run-train

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/write_outputs.py

This fragment is a thin dynamic module loader that executes write_run_bundle.py from a computed relative filesystem location and then calls its main() with training defaults. No direct malicious behavior is evident in the fragment, but the use of spec.loader.exec_module without integrity/allowlist validation creates a meaningful supply-chain/sideloading risk if the target file can be tampered with. Review and verify the contents and provenance of shared/scripts/write_run_bundle.py and ensure build/distribution processes prevent replacement.

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
May 10, 2026, 12:37 PM
Package URL
pkg:socket/skills-sh/lllllllama%2Fai-paper-reproduction-skill%2Frun-train%2F@4f490081a1cadf33fbdca2f8398d6e085351b1cf