kernelgen-flagos

Warn

Audited by Socket on Sep 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
kernelgen-optimize-for-vllm.md

The fragment describes a legitimate but high-impact kernel optimization automation workflow. It is not overtly malicious and contains no visible credential theft, data exfiltration, persistence, destructive behavior, or obfuscation. It does create meaningful supply-chain and operational risk because it installs packages, executes local and MCP-generated code with GPU/environment access, and writes generated implementations into a vLLM repository. Use only with trusted MCP infrastructure, pinned and verified dependencies, validated paths, repository backups, and review of all generated diffs.

Confidence: 91%Severity: 62%
AnomalyLOW
kernelgen-optimize-for-flaggems.md

The fragment describes legitimate kernel optimization and integration automation, not malware. It can execute commands and modify repository code, and it presents moderate security risk when inputs or the MCP service are untrusted due to unquoted shell interpolation and direct acceptance of generated code. Use strict input validation, safe subprocess argument arrays, repository isolation, and mandatory code review before execution.

Confidence: 96%Severity: 58%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:36 PM
Package URL
pkg:socket/skills-sh/flagos-ai%2Fskills%2Fkernelgen-flagos%2F@a3b34ac7fc3c3d2f742f8896fe68ff40c3cd5cfad4f19f05c765a84d52f2a23a
Security Audit — socket — kernelgen-flagos