box-legal-workflows-ma
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core Box data-room capabilities match the stated M&A purpose and the referenced install sources are attributable to official operators, so this is not malicious on its face. However, it relies on transitive skill installation from npm/GitHub, uses unpinned remote skill loading, and can grant external access to sensitive documents; those are medium security risks even though the workflow includes user confirmation and Box-scoped audits.
Confidence: 89%Severity: 56%
Audit Metadata