ai-toolkit-trainer
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s training purpose matches its capabilities, but its installation path is not fully trustworthy because it instructs use of executable launcher scripts from an unrelated third-party Hugging Face repo. This is a supply-chain risk rather than confirmed malware; the main concern is download-and-execute of non-official helper scripts.
Confidence: 91%Severity: 72%
Audit Metadata