fortianalyzer-ops
Warn
Audited by Socket on Aug 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's stated purpose and read-only capabilities are internally consistent, and the intended endpoint aligns with FortiAnalyzer JSON-RPC. However, the skill delegates all sensitive access to an unspecified FORTINET_MCP_CMD binary with no verified public provenance or release artifacts in the evidence, while forwarding the FortiAnalyzer API token to it. That makes this primarily a supply-chain and credential-forwarding risk rather than confirmed malware.
Confidence: 86%Severity: 82%
Audit Metadata