nebius-finetune

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (fine-tuning models on Nebius Token Factory) is coherent with its described capabilities and data flows. It uses standard, verifiable API interactions and common tooling (OpenAI-compatible client, Python). Data flows are limited to uploading training data to Nebius and downloading checkpoints locally, which aligns with the workflow. The primary security considerations are the handling of the API key (environment variable exposure) and ensuring dataset privacy during upload/download. No suspicious download-execute patterns, unverifiable binaries, or credential-forwarding to third-party tools are detected. Overall, the risk is present due to credential handling and data transfer, but the footprint is proportionate to the stated purpose. Recommendation: treat as BENIGN with mindful handling of API keys and dataset privacy.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 02:03 AM
Package URL
pkg:socket/skills-sh/Arindam200%2Fnebius-skills%2Fnebius-finetune%2F@0c95dab60321bc8a8d4393dbea1e96a69e21deaf