novita-sandbox
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly coherent with its stated Novita sandbox-management purpose and uses mostly official Novita/npm/GitHub paths, so there is no strong evidence of malware. However, it combines transitive skill installation, mutable remote downloads, global CLI upgrades from a beta tag, Node bootstrap via curl|bash, and credential forwarding into remote sandboxes, which makes the overall security footprint medium risk.
Confidence: 88%Severity: 58%
Audit Metadata