ai-scientist

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core issue is install-trust mismatch: the skill presents itself as a wrapper for SakanaAI/AI-Scientist-v2 but directs installation of a separate PyPI package with no verified same-org relationship. The requested capabilities otherwise fit the stated research purpose, but forwarding API keys to an ambiguously sourced package materially raises risk.

Confidence: 90%Severity: 83%
Audit Metadata
Analyzed At
Apr 8, 2026, 04:52 AM
Package URL
pkg:socket/skills-sh/TerminalSkills%2Fskills%2Fai-scientist%2F@650b7f37d826ab4118dd6cabe7762f017234bbc8