outlook-calendar
Warn
Audited by Snyk on Aug 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). 该技能在运行时会读取 Microsoft Outlook 日历事件数据(POST/生成的文本由 Microsoft Outlook API 返回并被 LLM 处理),路径为
owa_calendar.py→fetch_calendar_api()(请求https://outlook.office.com/api/v2.0/me/CalendarView)→parse_events()(将返回的Subject/Organizer等字段作为可读文本参与输出/整理)。
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata