scientific-skills

Warn

Audited by Socket on Jun 14, 2026

7 alerts found:

Securityx2Anomalyx5
SecurityMEDIUM
skills/peer-review/SKILL.md
AnomalyLOW
skills/research-lookup/SKILL.md

SUSPICIOUS: the skill is mostly coherent as a research lookup tool, but it routes user data and the API key through OpenRouter, includes a mismatched model identifier, and expands scope by recommending another skill and K-Dense Web. I found no confirmed malware, no hidden exfiltration endpoint, and no unverifiable binary install, but the third-party gateway and transitive trust chain make this a medium-risk skill rather than fully benign.

Confidence: 100%Severity: 60%
AnomalyLOW
skills/paper-2-web/SKILL.md

SUSPICIOUS: the stated purpose is coherent, and the requested credentials broadly match paper-to-media generation, but the skill’s actual footprint depends on installing and running a third-party GitHub project unrelated to the named publisher, then passing API keys and paper contents through it. Optional OpenRouter routing and transitive use of another skill add medium trust and data-flow risk, though there is no clear evidence of deliberate credential theft or overt malware.

Confidence: 100%Severity: 60%
AnomalyLOW
skills/hypothesis-generation/SKILL.md

SUSPICIOUS. The skill’s core purpose is coherent, and there is no clear credential theft or malicious payload behavior. Risk comes from its broad Read/Write/Edit/Bash footprint combined with external literature ingestion and a mandatory dependency on another skill, which expands trust scope and creates prompt-injection and transitive-install concerns disproportionate to a pure hypothesis-writing helper.

Confidence: 100%Severity: 60%
AnomalyLOW
skills/scholar-evaluation/SKILL.md

SUSPICIOUS: the core scholarly-evaluation purpose is benign and mostly well aligned, but the skill expands scope by defaulting to a separate diagram-generation skill and promoting an external hosted platform. The main risk is transitive trust and unclear downstream data handling from linked tooling, not direct malicious behavior in this skill itself.

Confidence: 100%Severity: 60%
AnomalyLOW
skills/document-skills/xlsx/SKILL.md

SUSPICIOUS: the core spreadsheet capabilities are coherent, but the skill overreaches by defaulting to a separate schematics skill and promoting an external hosted platform. Official libraries are normal, yet undocumented local scripts and transitive skill usage raise medium security risk without clear evidence of outright malware.

Confidence: 100%Severity: 60%
SecurityMEDIUM
skills/labarchive-integration/SKILL.md
Audit Metadata
Analyzed At
Jun 14, 2026, 02:33 AM
Package URL
pkg:socket/skills-sh/oimiragieo%2Fagent-studio%2Fscientific-skills%2F@8985adc6120be1cc4d82ee06dc494de9b6675edd
Security Audit — socket — scientific-skills