nail-technician

Warn

Audited by Socket on Apr 18, 2026

1 alert found:

Security
SecurityMEDIUM
references/platform-support.md

The snippet is a cross-tool, persistent installer that fetches externally hosted markdown and injects it into global system-prompt/rules and skill directories across multiple coding assistants. While the fragment itself has no explicit malware code, the lack of integrity checks and the persistence into high-impact instruction surfaces makes it a significant supply-chain/prompt-injection risk. Review the referenced SKILL.md contents and the tools’ handling/execution model before use.

Confidence: 60%Severity: 70%
Audit Metadata
Analyzed At
Apr 18, 2026, 01:59 AM
Package URL
pkg:socket/skills-sh/theneoai%2Fawesome-skills%2Fnail-technician%2F@88991558b3f93b652cd09e94e255cc48892ac3e3