ms365-tenant-manager

Warn

Audited by Socket on Aug 21, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
references/powershell-templates.md

No clear supply-chain malware indicators are present (no obfuscation, no dynamic execution, no suspicious external network exfiltration logic). The primary security concern is credential disclosure: bulk provisioning exports plaintext per-user passwords to a CSV file, creating an at-rest secret exposure risk. Secondary concerns are high-impact privileged operations (Conditional Access policy creation and user/mailbox lifecycle changes) that require strict access control, auditing, and careful use of WhatIf/report-only modes.

Confidence: 62%Severity: 56%
AnomalyLOW
scripts/user_management.py

No strong evidence of covert malware (e.g., exfiltration, backdoor/persistence, or obfuscated payloads) is present in the provided fragment. However, the module generates highly privileged Microsoft 365 administration scripts and directly interpolates user-controlled fields into PowerShell code without visible escaping, creating a realistic script/command injection risk if attacker-controlled inputs can reach script generation/execution. It also embeds a weak default initial password pattern, which is an operational security concern. The snippet appears malformed/incomplete, so certainty is limited, but overall security risk remains moderate-to-high due to privileged automation and insecure templating.

Confidence: 46%Severity: 66%
Audit Metadata
Analyzed At
Aug 21, 2026, 05:04 AM
Package URL
pkg:socket/skills-sh/ciciliaeth%2Fclaude-skills%2Fms365-tenant-manager%2F@8fc87f1a738d2d09cc686348f3239cc0dd4c3b3b44769edc0a55164e7b8257ae
Security Audit — socket — ms365-tenant-manager