msgraph-visio
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core workflow is coherent for SharePoint-hosted Visio generation, but it forwards Azure client secrets to an npx-installed third-party MCP package and can publish organization-scoped sharing links. This looks more like a high-trust integration than outright malware, but the credential handling and remote package execution create medium security risk.
Confidence: 81%Severity: 58%
Audit Metadata