classifier-lab
Audited by Socket on Aug 26, 2026
4 alerts found:
Obfuscated Filex2Anomalyx2The snippet is best characterized as a benign, configuration-like payload describing a classifier benchmark with a questionable timestamp and incomplete JSON structure (possible partial excerpt). No malware indicators are evident; primary concerns are data-path exposure and parsing integrity rather than exploitable code behavior. Recommend validating the full JSON, ensuring proper timestamp handling, and securing access to internal paths in production pipelines.
The Python code itself contains no overtly malicious constructs (no dynamic code eval, no hard-coded credentials, no direct network connections). However it delegates actions to a local helper script (run.sh) and passes user-controlled arguments to it; this is the primary supply-chain/trust risk. Minimal path validation and unbounded log accumulation increase the attack and resource-risk surface. Recommend auditing the bundled run.sh and any shipped binaries, adding stricter path whitelisting/schema validation, limiting in-memory log size, and adding timeouts or resource controls for long-running subprocesses before trusting this package in sensitive environments.
The code appears to be a legitimate benchmarking orchestrator for vision backbones, with telemetry and taxonomy tagging via external scripts. The primary security concerns are external script trust and shell command construction without explicit escaping. No explicit malware indicators (no hidden network calls, backdoors, or credential theft) are evident in this fragment, but external dependencies should be audited and inputs sanitized to prevent command injection or data leakage. Recommend validating and sandboxing taxonomy/memory tooling, constraining filesystem permissions for artifacts, and ensuring strict input validation for any text embedded into shell commands.
SUSPICIOUS. The core capability matches the stated purpose, and the only named credential is proportionate. Risk comes mainly from incomplete install/provenance details for the local runner, optional outbound logging/persistence, and reliance on mixed-trust model sources including a personal Hugging Face publisher. This looks like a plausible ML training skill with medium supply-chain and data-flow uncertainty, not confirmed malware.