ai-toolkit-trainer

Warn

Audited by Socket on Sep 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s training purpose matches its capabilities, but its installation path is not fully trustworthy because it instructs use of executable launcher scripts from an unrelated third-party Hugging Face repo. This is a supply-chain risk rather than confirmed malware; the main concern is download-and-execute of non-official helper scripts.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Sep 7, 2026, 01:59 PM
Package URL
pkg:socket/skills-sh/artokun%2Fcomfyui-mcp%2Fai-toolkit-trainer%2F@03700267ecfad0bdf6199c2afeb077aa501aacd921e14a5b2cf73dfc88e971bf
Security Audit — socket — ai-toolkit-trainer