1 check that ran failed — version behavior — so this release can’t be trusted as-is.
- Publisher
- io.github.mims-harvard
- Repository
- github.com/mims-harvard/ToolUniverse
- Install
- pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse, pypi:tooluniverse
- Versions
- 30
- Inspected
- 5 of 6 checks · 75%
- Scored
- 2026-08-31 · rubric 1.0.0
What we checked
Six static checks, weighted by risk. Every result reflects only what could be observed in the published package and repository — never intent.
Injection surface
unscannable25% of gradeTool descriptions/manifest scanned for instruction-injection patterns (imperatives at the model, hidden text, 'ignore previous', data-exfil URLs).
No tool descriptions, server instructions, prompts, or resources were fetched; nothing to scan for injection.
Supply chain
pass25% of gradePackage provenance: namespace verification, repo linkage, maintainer count, account age, postinstall scripts, typosquat distance.
Python build script has no build-time network/exec; repository linkage verified
Credential hygiene
pass15% of gradeHow the server takes secrets (env vs plaintext config vs hardcoded); secrets appearing in tool schemas.
Reads secrets from the environment (e.g. src/tooluniverse/__init__.py) — the recommended intake shape. PASS = no static red flag; static analysis cannot prove the code honors env-based secret handling at runtime.
Permission scope
warn15% of gradeDeclared tools vs. breadth (filesystem, network, exec); flags shell-exec and unbounded filesystem access.
has both shell/exec and network egress — capable of download-and-run, though no such path was observed (src/tooluniverse/boltz_tool.py: subprocess.* call; src/tooluniverse/alphafold_tool.py: outbound HTTP/socket call). has both shell/exec and destructive filesystem writes (src/tooluniverse/boltz_tool.py: subprocess.* call; src/tooluniverse/boltz_tool.py: open(…, 'w'/'a'/'x') write-mode file access). discloses shell/exec capability: 6 files (src/tooluniverse/boltz_tool.py, src/tooluniverse/compose_scripts/tool_discover.py, src/tooluniverse/generate_tools.py, +3 more) discloses dynamic code execution: 4 files (src/tooluniverse/compose_tool.py, src/tooluniverse/custom_tool.py, src/tooluniverse/rcsb_pdb_tool.py, +1 more) discloses broad/destructive filesystem access: 7 files (src/tooluniverse/boltz_tool.py, src/tooluniverse/compose_scripts/tool_discover.py, src/tooluniverse/compose_scripts/tool_graph_composer.py, +4 more) Capability DISCLOSURE, not a verdict: static analysis sees the primitive is present and reachable, not whether its use is attacker-controlled.
Version behavior
fail10% of gradeDiff of tool definitions between versions; new permissions or changed descriptions in a patch release (the postmark-mcp class).
vs prior 1.4.0 (patch bump): new capability primitive(s) in source: child_process, fs-write, http-client, net, subprocess; new hardcoded outbound host/BCC destination(s): ..., 0.0.0.0, actionability.clinicalgenome.org, aiscientist.tools, alphafold.ebi.ac.uk, alphamissense.hegelab.org, analysis-server, api.archives-ouvertes.fr, api.biorxiv.org, api.cellmodelpassports.sanger.ac.uk, api.cellosaurus.org, api.clinpgx.org, api.core.ac.uk, api.emolecules.com, api.fda.gov, api.gbif.org, api.gdc.cancer.gov, api.genetics.opentargets.org, api.github.com, api.medrxiv.org, api.monarchinitiative.org, api.nvcf.nvidia.com, api.obis.org, api.omim.org, api.oncokb.org, api.openaire.eu, api.openalex.org, api.orphacode.org, api.orphadata.com, api.osf.io, api.pharmgkb.org, api.platform.opentargets.org, api.semanticscholar.org, arxiv.org, azure-ai.hms.edu, batch.rfam.org, bigg.ucsd.edu, biocyc.org, brenda-enzymes.org, build.nvidia.com, cadd.gs.washington.edu, cdnjs.cloudflare.com, chip-atlas.dbcls.jp, chip-atlas.org, civicdb.org, clinicaltables.nlm.nih.gov, clinicaltrials.gov, d3js.org, dailymed.nlm.nih.gov, data.4dnucleome.org, data.cdc.gov, data.rcsb.org, dblp.org, dbpedia.org, deepgo.cbrc.kaust.edu.sa, demo.oncokb.org, depmap.sanger.ac.uk, dgidb.org, doaj.org, docs.gpcrdb.org, doi.org, enamine.net, erepo.clinicalgenome.org, europepmc.org, eutils.ncbi.nlm.nih.gov, evemodel.org, example.com, export.arxiv.org, fair.healthinformationportal.eu, files.rcsb.org, github.com, gnomad.broadinstitute.org, gpcrdb.org, gtexportal.org, hb.flatironinstitute.org, health.api.nvidia.com, hmdb.ca, huggingface.co, integrate.api.nvidia.com, jaspar.elixir.no, maayanlab.cloud, metacyc.org, ml-server, mychem.info, mygene.info, myvariant.info, new.enaminestore.com, odphp.health.gov, omim.org, openrouter.ai, opig.stats.ox.ac.uk, paleobiodb.org, pangolin-37-xwkwwwxdwq-uc.a.run.app, pangolin-38-xwkwwwxdwq-uc.a.run.app, pharos-api.ncats.io, pharos.nih.gov, pubchem.ncbi.nlm.nih.gov, purl.org, pypi.org, pypistats.org, query-api.iedb.org, reactome.org, regulomedb.org, rest.ensembl.org, rest.kegg.jp, rfam.org, rnacentral.org, rxnav.nlm.nih.gov, scholar.archive.org, search.clinicalgenome.org, search.rcsb.org, server, service.azul.data.humancellatlas.org, simbad.cds.unistra.fr, sparql.dsmz.de, spliceai-37-xwkwwwxdwq-uc.a.run.app, spliceai-38-xwkwwwxdwq-uc.a.run.app, stitch.embl.de, string-db.org, w3id.org, webservice.thebiogrid.org, www.atsdr.cdc.gov, www.bindingdb.org, www.biorxiv.org, www.cbioportal.org, www.countyhealthrankings.org, www.dgidb.org, www.disgenet.org, www.ebi.ac.uk, www.emolecules.com, www.encodeproject.org, www.fda.gov, www.guidetopharmacology.org, www.hmdb.ca, www.imgt.org, www.medrxiv.org, www.metabolomicsworkbench.org, www.ncbi.nlm.nih.gov, www.oncokb.org, www.pathwaycommons.org, www.proteinatlas.org, www.semanticscholar.org, www.w3.org, wwwn.cdc.gov, xmlns.com, zitniklab.hms.harvard.edu.
Transport config
warn10% of gradeRemote servers: TLS and auth mode (none/token/OAuth). Local servers: whether the manifest indicates it phones home.
manifest/source references telemetry behavior — disclosure
Version history
Each release plotted by grade against the safe line at B. A version that sinks below the line has lost its trusted standing — the shape of a rug-pull.
| Version | Published | Grade | Score | Inspected | Change |
|---|---|---|---|---|---|
| v1.4.1 · current | 2026-08-12 | B | 77.5 | 5/6 · 75% | ±0 |
| v1.4.0 | 2026-07-24 | B | 100 | 3/6 · 55% | ±0 |
| v1.3.1 | 2026-07-02 | B | 87.5 | 4/6 · 65% | ±0 |
| v1.1.11 | 2026-03-29 | B | 100 | 3/6 · 55% | — |