microsoft-teams-automation

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the user to connect to an external MCP server endpoint at https://rube.app/mcp. This establishes a dependency on an external service provider for the skill's core functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides tools to retrieve and search messages from Microsoft Teams, creating a surface where malicious instructions embedded in messages could influence the agent.
  • Ingestion points: Tools such as MICROSOFT_TEAMS_SEARCH_MESSAGES and MICROSOFT_TEAMS_GET_CHAT_MESSAGE ingest external, user-generated content from Teams into the agent's context (SKILL.md).
  • Boundary markers: There are no instructions or delimiters defined to help the agent distinguish between message content and legitimate system instructions.
  • Capability inventory: The skill possesses significant capabilities, including posting messages (MICROSOFT_TEAMS_TEAMS_POST_CHANNEL_MESSAGE), creating meetings (MICROSOFT_TEAMS_CREATE_MEETING), and managing team members (MICROSOFT_TEAMS_ADD_MEMBER_TO_TEAM), which could be targeted by an injection attack.
  • Sanitization: The skill does not implement or recommend any sanitization or validation of the retrieved message content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:52 PM