teams-migration

Warn

Audited by Socket on Jun 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s core purpose and capabilities mostly align, but it forwards Microsoft auth material and chat data through a third-party personal npm MCP tool invoked via unpinned @latest, plus mandatory localhost notification behavior. This is not clearly malicious, but the install trust and credential-handling footprint are broader than ideal for a Teams migration skill.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 15, 2026, 04:18 PM
Package URL
pkg:socket/skills-sh/julianobarbosa%2Fclaude-code-skills%2Fteams-migration%2F@95e478c7dd84b7ba200e02c3af01d98f8dc16ad9e5a931bc203338c95a17af53
Security Audit — socket — teams-migration