nemoclaw-get-started

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose broadly matches its capabilities, but it relies on unpinned remote script execution for install/uninstall and explicitly disables device authentication during onboarding. Those choices create meaningful security risk even without clear evidence of credential theft or malicious data exfiltration.

Confidence: 74%Severity: 61%
Audit Metadata
Analyzed At
Apr 7, 2026, 04:33 AM
Package URL
pkg:socket/skills-sh/NVIDIA%2FNemoClaw%2Fnemoclaw-get-started%2F@52cef34804b756353717d5b592e73a91b754c857
Security Audit — socket — nemoclaw-get-started