catc-inventory

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent with the inventory/query capabilities and official Cisco API usage, but the skill’s real trust boundary is the local MCP wrapper chain. It passes Catalyst Center credentials to unverifiable local scripts and optionally forwards inventory summaries to GAIT, creating disproportionate credential and data-flow risk despite otherwise benign network-management intent.

Confidence: 86%Severity: 81%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:13 AM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fcatc-inventory%2F@0439ceca505a468800467dd6fa2eac4a5f94767e