omniverse-cad-to-simready

Warn

Audited by Socket on Sep 1, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities broadly fit its stated Omniverse CAD-to-SimReady orchestration purpose, and the NVIDIA publisher relationship lowers concern. However, trust is diluted by delegated shell execution through nested references, local upstream checkouts, Dockerized services, and forwarding of multiple provider credentials/tokens to auxiliary Content Agents or configured endpoints. This looks like a legitimate but high-trust orchestration skill with medium security risk rather than confirmed malware.

Confidence: 84%Severity: 62%
AnomalyLOW
references/preflight/scripts/preflight.py

No explicit malicious code is evident in this fragment (no eval/exec, no obvious obfuscation, no explicit exfiltration/backdoor). The tool’s main risk is supply-chain/operational: it executes git/uv/pip and docker compose up/build, reads/writes credential-bearing env files, and performs network health/render probes to configured endpoints. If upstream specs or inputs are compromised, this could enable malicious code execution through the installed/deployed components. Confidence is limited because the snippet appears truncated in _dotenv_line_pair (possible code corruption).

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Sep 1, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/nvidia%2Fskills%2Fomniverse-cad-to-simready%2F@bccc47bd303ee339c55b0f15d29b1411763dd87b161c49abc7bed893869d11fe
Security Audit — socket — omniverse-cad-to-simready