NYC
skills/smithery/ai/nix-best-practices/Gen Agent Trust Hub

nix-best-practices

Fail

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (MEDIUM): The skill references several external GitHub repositories not included in the trusted list, such as NixOS/nixpkgs, numtide/nixpkgs-unfree, 0xBigBoss/atlas-overlay, and 0xBigBoss/bun-overlay.\n- [REMOTE_CODE_EXECUTION] (HIGH): The 'Creating Binary Overlay Repos' section provides a template for downloading binaries from remote URLs via pkgs.fetchurl and subsequently granting execution permissions with chmod +x. This pattern facilitates the execution of untrusted remote code when the resulting package is used.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 08:29 AM