nvm-mirror-and-auth

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but its core function is to redirect Node binary downloads and optionally send bearer tokens to whatever mirror the user configures. That is acceptable in corporate environments, yet the example uses a non-official mirror and the data flow explicitly forwards credentials to the mirror operator. No clear malware behavior or hidden exfiltration is present, but supply-chain and credential-forwarding risk are medium.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
Apr 6, 2026, 10:48 AM
Package URL
pkg:socket/skills-sh/teachingai%2Ffull-stack-skills%2Fnvm-mirror-and-auth%2F@170bc13e961f9a4894bf164d39cd61205426badd