catc-inventory
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is coherent with the inventory/query capabilities and official Cisco API usage, but the skill’s real trust boundary is the local MCP wrapper chain. It passes Catalyst Center credentials to unverifiable local scripts and optionally forwards inventory summaries to GAIT, creating disproportionate credential and data-flow risk despite otherwise benign network-management intent.
Confidence: 86%Severity: 81%
Audit Metadata