remote-compute-modal

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Anomaly
AnomalyLOW
envs/proteomics_rfd_diffdock_gpu.py

No clear direct malware behavior (e.g., backdoor/exfiltration/reverse shell) is evident in the shown fragment. However, the module performs high-impact supply-chain actions typical of ML build pipelines: it installs many third-party packages from external wheel indexes, fetches and installs code from remotely fetched Git repositories (even though commits are pinned by SHA), and downloads checkpoint artifacts into a persistent volume using only a zip-format check rather than cryptographic hash/signature verification. Combined with a likely incomplete egress allowlist, this warrants security review and stronger integrity controls (hash-pinning/attestations for wheels and weights, and verification for fetched repos).

Confidence: 52%Severity: 55%
Audit Metadata
Analyzed At
Aug 1, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/HughYau%2FAcademicForge%2Fremote-compute-modal%2F@01f2120fe1ac94bcdd8f449f7fc823e1aa1edb132f1e8905f6ea8ab451e4d0b4
Security Audit — socket — remote-compute-modal