lambda-labs-gpu-cloud
Warn
Audited by Socket on Mar 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's overall purpose is coherent, and most network/data flows target official Lambda domains. The main inconsistency is the Python dependency: it forwards a powerful Lambda API key to a PyPI client that does not appear verifiably official to Lambda, despite the skill otherwise relying on first-party docs and direct API examples. That makes this a medium-risk supply-chain and credential-forwarding concern rather than confirmed malware.
Confidence: 87%Severity: 63%
Audit Metadata