ad-model-onboard
Warn
Audited by Socket on May 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's core actions mostly match its stated NVIDIA model-onboarding purpose and use official Hugging Face/GitHub endpoints, so it is not malware. However, it grants the agent a broad footprint: fetching untrusted external content, generating code, executing builds/tests on GPU, and autonomously posting/polling on GitHub. The main concern is high operational risk from indirect prompt injection and autonomous public actions, not deceptive credential theft.
Confidence: 87%Severity: 72%
Audit Metadata