compute-env-setup

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
references/envs_reference.md

No explicit malicious behavior (e.g., backdoor/persistence, reverse shells, credential theft, or direct exfiltration code) is evident in the provided fragment. The primary concerns are supply-chain and integrity risks: broad network and git fetch surface, multiple no_deps/manual conflict strategies, checkpoint deserialization and torch/hub artifact loading, and high-impact native .so/CUDA ops loading via custom LD_LIBRARY_PATH/RPATH. The fragment also highlights failure/marker scenarios where unintended fallback artifacts could be loaded. Treat this as high supply-chain exposure requiring strict artifact verification (hash/signing), locked dependency resolution with checksums, controlled egress, and reliable marker/cache validation.

Confidence: 55%Severity: 62%
Audit Metadata
Analyzed At
Aug 1, 2026, 05:34 AM
Package URL
pkg:socket/skills-sh/HughYau%2FAcademicForge%2Fcompute-env-setup%2F@1d94c722d68d0322f73e4cc041c0547a2b52d3c2b21b78eba3bbf26cf8b230ab
Security Audit — socket — compute-env-setup