huashu-nuwa

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior mostly matches the stated purpose of generating persona/framework skills, but the skill has a broad footprint: extensive ingestion of untrusted external content, autonomous multi-agent file-writing, and recommendations to use unstable third-party/shadow-library sources. `yt-dlp` itself appears legitimate and same-project verifiable, so this is not confirmed malware, but the overall workflow poses meaningful supply-chain and prompt-injection risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 5, 2026, 11:29 AM
Package URL
pkg:socket/skills-sh/alchaincyf%2Fnuwa-skill%2Fhuashu-nuwa%2F@e2d4a7d9cda8f209a6b4844783e11ea7871147f6