tooluniverse-install-skills-d87581 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited tooluniverse-install-skills-d87581 (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Checks whether the ToolUniverse specialized skills are installed and installs them automatically if not.
Use the Shell tool to check for the canary file across all common client locations:
ls .cursor/skills/tooluniverse-drug-research/SKILL.md 2>/dev/null \
|| ls .agents/skills/tooluniverse-drug-research/SKILL.md 2>/dev/null \
|| ls .windsurf/skills/tooluniverse-drug-research/SKILL.md 2>/dev/null \
|| ls .gemini/skills/tooluniverse-drug-research/SKILL.md 2>/dev/null \
|| ls .claude/skills/tooluniverse-drug-research/SKILL.md 2>/dev/null \
|| ls .opencode/skills/tooluniverse-drug-research/SKILL.md 2>/dev/null \
|| ls .trae/skills/tooluniverse-drug-research/SKILL.md 2>/dev/null \
|| ls .skills/tooluniverse-drug-research/SKILL.md 2>/dev/null \
|| echo "NOT_INSTALLED"# 1. Download skills from GitHub (shallow, sparse — only skills/ folder)
git clone --depth 1 --filter=blob:none --sparse \
https://github.com/mims-harvard/ToolUniverse.git /tmp/tu-skills
cd /tmp/tu-skills && git sparse-checkout set skills
# 2. Copy to the correct directory for the detected client:
mkdir -p .cursor/skills && cp -r /tmp/tu-skills/skills/* .cursor/skills/ # Cursor
# mkdir -p .agents/skills && cp -r /tmp/tu-skills/skills/* .agents/skills/ # Codex/OpenAI
# mkdir -p .windsurf/skills && cp -r /tmp/tu-skills/skills/* .windsurf/skills/ # Windsurf
# mkdir -p .gemini/skills && cp -r /tmp/tu-skills/skills/* .gemini/skills/ # Gemini CLI
# mkdir -p .claude/skills && cp -r /tmp/tu-skills/skills/* .claude/skills/ # Claude Code
# mkdir -p .opencode/skills && cp -r /tmp/tu-skills/skills/* .opencode/skills/ # OpenCode
# mkdir -p .trae/skills && cp -r /tmp/tu-skills/skills/* .trae/skills/ # Trae
# mkdir -p .skills && cp -r /tmp/tu-skills/skills/* .skills/ # Cline/VS Code
# 3. Clean up
rm -rf /tmp/tu-skillsIf the client cannot be detected automatically, ask the user which one they use before running step 2.
Detect the client from the presence of config files:
| Config file present | Client |
|---|---|
.cursor/ | Cursor |
.agents/ | Codex / OpenAI |
.windsurf/ | Windsurf |
.gemini/ | Gemini CLI |
.claude/ | Claude Code |
.opencode/ | OpenCode |
.trae/ | Trae |
| None of the above | Ask the user |
Confirm success:
ls .cursor/skills/tooluniverse-drug-research/SKILL.mdTell the user: "ToolUniverse skills installed successfully. You now have access to 50+ specialized research workflows."
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.