auvik-lifecycle

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core behavior is mostly coherent with a lifecycle/reporting skill and the API target is Auvik's official endpoint, so there is no strong evidence of malware or credential harvesting. However, the skill handles sensitive configuration backup contents, forwards API credentials through local MCP code, permits TLS verification disablement, and depends on another skill for workflow logging; these combined factors make it higher risk than a simple read-only inventory skill.

Confidence: 88%Severity: 52%
Audit Metadata
Analyzed At
Jul 30, 2026, 04:30 PM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fauvik-lifecycle%2F@2418b1ee901afe6007be2041191a35a5afe60ee849b88f435cfa9554a491f981
Security Audit — socket — auvik-lifecycle