nre

Warn

Audited by Socket on Sep 4, 2026

7 alerts found:

Anomalyx6Security
AnomalyLOW
references/asset-editing.md

The supplied fragment is documentation for a dynamic asset-rendering and gRPC workflow, not apparent malware. It presents notable security risks if deployed as shown: privileged Docker execution, host networking, broad filesystem mounts, arbitrary server-side PLY path loading, and unauthenticated unencrypted gRPC. These risks concern unsafe deployment and authorization boundaries rather than demonstrated malicious behavior in the fragment.

Confidence: 98%Severity: 68%
AnomalyLOW
references/example-workflows/hydra/tools.yaml

This is infrastructure setup code for NVIDIA GPU, Docker, and Kubernetes tooling. It contains significant supply-chain and operational risks from unverified and mutable remote downloads, curl-piped shell execution, unpinned Go and container artifacts, and possible exposure or injection involving templated values and the NGC API key. The supplied code does not show clear malicious behavior, data theft, persistence, or sabotage. Pin versions, verify checksums/signatures, avoid piping remote scripts to shell, validate template values, and use secure secret handling.

Confidence: 97%Severity: 68%
AnomalyLOW
references/example-workflows/hydra/pai-steps.yaml

The fragment implements a legitimate NVIDIA PAI data-processing workflow. It contains no clear evidence of malware, data theft, backdoors, or unauthorized exfiltration. Supply-chain risk is elevated because it executes an unpinned mutable Git checkout and build dependencies, while configuration interpolation and privileged execution create security risks if inputs or upstream sources are compromised. Pin the repository and Docker image by immutable digests/commits, validate paths and identifiers, quote shell arguments safely, and avoid root where possible.

Confidence: 96%Severity: 57%
AnomalyLOW
references/cookbook.md

The fragment contains operational Docker documentation with no direct evidence of malware or intentional sabotage. It does document potentially risky deployment practices: exposing the gRPC service through host networking, running it privileged, passing a sensitive API key into the container, and relying on the mutable latest image tag. These should be reviewed and hardened, but the code fragment itself does not demonstrate malicious behavior.

Confidence: 98%Severity: 55%
SecurityMEDIUM
references/example-workflows/bash/start_grpc.sh

The script appears to be a legitimate launcher for an NVIDIA rendering service and contains no direct malware logic. Its principal security concern is the highly privileged execution of an unpinned external container image with host networking, GPU access, a host bind mount, and an authentication key. Use a trusted, digest-pinned and verified image, avoid --privileged where possible, restrict the mounted directory, validate RUN_ID, and limit network and credential exposure.

Confidence: 98%Severity: 78%
AnomalyLOW
references/example-workflows/bash/aux.sh

No direct malicious behavior is evident in the script. It is a container launcher for NVIDIA dataset processing. The main security risks are reliance on the mutable :latest image, exposure of NGC_API_KEY to that image, and writable host-directory mounts combined with GPU access. Pinning the image by a trusted digest, minimizing mounts and permissions, and limiting credential exposure would reduce risk.

Confidence: 98%Severity: 58%
AnomalyLOW
references/example-workflows/bash/render.sh

The script is a container launcher for GPU rendering, not demonstrably malware. Its primary security concerns are excessive container privileges, host-network access, read-write host mounts, and execution of an unpinned external latest image. The code itself shows no direct malicious behavior, but the privileges mean a compromised or malicious image could substantially affect the host.

Confidence: 97%Severity: 68%
Audit Metadata
Analyzed At
Sep 4, 2026, 02:25 PM
Package URL
pkg:socket/skills-sh/nvidia%2Fnurec-skills%2Fnre%2F@acb849161d8a85b5355e3cfb4fdeec16711902f30c4df3cf84ad5fd751b05e19
Security Audit — socket — nre