denario
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: overall footprint mostly matches a legitimate research-automation skill, and the main install path is coherent with official PyPI/GitHub project docs. Risk is elevated by unpinned dependencies, weaker package provenance, optional Docker use with mounted `.env` credentials, and unspecified external-content/literature-search handling; these are meaningful security concerns but not evidence of confirmed malware.
Confidence: 83%Severity: 53%
Audit Metadata