gpu-container-setup

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior matches a GPU container setup skill, but its trust boundary is too loose: it can discover images via web search, execute pulled containers with broad device access, and persist discovered sources into its own references. No direct credential harvesting or clear exfiltration is present, so this is not confirmed malware, but it carries meaningful supply-chain and execution risk.

Confidence: 85%Severity: 66%
Audit Metadata
Analyzed At
Mar 25, 2026, 07:08 AM
Package URL
pkg:socket/skills-sh/flagos-ai%2Fskills%2Fgpu-container-setup%2F@9af801d315b6b3f1bef9c83368cc09db8a3bc58f