microsoft-teams-automation
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to connect to an external MCP server endpoint at
https://rube.app/mcp. This establishes a dependency on an external service provider for the skill's core functionality. - [INDIRECT_PROMPT_INJECTION]: The skill provides tools to retrieve and search messages from Microsoft Teams, creating a surface where malicious instructions embedded in messages could influence the agent.
- Ingestion points: Tools such as
MICROSOFT_TEAMS_SEARCH_MESSAGESandMICROSOFT_TEAMS_GET_CHAT_MESSAGEingest external, user-generated content from Teams into the agent's context (SKILL.md). - Boundary markers: There are no instructions or delimiters defined to help the agent distinguish between message content and legitimate system instructions.
- Capability inventory: The skill possesses significant capabilities, including posting messages (
MICROSOFT_TEAMS_TEAMS_POST_CHANNEL_MESSAGE), creating meetings (MICROSOFT_TEAMS_CREATE_MEETING), and managing team members (MICROSOFT_TEAMS_ADD_MEMBER_TO_TEAM), which could be targeted by an injection attack. - Sanitization: The skill does not implement or recommend any sanitization or validation of the retrieved message content before it is processed by the agent.
Audit Metadata