NYC

mlflow

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This is documentation/examples for MLflow with expected dependencies and behaviors. I found no evidence of hidden malicious code or supply-chain injection inside the provided text. The main security concerns are operational: users may inadvertently send sensitive experiment data or artifacts to untrusted tracking URIs or artifact stores, and loading model artifacts from untrusted sources can lead to remote code execution because model formats may contain executable Python code. Recommend: verify tracking URIs and artifact stores before use, avoid embedding real credentials in example commands, restrict cloud credentials to least privilege, and treat downloaded model artifacts as untrusted until validated.

Confidence: 80%Severity: 55%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:49 PM
Package URL
pkg:socket/skills-sh/ovachiever%2Fdroid-tings%2Fmlflow%2F@e9fe6ebbc37e280265b7501dd1b0113ee90ba5ef