model-serving

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] BENIGN: The code fragment is a coherent deployment guide for Databricks Model Serving. It contains no executable logic, no credential leakage, and no anomalous data flows. It is appropriate for its stated purpose as documentation and quick-start instructions. LLM verification: The provided document is legitimate operational documentation for deploying and querying Databricks Model Serving endpoints. It contains no explicit malicious code or obfuscation. The dominant security concern is operational: the workflow directs installation of third-party packages and uploading/execution of arbitrary user code on Databricks clusters — actions that are necessary for the described functionality but create a supply-chain and runtime risk (possible credential access and data exfil

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 04:20 PM
Package URL
pkg:socket/skills-sh/databricks-solutions%2Fai-dev-kit%2Fmodel-serving%2F@caad9e7a65591e787d4b3509f355b568417c8988