cisco-yang-cli

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The purpose and device-management capabilities are coherent for IOS-XE RESTCONF/YANG operations, and the stated data flow to Cisco devices is plausible. The main issue is trust: the skill centers on an unverifiable `cisco-yang` binary that accepts credentials and can execute powerful device actions, with no official install or release provenance provided. That creates a high security risk even without direct evidence of malicious exfiltration.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Apr 6, 2026, 02:04 AM
Package URL
pkg:socket/skills-sh/cmds-cc%2Fskills%2Fcisco-yang-cli%2F@3d21394fb88515df3f4d6d257e5c0da269e57be9