microsoft-entra-id

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities broadly match its stated Entra ID management purpose, and the install source is a legitimate npm package rather than an opaque binary. The main concern is data-flow integrity and scope: authentication, token refresh, and API requests are mediated by Membrane instead of going directly to Microsoft Graph, creating a third-party trust boundary for high-impact identity administration. This is not clearly malicious, but it is a medium-risk enterprise integration skill with disproportionate consequences if misused.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 28, 2026, 07:40 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fmicrosoft-entra-id%2F@89ef5accedce2e29445506a84533abfc7012e11c