microsoft-entra-id
Warn
Audited by Socket on Sep 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is coherent with its stated purpose and the install source is a legitimate npm package, but its real data flow depends on Membrane as a credential-handling intermediary and API proxy rather than direct Microsoft Graph access. That third-party routing materially increases trust and data-flow risk beyond a normal direct Entra integration, though there is not enough evidence to call it malicious.
Confidence: 86%Severity: 58%
Audit Metadata