launch-nemo-rl
Warn
Audited by Socket on Jul 22, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s cluster-management purpose matches most capabilities, and data flows stay largely within official/local endpoints, but the footprint is high-risk because it performs consequential Kubernetes actions and forwards raw local credentials (`~/.ssh/id_rsa`, tokens) into an internal, not publicly verifiable `nrl-k8s` CLI workflow. This looks more like a powerful internal ops playbook than malware, but its credential handling and trust model are disproportionate enough to warrant caution.
Confidence: 84%Severity: 81%
Audit Metadata