nixomatic

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose and behavior are broadly aligned, and it includes a reasonable instruction not to read secret files, but it asks the agent to trust and execute remote flake definitions from a non-open-source third-party service using --accept-flake-config. That remote execution trust is disproportionate enough to make the skill medium/high risk even without clear malicious intent.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 23, 2026, 03:39 PM
Package URL
pkg:socket/skills-sh/curriedsoftware%2Fnixomatic-skill%2Fnixomatic%2F@84878815f1f3074ad07242417722248b6a32ea39