aris-run-experiment
Warn
Audited by Socket on May 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s core behavior matches its stated purpose of experiment deployment, and the main third-party tools (Vast.ai CLI and Modal) are official. However, its footprint is high-risk for an agent skill: wildcard shell access, remote execution, file transfer, optional credential forwarding to W&B over SSH, transitive installation/delegation to other skills, and autonomous cost-incurring actions like renting and destroying Vast.ai instances. This looks coherent but overpowered, so it is not malware, yet it should be treated as a high-risk operational skill.
Confidence: 87%Severity: 76%
Audit Metadata