microsoft-teams

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's purpose matches Teams access, but it routes authentication and data through ClawLink rather than direct Microsoft APIs. Same-org npm provenance reduces supply-chain concern, yet third-party credential/token brokering and remote write capability make the overall risk medium.

Confidence: 87%Severity: 62%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:44 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fmicrosoft-teams%2F@e0bca7ad023d34247517289859749bf0ff777a98526e795824287dc27095c7f7
Security Audit — socket — microsoft-teams