mutation-design-aav

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for computational AAV mutant design, but it relies on opaque shared-file downloads for a PyTorch oracle model that is loaded with torch.load(), creating a high supply-chain and arbitrary code execution risk. No credential theft or exfiltration is evident, so this is not confirmed malware, but the install/execution trust is poor and the biological optimization target is sensitive.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
Mar 25, 2026, 05:58 AM
Package URL
pkg:socket/skills-sh/PharMolix%2FOpenBioMed%2Fmutation-design-aav%2F@20126c0b3763564616e31e1b840621a73c0544b1