npu-torchair-infer

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run_benchmark.sh

This bash wrapper itself does not show obvious malicious payload behavior (no exfiltration/persistence/backdoor code), but it materially increases supply-chain risk. It can download model artifacts from a configurable mirror without cryptographic integrity verification, and it can enable remote repository code execution via --trust_remote_code passed into the local Python runners. Treat MODEL inputs, HF_ENDPOINT, and TRUST_REMOTE_CODE as high-risk controls; review the referenced Python scripts and ensure trusted, verified model sources (or disable TRUST_REMOTE_CODE by default).

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/ascend-ai-coding%2Fawesome-ascend-skills%2Fnpu-torchair-infer%2F@44a1716ca12f6443dc8cf334a0b4bcd100d4c6435b648f0264456cf526a3db6a
Security Audit — socket — npu-torchair-infer