launch-nemo-rl

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s cluster-management purpose matches most capabilities, and data flows stay largely within official/local endpoints, but the footprint is high-risk because it performs consequential Kubernetes actions and forwards raw local credentials (`~/.ssh/id_rsa`, tokens) into an internal, not publicly verifiable `nrl-k8s` CLI workflow. This looks more like a powerful internal ops playbook than malware, but its credential handling and trust model are disproportionate enough to warrant caution.

Confidence: 84%Severity: 81%
Audit Metadata
Analyzed At
Jul 22, 2026, 07:47 AM
Package URL
pkg:socket/skills-sh/NVIDIA-NeMo%2FRL%2Flaunch-nemo-rl%2F@2f9f700d7193908e43dc45693fc54218d5f3fb97e4089ea74308eefd13bfc90d
Security Audit — socket — launch-nemo-rl