nvd-cve

Warn

Audited by Socket on May 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose is coherent and the intended external service is the official NVD API, so this is not fundamentally incompatible with its stated use. However, the trust boundary is unclear because the API key and queries are routed through opaque local MCP wrapper scripts whose provenance and behavior are not verified by the skill, creating moderate credential-forwarding and execution-trust risk.

Confidence: 84%Severity: 57%
Audit Metadata
Analyzed At
May 18, 2026, 04:23 PM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fnvd-cve%2F@eb3efa86e0ae80f436e5cbec26cc6516cb7cdad3
Security Audit — socket — nvd-cve