profiling-qwen3-tts

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated profiling purpose is coherent, and the commands largely match that purpose, but the core execution path relies on an unofficial, mutable CUDA Docker image with GPU access and no strong provenance in the official QwenLM distribution docs. That makes this a supply-chain risk rather than confirmed malware.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Mar 21, 2026, 07:18 PM
Package URL
pkg:socket/skills-sh/trevors%2Fdot-claude%2Fprofiling-qwen3-tts%2F@87695446d836a16e8ca9ce275181fb4e0fc8f3b8