remote-npu-test
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core behavior matches its stated purpose, but it authorizes high-impact remote actions: SSH with host-key checks disabled, privileged Docker on a remote server, broad host mounts, unpinned image/package selection, and shell interpolation of user inputs. This is not confirmed malware or credential harvesting, but it is a medium-high risk remote-operation skill that should only run in a trusted environment with tighter quoting, pinning, and SSH verification.
Confidence: 88%Severity: 68%
Audit Metadata