msgraph-teams

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s Teams-notification purpose aligns with its messaging capabilities and Azure Graph credentials, but the main execution path fetches and runs an unpinned npm package whose official provenance was not verified in the provided evidence. Because that external package receives Azure client secrets and can perform outbound Teams actions, the overall risk is high despite generally coherent functionality.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:14 AM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fmsgraph-teams%2F@a4fb8a6a24367ca76f6be5ff642f6eec95bd345a