ad-model-onboard

Warn

Audited by Socket on May 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core actions mostly match its stated NVIDIA model-onboarding purpose and use official Hugging Face/GitHub endpoints, so it is not malware. However, it grants the agent a broad footprint: fetching untrusted external content, generating code, executing builds/tests on GPU, and autonomously posting/polling on GitHub. The main concern is high operational risk from indirect prompt injection and autonomous public actions, not deceptive credential theft.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 18, 2026, 06:18 AM
Package URL
pkg:socket/skills-sh/nvidia%2Fskills%2Fad-model-onboard%2F@3ed555de1bfbcdfa24f42b1716e8e1ce437ffddc
Security Audit — socket — ad-model-onboard