nemoclaw-setup

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated NemoClaw setup purpose, and the main installers appear to be official NVIDIA paths rather than an unrelated third party. However, it uses multiple remote-script installers, performs privileged host reconfiguration, exposes/prints gateway tokens, and optionally publishes the service through Cloudflare Tunnel. This is coherent but high-impact infrastructure setup, so the overall risk is medium rather than benign.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 11:13 AM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Fnemoclaw-setup%2F@b2c2928c151352a771c23f4e9d885fe9f73129ca