flash-moe-inference

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose and capabilities mostly align for a local MoE inference engine, and data flow appears local with no credential harvesting or exfiltration. The main concern is install trust: ara.so publishes the skill, but the code comes from an unrelated personal GitHub repo built into executables without stronger provenance, checksums, or same-org verification.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Mar 21, 2026, 03:02 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fflash-moe-inference%2F@c19e0cd453a6058178d55d6a5b65409b2b2fe325