run-train

Warn

Audited by Socket on Apr 4, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/write_outputs.py

This fragment is a thin dynamic module loader that executes write_run_bundle.py from a computed relative filesystem location and then calls its main() with training defaults. No direct malicious behavior is evident in the fragment, but the use of spec.loader.exec_module without integrity/allowlist validation creates a meaningful supply-chain/sideloading risk if the target file can be tampered with. Review and verify the contents and provenance of shared/scripts/write_run_bundle.py and ensure build/distribution processes prevent replacement.

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Apr 4, 2026, 11:13 AM
Package URL
pkg:socket/skills-sh/lllllllama%2Fai-paper-reproduction-skills%2Frun-train%2F@a24d2e1ebba7544970e880e890c8bbd255d3d78f