dataverse-web-resources

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected This skill is a benign, authoritative guidance/reference for creating and managing Dataverse web resources. It documents expected APIs and deployment patterns and does not contain embedded malicious code, external untrusted downloads, or instructions to exfiltrate credentials. The legitimate risk arises from the general capability to upload and host JavaScript that will run in tenant users' browsers — that is an operational/platform security concern rather than a problem with this skill text itself. Recommended mitigations when implementing: validate and review any web resource code before upload, avoid storing sensitive tokens in client-side caches, and follow least-privilege when assigning permissions for deployment scripts. LLM verification: The SKILL.md is documentation for Dataverse web resource development and deployment. Its stated capabilities match the actions it describes (form scripts, Xrm APIs, webresource create/update/publish). There are no indicators of malicious payloads, credential exfiltration, remote download-and-execute chains, or obfuscation in the provided text. However, the documented operations are privileged (modify/publish web resources and records) and should only be executed with proper authentication and le

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 20, 2026, 10:31 PM
Package URL
pkg:socket/skills-sh/DanielKerridge%2Fclaude-code-power-platform-skills%2Fdataverse-web-resources%2F@83556b72684c862109a39c44c5a65eafe26375d0