earth2studio-create-diagnostic
Warn
Audited by Socket on Oct 3, 2026
1 alert found:
AnomalyAnomalyevals/targets/eval_3_target.py
LOWAnomalyLOW
evals/targets/eval_3_target.py
No direct malware behavior is evident. The unrestricted PyTorch pickle deserialization is a significant supply-chain risk if the package artifact is not trusted and authenticated; use trusted artifacts or a safer weights-only loading format where possible.
Confidence: 98%Severity: 63%
Audit Metadata