earth2studio-create-prognostic

Warn

Audited by Socket on Oct 3, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
evals/targets/eval_2_target.py

No direct malware behavior is evident. The principal risk is unrestricted pickle deserialization of model.pt; only load artifacts from trusted sources. The remaining code performs coordinate handling and a fixed tensor increment.

Confidence: 98%Severity: 57%
AnomalyLOW
references/skeleton-template.py

The primary supply-chain security risk in this module is unsafe model artifact deserialization: it loads an externally resolved model.pt using torch.load(..., weights_only=False), which can execute attacker-controlled code if the artifact is malicious or tampered with. Aside from that, the shown code focuses on coordinate validation and iterator scaffolding and contains no clear evidence of data exfiltration, credential theft, shell execution, or other overt malware behavior in the fragment provided (though inference/hook logic is not shown).

Confidence: 66%Severity: 62%
AnomalyLOW
references/method-templates.py

This module is largely framework/runtime orchestration for coordinate handling and iterative model inference. It contains a significant supply-chain security concern: `load_model_template` deserializes a resolved `model.pt` with `torch.load(..., weights_only=False)`, which can enable code execution if the checkpoint artifact is untrusted or tampered with. Other observed issues are non-malicious but relevant: an abrupt/truncated `to_template` implementation and an unbounded infinite generator loop that could cause resource exhaustion. No direct evidence of exfiltration or backdoor behavior is present in the shown fragment.

Confidence: 62%Severity: 58%
Audit Metadata
Analyzed At
Oct 3, 2026, 05:29 PM
Package URL
pkg:socket/skills-sh/nvidia%2Fearth2studio%2Fearth2studio-create-prognostic%2F@c1b2ac0ef05833404a6d0ecd35182c25789c16ddaaf97a1628d40ea3ad207aec
Security Audit — socket — earth2studio-create-prognostic