nmt-upgrade
Warn
Audited by Socket on Aug 15, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s behavior mostly matches its stated purpose as an updater, but it relies on high-trust remote execution (curl|bash / iex), clones mutable main without pinning or release verification, and adds a non-essential telemetry ping. This looks more like risky installer/update design than confirmed malware, but the supply-chain and transitive-instruction update surface are significant.
Confidence: 90%Severity: 62%
Audit Metadata