nix-best-practices
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGHEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS] (MEDIUM): The skill references several external GitHub repositories not included in the trusted list, such as
NixOS/nixpkgs,numtide/nixpkgs-unfree,0xBigBoss/atlas-overlay, and0xBigBoss/bun-overlay.\n- [REMOTE_CODE_EXECUTION] (HIGH): The 'Creating Binary Overlay Repos' section provides a template for downloading binaries from remote URLs viapkgs.fetchurland subsequently granting execution permissions withchmod +x. This pattern facilitates the execution of untrusted remote code when the resulting package is used.
Recommendations
- AI detected serious security threats
Audit Metadata