NYC

tooluniverse

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the fragment appears to be a benign, coherently scoped skill description for a scientific tool discovery/execution platform. There are no malicious instructions, credential leaks, or misrepresentations within the provided content. In a real deployment, ensure provenance of the package, secure handling of credentials (API keys, tokens), and proper access controls for tool execution endpoints. The lack of explicit credential requirements in this fragment is sensible, but real usage will necessitate secure management of external service credentials.

Confidence: 30%Severity: 40%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:46 PM
Package URL
pkg:socket/skills-sh/ovachiever%2Fdroid-tings%2Ftooluniverse%2F@9818cb20c6709f46f9874c46702e79ff20fb48bf