ai-for-science-oligoformer

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities are mostly aligned with an Ascend NPU migration guide, and it does not seek disproportionate credentials or route data to odd endpoints. However, it instructs the agent to download and extract RNA-FM from a file-sharing tarball without checksums/signatures instead of the upstream repo/package path, creating a meaningful supply-chain trust issue. This looks more like a risky install choice than confirmed malware.

Confidence: 89%Severity: 58%
Audit Metadata
Analyzed At
Mar 28, 2026, 02:18 AM
Package URL
pkg:socket/skills-sh/ascend-ai-coding%2Fawesome-ascend-skills%2Fai-for-science-oligoformer%2F@326a6ca92a4db5f941e3577501915d04265d3171
Security Audit — socket — ai-for-science-oligoformer