nano-world-model

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities fit its ML research purpose and there is no clear credential theft or exfiltration, but install trust is weakened by an unverified Dropbox-hosted TorchScript download and generally unpinned remote artifacts. Overall this looks like a legitimate research skill with medium supply-chain risk rather than malware.

Confidence: 88%Severity: 62%
Audit Metadata
Analyzed At
May 5, 2026, 05:59 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fnano-world-model%2F@3af371c226d35f93c37d86f198ac78de8b60b6e6