evaluation

Warn

Audited by Socket on Jul 6, 2026

1 alert found:

Anomaly
AnomalyLOW
recipes/examples/example_eval_next.yaml

No explicit backdoor, reverse shell, or hardcoded exfiltration endpoint is present in the provided YAML fragment (it is a configuration template). However, it does include a major supply-chain execution risk: the vLLM server is started with --trust-remote-code, meaning remote model repository/artifacts can lead to code execution during model loading. Additionally, the evaluation runtime receives HF and AWS credentials, increasing impact if the eval image, model artifacts, or any execution path is compromised. Overall: elevated supply-chain security risk due to trust boundary expansion (remote model code execution) and broad credential injection; malware intent is not directly evidenced by this fragment alone.

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Jul 6, 2026, 01:47 PM
Package URL
pkg:socket/skills-sh/NVIDIA%2FModel-Optimizer%2Fevaluation%2F@3b0dab604a656154b4b388e999846565c95ced92a7baf5f3b2de00f356fdc777
Security Audit — socket — evaluation