perf-test-flagos

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/run_benchmark.py

The code is a readable benchmark wrapper with no direct evidence of malware or intentional data theft. Its main security risk is the unconditional use of vllm's --trust-remote-code option, which can execute arbitrary code from a selected remote model or tokenizer repository. The caller-controlled extra arguments are passed without shell execution, reducing command-injection risk in this module. Use only trusted model repositories and disable remote-code trust where possible.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 08:44 AM
Package URL
pkg:socket/skills-sh/flagos-ai%2Fskills%2Fperf-test-flagos%2F@079ab08fa87a4f200b68808e93a3b5ed0a4f5525ab8ace754abfa8fc4e7f5aff
Security Audit — socket — perf-test-flagos