msgraph-visio

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core workflow is coherent for SharePoint-hosted Visio generation, but it forwards Azure client secrets to an npx-installed third-party MCP package and can publish organization-scoped sharing links. This looks more like a high-trust integration than outright malware, but the credential handling and remote package execution create medium security risk.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:14 AM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fmsgraph-visio%2F@d277232245b4e008e1048efcf98ce37cf9fed98f
Security Audit — socket — msgraph-visio