model-serving-security

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
examples/insecure-serving.json

No direct evidence of embedded malware in this configuration fragment. The primary finding is severe security misconfiguration: a public unauthenticated inference endpoint served over plain HTTP combined with a privileged, root-running container, both of which materially increase the likelihood and impact of compromise or abuse. Additionally, using model version 'latest' adds version/supply-chain drift risk. This should be reviewed and hardened (auth required, HTTPS, network restrictions, and least-privilege container settings; pin model versions).

Confidence: 70%Severity: 86%
Audit Metadata
Analyzed At
Apr 20, 2026, 01:19 AM
Package URL
pkg:socket/skills-sh/msaad00%2Fcloud-ai-security-skills%2Fmodel-serving-security%2F@5238cb7d303cb54706cb5b06870af7aa4007f2b5
Security Audit — socket — model-serving-security