lambda-labs-gpu-cloud

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's overall purpose is coherent, and most network/data flows target official Lambda domains. The main inconsistency is the Python dependency: it forwards a powerful Lambda API key to a PyPI client that does not appear verifiably official to Lambda, despite the skill otherwise relying on first-party docs and direct API examples. That makes this a medium-risk supply-chain and credential-forwarding concern rather than confirmed malware.

Confidence: 87%Severity: 63%
Audit Metadata
Analyzed At
Mar 28, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/firecrawl%2FAI-research-SKILLs%2Flambda-labs-gpu-cloud%2F@ce78b9c6e9a6a5e9931b1d66181eeb3d65a1090c