msgraph-files

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches Microsoft Graph file management, but its execution model is riskier than necessary: it uses unpinned npx execution of a not-fully-verified external MCP package and forwards raw Azure application credentials to that package. Data flows are broadly consistent with the purpose, so this is not confirmed malware, but install trust and credential forwarding make it a high security-risk skill.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:14 AM
Package URL
pkg:socket/skills-sh/automateyournetwork%2Fnetclaw%2Fmsgraph-files%2F@d0436bb62c3f9b6cf32870d4d9cadf83045a81d0