Nia

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly consistent with its stated purpose as a hosted indexing/search platform, but it concentrates many sensitive data flows and credentials into one external service, uses an unpinned `npx` installer, and enables wide ingestion of local and SaaS content. This looks more like a high-trust enterprise data connector than malware, but its scope and third-party data routing make it medium-to-high risk.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
Mar 30, 2026, 06:59 PM
Package URL
pkg:socket/skills-sh/nozomio-labs%2Fnia-skill%2Fnia%2F@b253a81f257d219f9842d864f9991be287bfc66f