agent-teams
Warn
Audited by Socket on May 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's Teams capabilities largely match its stated purpose and the npm install path appears official, but its authentication model relies on silent extraction of Teams tokens from local desktop/browser stores and it enables autonomous messaging, deletion, reactions, and file uploads without clear per-action approval. This is high-impact agent functionality with meaningful credential and action risk, though not clear evidence of malware or third-party credential exfiltration.
Confidence: 83%Severity: 72%
Audit Metadata