tao-run-deft-aoi-cosmos3

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/submit_cfw_train.py

The fragment is a legitimate-looking Docker-based training submission launcher, not apparent malware. Its main risks are the intentionally powerful Docker execution and permissive bind-mount handling: annotation-controlled absolute paths and arbitrary extra mounts can expose host data to the container, and writable mounts can affect host files accessible to the invoking user. Review the external resolver, validation module, Docker image, and caller trust model before use.

Confidence: 96%Severity: 58%
AnomalyLOW
scripts/deft_exec.py

No direct malware, credential theft, exfiltration, persistence, destructive behavior, or obfuscation is evident. The code is a policy wrapper around arbitrary subprocess execution and is security-sensitive by design. Its air-gap enforcement is heuristic and bypassable if untrusted input can select commands, invoke unrecognized interpreters or wrappers, or modify the state file. It should not be treated as a standalone security boundary.

Confidence: 97%Severity: 64%
Audit Metadata
Analyzed At
Sep 17, 2026, 02:59 AM
Package URL
pkg:socket/skills-sh/nvidia-tao%2Ftao-skill-bank%2Ftao-run-deft-aoi-cosmos3%2F@7a25de0a9a6e1197f5c88a0cfc6b0da5d4789f9ddd73c8e5ee5314a31bd4be56
Security Audit — socket — tao-run-deft-aoi-cosmos3