aap-eda

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent, but its actual trust model is not: a Red Hat/Ansible admin workflow is routed through a personal GitHub MCP server installed by git clone and given EDA credentials plus control over live automation. That combination makes the skill high risk even without confirmed malicious behavior.

Confidence: 89%Severity: 86%
Audit Metadata
Analyzed At
Jul 30, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Faap-eda%2F@daacdc83e875b043f1dfa69f5b8a8e4dad3f7688670cdce30f84a2a4ed034cf8
Security Audit — socket — aap-eda