building-neural-networks
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is plausible, but the skill’s core functionality depends on an unverifiable external `build-nn` plugin/CLI and grants unnecessary wildcard shell access. Provenance is inconsistent across marketplace evidence, and transitive installation via a third-party installer adds trust-chain risk. No direct credential theft or explicit exfiltration is shown, so this is high-risk/vulnerable rather than confirmed malware.
Confidence: 88%Severity: 82%
Audit Metadata