nel-assistant
Warn
Audited by Socket on May 18, 2026
1 alert found:
AnomalyAnomalyevals/nemotron3-nano-bf16-reasoning.json
LOWAnomalyLOW
evals/nemotron3-nano-bf16-reasoning.json
The analyzed fragment exposes notable supply-chain and runtime risks due to remote code loading and plugin-based execution triggered by model-card-driven configurations. Without robust integrity checks, authentication controls, and strict validation, an attacker could tamper with downloaded scripts or influence runtime behavior. Recommend disabling or sandboxing remote code execution, enforcing signed/verified assets, validating all inputs before use, and masking tokens in logs. Ensure auditability of model-card sources and restrict plugin execution to trusted, internal registries.
Confidence: 61%Severity: 67%
Audit Metadata