build-nitro-modules

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent as a React Native/Nitro build guide, but its main install path is not internally consistent with the apparent official Nitro package name. Because it instructs remote execution of an apparently unrelated npm package with `@latest`, the install trust risk is medium-high even though there is no evidence of credential theft or exfiltration.

Confidence: 89%Severity: 72%
Audit Metadata
Analyzed At
Mar 14, 2026, 04:52 PM
Package URL
pkg:socket/skills-sh/riteshshukla04%2Fagent-skills%2Fbuild-nitro-modules%2F@30efcadb1955dbd1a10994f732539a587bb198ff