nano-world-model
Warn
Audited by Socket on May 5, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities fit its ML research purpose and there is no clear credential theft or exfiltration, but install trust is weakened by an unverified Dropbox-hosted TorchScript download and generally unpinned remote artifacts. Overall this looks like a legitimate research skill with medium supply-chain risk rather than malware.
Confidence: 88%Severity: 62%
Audit Metadata