embedding-ft

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/job-contract.md

The workflow presents a pragmatic, low-retry design emphasizing determinism and safety but introduces a notable dynamic invocation risk through contentFunction supplied by the payload. Without strict whitelisting and sandboxing of contentFunction, there is a medium-to-high risk of code execution or unintended side effects. Atomicity concerns and shutdown-race handling also warrant explicit transactional boundaries and better visibility. Overall, the design is not malicious but requires stronger input validation, function governance, and robust observability to mitigate data integrity and security risks.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:36 AM
Package URL
pkg:socket/skills-sh/tiangong-lca%2Fskills%2Fembedding-ft%2F@fe68486477b3ae4a3f119cb5fa2d999762c4162b