agent-teams

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's Teams capabilities largely match its stated purpose and the npm install path appears official, but its authentication model relies on silent extraction of Teams tokens from local desktop/browser stores and it enables autonomous messaging, deletion, reactions, and file uploads without clear per-action approval. This is high-impact agent functionality with meaningful credential and action risk, though not clear evidence of malware or third-party credential exfiltration.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
May 8, 2026, 05:19 AM
Package URL
pkg:socket/skills-sh/devxoul%2Fagent-messenger%2Fagent-teams%2F@1e32c7ea675fbb70edf1cf77784a3926506bca53