cisco-yang-cli
Warn
Audited by Socket on Apr 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The purpose and device-management capabilities are coherent for IOS-XE RESTCONF/YANG operations, and the stated data flow to Cisco devices is plausible. The main issue is trust: the skill centers on an unverifiable `cisco-yang` binary that accepts credentials and can execute powerful device actions, with no official install or release provenance provided. That creates a high security risk even without direct evidence of malicious exfiltration.
Confidence: 87%Severity: 84%
Audit Metadata