model-verify
Warn
Audited by Socket on Mar 25, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned for model verification, but it materially increases risk by downloading user-selected model repositories and executing their remote code inside the container with broad Bash capability. No clear credential harvesting or covert exfiltration is present, so this is not confirmed malware, but it is a meaningful supply-chain and execution-risk skill.
Confidence: 87%Severity: 74%
Audit Metadata