auvik-lifecycle
Warn
Audited by Socket on Jul 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core behavior is mostly coherent with a lifecycle/reporting skill and the API target is Auvik's official endpoint, so there is no strong evidence of malware or credential harvesting. However, the skill handles sensitive configuration backup contents, forwards API credentials through local MCP code, permits TLS verification disablement, and depends on another skill for workflow logging; these combined factors make it higher risk than a simple read-only inventory skill.
Confidence: 88%Severity: 52%
Audit Metadata