Scientific Agent Skills, formerly Claude Scientific Skills, is K-Dense's collection of 177 skills that teach AI agents how to use scientific software and data correctly. They cover bioinformatics and genomics (Scanpy, Biopython, single-cell RNA-seq, CRISPR screens, primer design), cheminformatics and drug discovery (RDKit, docking, ADMET), proteomics, clinical research, microscopy and medical imaging, materials science, physics and astronomy, lab automation (Opentrons, Benchling, protocols.io), and scientific writing, posters and slides.
Each skill is a SKILL.md with the package's workflow, version notes and the validation checks a scientist would expect, often with helper scripts and their own tests. A database-lookup skill documents 80 sources such as PubChem, ChEMBL, UniProt, ClinicalTrials.gov and NCBI, with how to page through results and record where data came from. The agent can still use any Python package; these skills are the pre-documented paths that make it more reliable.
The repository is MIT-licensed, has about 48,000 stars and 59 contributors, and is described in a paper on arXiv. It is large: roughly 2,800 files, 684,000 lines and a 290 MB clone. K-Dense itself advises installing only the skills you need, partly because many are now community contributions, and notes that individual skills can carry their own licence terms.
- Repository: github.com/K-Dense-AI/scientific-agent-skills
- Licence: MIT (MIT License)
- Language: Python. Stars: 48K. Forks: 4,327. Last push: Oct 5, 2026.
- Scan: safe, Oct 8, 2026, commit 92ace75
Who it is for
Researchers, lab scientists and computational biologists or chemists who use Claude Code, Codex, Cursor or a similar agent for analysis and want it to follow each field's conventions instead of improvising with unfamiliar libraries.
Getting started
1. Install with the npx skills installer (Claude Code, Codex, Cursor, Gemini CLI and others)
npx skills add K-Dense-AI/scientific-agent-skills2. Or with the GitHub CLI, choosing skills interactively
gh skill install K-Dense-AI/scientific-agent-skills3. Install a single skill for Claude Code
gh skill install K-Dense-AI/scientific-agent-skills scanpy --agent claude-codeInstalling the skill files does not install their scientific dependencies. The README asks for Python and uv, and recommends a separate environment per workflow because some skills pin incompatible package versions.
Safety scan
We cloned K-Dense-AI/scientific-agent-skills at commit 92ace75 on Oct 8, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- One secret hit: a fake OpenSSH private key block in tests/autoskill/test_redact.py, test data that checks the redaction helper removes keys. It is not a real key. No suspicious code patterns, binaries or installer scripts across about 2,800 files.
- A second, skill-specific pass for invisible Unicode, prompt-injection phrases, exfiltration hosts, credential paths and pipe-to-shell commands found nothing malicious. The README says every skill is also scanned with Cisco's AI Defense Skill Scanner, and docs/security-report.json publishes those results.
- Many skills call outside services: public science APIs such as NCBI, EBI, OpenAlex, arXiv, bioRxiv, Crossref and KEGG, and in a few skills (image generation, posters, literature review) openrouter.ai or api.anthropic.com with your own key. Your queries, and for the model APIs your prompts, go to those services.
- Two reference documents show vendors' own curl | sh installers, for Paperclip (paperclip.gxl.ai) and the Pi agent (pi.dev). These are third-party tools that run only if you choose to install them.
- No known advisories in the requirements files. Five workflows, none using pull_request_target. Security policy, licence, contributing guide and code of conduct present; no Dependabot or CodeQL.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | 1 candidate found and read; see the notes above. |
| Suspicious code | None found. |
| Install-time code | None: nothing runs at install beyond the package manager itself. |
| Committed binaries | None. |
| CI workflows | 5 workflows. None use pull_request_target. 7 of 7 third-party actions pinned to a tag rather than a commit. |
| Network hosts | 40 distinct hosts referenced from source; most often openrouter.ai, doi.org, example.invalid, www.protocols.io. No URLs to bare IP addresses. |
| Known vulnerabilities | 0 advisories across 6 pinned packages: 0 critical, 0 high, 0 moderate, 0 low. skills/13c-metabolic-flux/assets/requirements.txt: 3 packages, 0 advisories; skills/opentrons-integration/requirements-flex.txt: 1 packages, 0 advisories; skills/opentrons-integration/requirements-ot2.txt: 1 packages, 0 advisories; skills/primer-design/assets/requirements.txt: 1 packages, 0 advisories. |
| Project hygiene | Has security policy, licence file, contributing guide. Missing automated dependency updates, CodeQL. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Secret candidates (1, redacted)
| Where | Rule | Match |
|---|---|---|
| tests/autoskill/test_redact.py:78 | private-key | -----B…--- (35 chars) |
By the numbers
| Stars | 48K |
|---|---|
| Forks | 4,327 |
| Contributors | 59 |
| Commits | 759 |
| Open issues | 2 |
| Open pull requests | 20 |
| Releases | 109 |
| Latest release | v2.72.0 |
| Licence | MIT |
| Main language | Python |
| Project age | 11 months |
| Last push | Oct 5, 2026 |
| Tracked files | 2,780 |
| Lines of code | 684.4K |
| Checkout size | 291 MB |
Lines by language: Markdown 331.2K, Python 249.4K, JSON 100.7K, YAML 1,691, TOML 941, Shell 247.
Questions
Is Scientific Agent Skills free?
Yes. The repository is MIT-licensed and free, though some individual skills declare their own licence in their SKILL.md, so check those before reusing them in a product. You still need an AI agent such as Claude Code, Codex or Cursor under its own pricing, and some databases or services the skills use require registration or a paid licence.
Should I install all 177 skills?
Probably not. K-Dense's own security notes advise installing only what you need and reading each SKILL.md first, since many skills are community contributions. The GitHub CLI and npx skills installers both let you pick individual skills, which also keeps your agent's skill list focused.
Is it safe for clinical or patient data?
The skills are research aids, not tools for patient-specific diagnosis or treatment decisions. Data you analyse locally stays on your machine, but any skill that queries an online database or model API sends your query there, so check a skill's external services before using it with confidential data.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
