aris-run-experiment

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior matches its stated purpose of experiment deployment, and the main third-party tools (Vast.ai CLI and Modal) are official. However, its footprint is high-risk for an agent skill: wildcard shell access, remote execution, file transfer, optional credential forwarding to W&B over SSH, transitive installation/delegation to other skills, and autonomous cost-incurring actions like renting and destroying Vast.ai instances. This looks coherent but overpowered, so it is not malware, yet it should be treated as a high-risk operational skill.

Confidence: 87%Severity: 76%
Audit Metadata
Analyzed At
May 6, 2026, 01:45 AM
Package URL
pkg:socket/skills-sh/OpenLAIR%2Fdr-claw%2Faris-run-experiment%2F@fe5026bc32229f4658852eceedfb3f79fd4e92cc
Security Audit — socket — aris-run-experiment