ms-teams-setup

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and requested Microsoft Graph access are broadly coherent, but the trust chain is not: it installs an unpinned third-party MCP package via `npx -y`, uses a package name that does not match the cited upstream documentation, and forwards Microsoft OAuth tokens plus message access to non-Microsoft code. This is not clearly malicious, but it is a high-risk supply-chain and credential-forwarding pattern for a Teams setup skill.

Confidence: 91%Severity: 86%
Audit Metadata
Analyzed At
May 20, 2026, 12:43 AM
Package URL
pkg:socket/skills-sh/davekilleen%2FDex%2Fms-teams-setup%2F@f98fff931808d386feaf69c882721d46e675213e
Security Audit — socket — ms-teams-setup