microsoft-onedrive
Warn
Audited by Socket on Sep 17, 2026
1 alert found:
AnomalyAnomaly.mcp.json
LOWAnomalyLOW
.mcp.json
No direct malicious or obfuscated behavior is present in this JSON snippet. However, it configures the system to execute a third-party npm package at runtime via 'npx -y' without visible version pinning/integrity controls, creating a meaningful supply-chain execution risk. The connector package contents and the consuming project's dependency/version enforcement should be verified before trust is granted.
Confidence: 65%Severity: 52%
Audit Metadata