nso-service-mgmt
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and read-only capabilities are coherent, but it relies on a non-Cisco third-party MCP package from PyPI and forwards high-value NSO credentials into that code. This is not confirmed malware and there is no clear exfiltration path, but the install trust and credential-forwarding model create meaningful security risk for enterprise environments.
Confidence: 87%Severity: 68%
Audit Metadata