onnx-webgpu-converter

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/preflight_check.py

This script is not overtly malicious but contains a critical code-injection vulnerability: it embeds user-controlled model identifiers into a Python -c payload and executes them, enabling arbitrary code execution if an attacker can control the model_id input. There are also quality bugs (malformed inlined -c payload and an undefined detect_task), which increase unpredictability. Treat inputs as untrusted, avoid the -c pattern, or sanitize strictly; do not run this script on untrusted model identifiers or in privileged CI without fixes.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:11 AM
Package URL
pkg:socket/skills-sh/jakerains%2Fagentskills%2Fonnx-webgpu-converter%2F@3984a0f00d716c3dfae113716156866d32fc36b3