ovphysx-host-runtime-boundary

Warn

Audited by Socket on Jul 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's host-Blender execution model fits its stated OVPhysX purpose, and there is no explicit credential harvesting or off-host exfiltration. However, its core function depends on executing an unverifiable local helper script from a user-home path and on companion-skill trust not included in the evidence, so the install/execution trust is too weak to rate benign.

Confidence: 80%Severity: 72%
Audit Metadata
Analyzed At
Jul 22, 2026, 03:09 PM
Package URL
pkg:socket/skills-sh/NVIDIA%2Fnemoclaw-community%2Fovphysx-host-runtime-boundary%2F@e5d7011d8e99d7ca8d59624e748cdcc5c230c779b0d8e891b9eb46b66dba52d1
Security Audit — socket — ovphysx-host-runtime-boundary