cml-topology-builder

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's topology-building capabilities and required CML credentials are broadly consistent with its stated purpose, but it relies on a community-maintained third-party MCP server that receives those credentials. There is no clear evidence of malicious exfiltration, yet the external credential-forwarding trust boundary and undeclared cross-tool references make the overall footprint moderately risky.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:13 AM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fcml-topology-builder%2F@234397752494665f0b24860e61de5988add6de5a