cml-node-operations
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's capabilities fit its stated CML node-operations purpose, and data flows mostly match that purpose. Main concerns are trust in a third-party MCP package from a personal GitHub owner, credential forwarding to that package, and optional disabling of SSL verification; these raise moderate security risk but do not indicate confirmed malicious intent.
Confidence: 86%Severity: 52%
Audit Metadata