experiment-bridge
Warn
Audited by Socket on Apr 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly fit an experiment orchestration purpose, but its footprint is large: wildcard bash, autonomous GPU actions, unpinned arbitrary repo cloning, and outbound code review to an external model service. The main issue is high operational and supply-chain risk rather than confirmed malicious intent.
Confidence: 87%Severity: 76%
Audit Metadata