microsoft-onedrive

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
.mcp.json

No direct malicious or obfuscated behavior is present in this JSON snippet. However, it configures the system to execute a third-party npm package at runtime via 'npx -y' without visible version pinning/integrity controls, creating a meaningful supply-chain execution risk. The connector package contents and the consuming project's dependency/version enforcement should be verified before trust is granted.

Confidence: 65%Severity: 52%
Audit Metadata
Analyzed At
Sep 17, 2026, 10:25 PM
Package URL
pkg:socket/skills-sh/zapier%2Fconnectors%2Fmicrosoft-onedrive%2F@40a0d1208fdf74104196aec27a1ff93d708a9cac1267540083b9ae2a288f2a15
Security Audit — socket — microsoft-onedrive