microsoft-graph-gateway
Warn
Audited by Socket on May 20, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The core purpose is coherent for Microsoft Graph access, and the write-confirmation rules are proportionate. The main concern is install/execution trust: the skill delegates to unspecified substrates and can bootstrap the third-party `merill/msgraph` runner, creating a transitive trust chain and moderate supply-chain risk without clear first-party Microsoft-only execution paths.
Confidence: 82%Severity: 66%
Audit Metadata