lambda-labs

Warn

Audited by Socket on Aug 22, 2026

1 alert found:

Anomaly
AnomalyLOW
references/advanced-usage.md

No clear evidence of intentional malware (e.g., backdoor/persistence/reverse shell/targeted credential theft) is visible in the fragment. However, the code and workflows contain several high-impact security hazards: remote command execution over SSH (including git pull and pip install), relaxed SSH host key verification via AutoAddPolicy, unsafe deserialization via torch.load of shared checkpoints without demonstrated integrity checks, and potential injection risk from variable interpolation in shell commands. These issues primarily elevate supply-chain and integrity risk; if repo/dependency sources, checkpoints, or SSH trust are compromised or attacker-influenced, the automation could facilitate compromise.

Confidence: 55%Severity: 62%
Audit Metadata
Analyzed At
Aug 22, 2026, 03:32 AM
Package URL
pkg:socket/skills-sh/nousresearch%2Fhermes-agent%2Flambda-labs%2F@0f4198541bb80b9844561d206f067146191ef5a18fd1710743056df2f231a99b
Security Audit — socket — lambda-labs