microsoft-graph-api
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly coherent with its Microsoft Graph purpose and uses an official npm-distributed vendor CLI, but it routes authentication and API traffic through Membrane instead of directly to Microsoft Graph. That intermediary credential/data flow is disclosed rather than hidden, so this is not confirmed malware, but it materially increases trust and security risk beyond a direct Graph integration.
Confidence: 85%Severity: 56%
Audit Metadata