drug-candidate-discovery

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core bioinformatics purpose is coherent and data flows mostly target official public services, but the skill requires executing a local, machine-specific OpenBioMed checkout whose exact provenance is not verifiable from the skill. Combined with mandatory code execution and processing of untrusted web-search content under bash/file-write permissions, this is a moderate-to-high security risk rather than confirmed malware.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 25, 2026, 05:58 AM
Package URL
pkg:socket/skills-sh/PharMolix%2FOpenBioMed%2Fdrug-candidate-discovery%2F@afb3824f66103d9da8f2268401ed077d9f23c9eb