embedding

Warn

Audited by Socket on Sep 20, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
embed.py

No clear malicious or supply-chain attack behavior is present in the supplied module. The code is consistent with an embedding service, but it has meaningful security risks: the API defaults to all-interface binding and exposes unauthenticated shutdown and reload endpoints; arbitrary image URIs are forwarded to a multimodal backend; and service failures can restart environment-selected Docker containers. Restrict network access, authenticate administrative endpoints, validate image URI schemes and destinations, and treat dotenv/configuration and Docker permissions as trusted inputs.

Confidence: 96%Severity: 66%
AnomalyLOW
docker-compose.yml

No direct malicious behavior is evident in the supplied Compose file. The primary security concerns are supply-chain trust in unpinned images/models, execution enabled by --trust-remote-code, exposure of unauthenticated inference ports, and elevated container access through GPU, host IPC, and a host-mounted cache. Pin image and model revisions, avoid trust of remote code where possible, protect the APIs with network controls or authentication, and handle HF_TOKEN via safer secret mechanisms.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Sep 20, 2026, 03:49 AM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fembedding%2F@c145fbe2f9f4c90ab9180ef6574521f536c021f49b2a60fcca215c3a5956c25c
Security Audit — socket — embedding