aap-eda
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent, but its actual trust model is not: a Red Hat/Ansible admin workflow is routed through a personal GitHub MCP server installed by git clone and given EDA credentials plus control over live automation. That combination makes the skill high risk even without confirmed malicious behavior.
Confidence: 89%Severity: 86%
Audit Metadata