nel-assistant

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
evals/nemotron3-nano-bf16-reasoning.json

The analyzed fragment exposes notable supply-chain and runtime risks due to remote code loading and plugin-based execution triggered by model-card-driven configurations. Without robust integrity checks, authentication controls, and strict validation, an attacker could tamper with downloaded scripts or influence runtime behavior. Recommend disabling or sandboxing remote code execution, enforcing signed/verified assets, validating all inputs before use, and masking tokens in logs. Ensure auditability of model-card sources and restrict plugin execution to trusted, internal registries.

Confidence: 61%Severity: 67%
Audit Metadata
Analyzed At
May 18, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/nvidia%2Fskills%2Fnel-assistant%2F@54f621ac07f3145d699dc1fa66dd271f8aa763c4
Security Audit — socket — nel-assistant