post-exploiting-microsoft-graph-with-graphrunner

Fail

Audited by Socket on Aug 4, 2026

2 alerts found:

SecurityMalware
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally consistent with its stated red-team purpose, but that purpose is to give an AI agent offensive post-exploitation capability against Microsoft 365 tenants. No obvious credential-harvesting proxy or hidden exfiltration endpoint is shown, yet the combination of token handling, tenant modification, persistence, and data collection makes it a high-risk offensive skill.

Confidence: 92%Severity: 90%
MalwareHIGH
references/api-reference.md

Based on the described module capabilities, GraphRunner is a high-risk package in an enterprise supply-chain context because it can obtain/handle Graph tokens (including externally imported tokens), perform tenant-wide recon, modify identity state, establish persistence (OAuth app injection and hidden inbox forwarding rules), and search/read/download sensitive mailbox/SharePoint/OneDrive/Teams content to local disk. Implementation details are not present here, so this assessment is driven by explicit documented behavior; nonetheless, the capability set strongly aligns with account-compromise and data-theft tooling rather than benign administration.

Confidence: 55%Severity: 90%
Audit Metadata
Analyzed At
Aug 4, 2026, 02:42 PM
Package URL
pkg:socket/skills-sh/mukul975%2FAnthropic-Cybersecurity-Skills%2Fpost-exploiting-microsoft-graph-with-graphrunner%2F@ca7bacb03ec9ed185f8552bbf98b7619329ab467657e7ee010006032f105bd08
Security Audit — socket — post-exploiting-microsoft-graph-with-graphrunner