OverviewHistoryStatsSecurity
Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Warn5 providerslatest audit Apr 30, 2026
Independent checks from skills.sh's audit partners.
The skill provides comprehensive templates for MLOps and ML pipelines. It includes several instances of unsafe deserialization using 'pickle', 'joblib', and 'torch.load' for model artifacts and checkpoints. While standard in ML workflows, these methods can execute arbitrary code if loading from an untrusted source.
Detected behaviors
No alerts
No issues
6/6 files flagged
Score: 93/100 · 2 sections analyzed