deploying-machine-learning-models
Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches ML deployment, but the skill is overly generic and grants wildcard shell access for high-impact infrastructure actions without bounded procedures, approval checks, or explicit data-flow constraints. No direct malware or credential-stealing behavior is shown, but the permission scope is broader than the minimal instruction content and creates meaningful operational risk.
Confidence: 80%Severity: 63%
Audit Metadata