skills/merill/msgraph/msgraph/Gen Agent Trust Hub

msgraph

Pass

Audited by Gen Agent Trust Hub on May 25, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses platform-specific launcher scripts to execute a pre-bundled CLI binary located in its directory to provide search and API calling capabilities.
  • [PROMPT_INJECTION]: While the skill processes data from the Microsoft Graph API which could serve as a vector for indirect prompt injection, it includes strict instructions for the agent to seek user confirmation for any write operations and explicitly blocks all delete operations.
  • [DATA_EXFILTRATION]: The skill performs network operations to official Microsoft Graph and authentication endpoints. These interactions are necessary for the skill's functionality as an API client and target trusted domains.
Audit Metadata
Risk Level
SAFE
Analyzed
May 25, 2026, 09:03 AM
Security Audit — agent-trust-hub — msgraph