in the provided text. Main issues are: (1) operational risk from dual-use biological capabilities (biosafety/ethics) inherent to protein design tools, (2) unsafe example showing inline tokens, (3) use of a URL shortener and a likely typo in install instructions which could be cleaned up. Overall there is low likelihood of embedded malware, but moderate security/operational risk primarily from misuse and poor secret-handling practices.

Confidence: 70%Severity: 45%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/ovachiever%2Fdroid-tings%2Fesm%2F@dcd5f094e7a09fb214cc905bc62af3a075d01eb4