nso-service-mgmt
Pass
Audited by Gen Agent Trust Hub on Mar 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill requires sensitive credentials (NSO_PASSWORD, NSO_USERNAME) to be provided via environment variables, which is a standard and safe practice for network automation.
- [SAFE]: The pip-installed dependency cisco-nso-mcp-server is a vendor-appropriate tool for the skill's stated purpose of Cisco NSO management.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes service and device configuration data from NSO. 1. Ingestion points: get_service_types and get_services tools. 2. Boundary markers: None identified. 3. Capability inventory: Integration with github-ops for repository writes and messaging services for reporting. 4. Sanitization: None identified. This surface is considered safe given the auditing context and read-only nature of the NSO interactions.
Audit Metadata