nso-service-mgmt

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill requires sensitive credentials (NSO_PASSWORD, NSO_USERNAME) to be provided via environment variables, which is a standard and safe practice for network automation.
  • [SAFE]: The pip-installed dependency cisco-nso-mcp-server is a vendor-appropriate tool for the skill's stated purpose of Cisco NSO management.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes service and device configuration data from NSO. 1. Ingestion points: get_service_types and get_services tools. 2. Boundary markers: None identified. 3. Capability inventory: Integration with github-ops for repository writes and messaging services for reporting. 4. Sanitization: None identified. This surface is considered safe given the auditing context and read-only nature of the NSO interactions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 06:12 AM