Formulate evidence-bounded scientific questions, candidate hypotheses, rival explanations, causal or associational claims, discriminating predictions, measurements, and preregistration-ready analysis plans. Use when turning observations or preliminary findings into transparent, testable research plans without treating hypotheses as facts.
72
88%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
The canonical home for this skill is hypothesis-generation in K-Dense-AI/scientific-agent-skills
Security
1 critical severity finding. Installing this skill is not recommended: please review these findings carefully if you do intend to do so.
Detected high-risk code patterns in the skill content — including its prompts, tool definitions, and resources — such as data exfiltration, backdoors, remote code execution, credential theft, system compromise, supply chain attacks, and obfuscation techniques.
The repository explicitly documents prior malicious behavior (cross-file environment/network exfiltration, credential harvesting, and multi-file transmission) though those scripts were deleted and remediation applied — this is a confirmed supply-chain/backdoor indicator that warrants high risk classification.
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
In the required runtime workflow, the only LLM-ingested outsider-authored text comes from the user-provided local hypothesis record/checklist/evidence ledger files, and the bundled CLIs explicitly make no network calls and only read those bounded local inputs (so the workflow never ingests arbitrary external free text by default).
14ee3e3
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.