lambda-labs-gpu-cloud

Warn

Audited by Socket on Sep 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/advanced-usage.md

No clear evidence of intentional malware (e.g., backdoor/persistence/reverse shell/targeted credential theft) is visible in the fragment. However, the code and workflows contain several high-impact security hazards: remote command execution over SSH (including git pull and pip install), relaxed SSH host key verification via AutoAddPolicy, unsafe deserialization via torch.load of shared checkpoints without demonstrated integrity checks, and potential injection risk from variable interpolation in shell commands. These issues primarily elevate supply-chain and integrity risk; if repo/dependency sources, checkpoints, or SSH trust are compromised or attacker-influenced, the automation could facilitate compromise.

Confidence: 55%Severity: 62%
Audit Metadata
Analyzed At
Sep 9, 2026, 07:07 PM
Package URL
pkg:socket/skills-sh/qcmuu%2Fai-research-skills%2Flambda-labs-gpu-cloud%2F@bfdc754a71e41236c01e670a9c7c8c4ffddc78dfbc3800a6d28ee012a3a3bf11
Security Audit — socket — lambda-labs-gpu-cloud