skills/craftos-dev/craftbot/one-drive/Gen Agent Trust Hub

one-drive

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill makes network calls to the external domains maton.ai, ctrl.maton.ai, and gateway.maton.ai to facilitate OneDrive operations and OAuth management. While these are part of the service's architecture, they involve transmitting user-managed API keys and data to infrastructure outside of the immediate trust boundary.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides the ability to read and process content from OneDrive, which could allow maliciously crafted files to influence the AI agent's actions through embedded instructions.\n
  • Ingestion points: The skill retrieves file content via GET requests to the OneDrive API gateway (e.g., /me/drive/items/{item-id}).\n
  • Capability inventory: The skill has permissions to write, rename, move, and share files and folders within the user's cloud storage.\n
  • Boundary markers: There are no instructions for the agent to treat downloaded content as untrusted or to use specific delimiters to isolate data from instructions.\n
  • Sanitization: No sanitization or validation of the retrieved file content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:52 PM
Security Audit — agent-trust-hub — one-drive