Refua
v0.4.1Fold and score biomolecular complexes and optionally profile ADMET to prioritize molecules in drug discovery pipelines via the refua-mcp server.
⭐ 1· 1.8k·1 current·1 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
The SKILL.md describes a Refua-to-MCP integration (folding, affinity scoring, optional ADMET) and all declared requirements match that purpose: it requires running a refua-mcp server and optionally installing refua/refua-mcp and model assets. There are no unrelated environment variables, binaries, or config paths requested.
Instruction Scope
Runtime instructions are focused: pip-install Refua/refua-mcp, download model assets, and run the MCP server (python3 -m refua_mcp.server). The instructions do not ask the agent to read unrelated files or exfiltrate data. Note: starting the MCP server exposes a network service (local or remote) — the operator should consider access controls and firewalling when launching it.
Install Mechanism
This is an instruction-only skill (no install spec). It tells an operator to pip install packages from PyPI and to run a Python asset-download helper. Using pip is expected for a Python ML tool, but pip installs execute arbitrary code from the package; operators should install into an isolated virtualenv/container and verify the package source (the SKILL.md links to the GitHub repo). Model asset downloads may be large and come from external hosts (e.g., HF/GitHub), so check bandwidth, integrity, and provenance.
Credentials
The skill declares no required environment variables, credentials, or config paths. That is proportionate to the stated goal (local MCP server + local model assets).
Persistence & Privilege
The skill does not request always:true, does not request to modify other skills, and contains no install-time operations that would permanently alter agent-wide configuration. Agent autonomous invocation remains allowed (platform default) but is not combined with other concerning privileges.
Assessment
This skill appears coherent for running Refua via an MCP server, but take basic operational precautions before installing/running it:
- Install into an isolated Python environment or container (pip packages run code at install time).
- Verify the package source/repository (the SKILL.md points to github.com/agentcures/refua-mcp) and review maintainers if you need a higher trust level.
- Expect large model downloads and heavy CPU/GPU usage; check disk, GPU drivers, and bandwidth limits before downloading assets.
- When running the MCP server, restrict network exposure (bind to localhost, use firewall rules, or run in an internal network) so the service isn't unintentionally reachable from the public internet.
- No credentials are requested by the skill, but if you add auth or remote endpoints later, ensure secrets are scoped and stored securely.
- Do not use results as clinical or regulatory guidance without domain expert review; the SKILL.md itself warns against wet‑lab/clinical guidance.
If you want a deeper check, provide the refua/refua-mcp PyPI package names or the repository contents so I can review code-level behaviors (install-time scripts, remote URLs used for downloads, and any network/server authorization defaults).Like a lobster shell, security has layers — review code before you run it.
latestvk979bvt3ha63k32ct1c32c0ead80a5ft
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
