box-legal-workflows-ma

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Box data-room capabilities match the stated M&A purpose and the referenced install sources are attributable to official operators, so this is not malicious on its face. However, it relies on transitive skill installation from npm/GitHub, uses unpinned remote skill loading, and can grant external access to sensitive documents; those are medium security risks even though the workflow includes user confirmation and Box-scoped audits.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Sep 3, 2026, 06:14 PM
Package URL
pkg:socket/skills-sh/box%2Fskills%2Fbox-legal-workflows-ma%2F@7e9b379ff228c15df5a140c1e570ae6c2ceae00826896849a9c6e4953a62e9fa
Security Audit — socket — box-legal-workflows-ma