dgx-spark-user-guide

Warn

Audited by Socket on Jul 10, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/pxe-provisioning.md

No direct, explicit malware is present in the provided fragment. However, it has substantial supply-chain security risk typical of PXE/mirror/provisioning pipelines: it downloads and executes scripts/binaries from public URLs without visible integrity pinning, serves boot and update artifacts over plain HTTP, and executes an OEMDATA USB hook script. Additionally, it relaxes fwupd trust (OnlyTrusted=false), which increases the impact of any compromise of the mirror contents or network path. This should be reviewed/locked down with signature/hash verification, TLS or network isolation, and strict trust policies.

Confidence: 70%Severity: 75%
Audit Metadata
Analyzed At
Jul 10, 2026, 05:22 AM
Package URL
pkg:socket/skills-sh/Fandhe-AI%2Fagent-reference-skills%2Fdgx-spark-user-guide%2F@165fba2009b292da3bea93fb6f882d8c419c0a0f7329f819a1d7f99a54f28918
Security Audit — socket — dgx-spark-user-guide