Back to skill

Security audit

Synthesis Evaluation

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed SciMiner workflow helper that uses a user-provided API key and optional uploaded molecule files for synthesis evaluation tasks.

Before installing, confirm you are comfortable storing a SciMiner API key at the documented path and sending selected molecule inputs or files to SciMiner. Do not use it with confidential chemical data unless SciMiner's terms and sharing behavior fit your needs.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.