microsoft-graph-gateway

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose is coherent for Microsoft Graph access, and the write-confirmation rules are proportionate. The main concern is install/execution trust: the skill delegates to unspecified substrates and can bootstrap the third-party `merill/msgraph` runner, creating a transitive trust chain and moderate supply-chain risk without clear first-party Microsoft-only execution paths.

Confidence: 82%Severity: 66%
Audit Metadata
Analyzed At
May 20, 2026, 06:45 PM
Package URL
pkg:socket/skills-sh/aktsmm%2Fagent-skills%2Fmicrosoft-graph-gateway%2F@24ed5045426d70d5ceaefd2101685db12a7167a4
Security Audit — socket — microsoft-graph-gateway