cuda-kernels

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/huggingface-kernels-integration.md

No explicit malware or malicious payload is present in the supplied documentation. The primary security concern is the intentional dynamic loading and execution of unreviewed native CUDA binaries, especially when repository references are mutable or LOCAL_KERNELS bypasses trust and version checks. Use trusted repositories, immutable revisions or verified lockfiles, and review native artifacts before deployment.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 05:29 PM
Package URL
pkg:socket/skills-sh/huggingface%2Fkernels%2Fcuda-kernels%2F@8d18659805277ab1311ad2b053f65d4436275574a2d8f085964ea66649bb7f6c
Security Audit — socket — cuda-kernels