ml-ops-engineer

Warn

Audited by Socket on Oct 2, 2026

1 alert found:

Anomaly
AnomalyLOW
REFERENCE.md

No direct malware or deliberate data theft is evident in the supplied code. The principal risks are software and model supply-chain integrity: mutable container images, unpinned CI actions, execution of repository-controlled scripts, unverified MLflow/XGBoost artifacts, and automatic production deployment. Pin images and actions by immutable digest or commit, verify signed artifacts, restrict model-loading formats and registry permissions, validate paths and parameters, and add explicit promotion approvals and rollback controls.

Confidence: 94%Severity: 68%
Audit Metadata
Analyzed At
Oct 2, 2026, 05:16 PM
Package URL
pkg:socket/skills-sh/borghei%2Fclaude-skills%2Fml-ops-engineer%2F@79c2c3496e40eb6e561706900e32dc458c5200e96a1637292679320ca5fa3b53
Security Audit — socket — ml-ops-engineer