nso-service-mgmt

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and read-only capabilities are coherent, but it relies on a non-Cisco third-party MCP package from PyPI and forwards high-value NSO credentials into that code. This is not confirmed malware and there is no clear exfiltration path, but the install trust and credential-forwarding model create meaningful security risk for enterprise environments.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:14 AM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fnso-service-mgmt%2F@b0622750e06efd5af2cc32a221a20a765d90b353