tao-port-huggingface-model

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/docker-patterns.md

The fragment does not provide clear evidence of malware or data theft. It does contain a potentially dangerous broad filesystem deletion command targeting `.git` directories and `.gitlab-ci.yml` files. This may be intentional Docker image cleanup, but it should be restricted to the build workspace and verified to run only inside an isolated build stage. The telemetry variable alone does not demonstrate tracking or exfiltration.

Confidence: 91%Severity: 62%
Audit Metadata
Analyzed At
Sep 17, 2026, 02:58 AM
Package URL
pkg:socket/skills-sh/nvidia-tao%2Ftao-skill-bank%2Ftao-port-huggingface-model%2F@37e43b151a14971b97650871eaa57ba3258c7c130dd8f187bb9adb8e5a999a5a
Security Audit — socket — tao-port-huggingface-model