msgraph
Pass
Audited by Gen Agent Trust Hub on May 25, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses platform-specific launcher scripts to execute a pre-bundled CLI binary located in its directory to provide search and API calling capabilities.
- [PROMPT_INJECTION]: While the skill processes data from the Microsoft Graph API which could serve as a vector for indirect prompt injection, it includes strict instructions for the agent to seek user confirmation for any write operations and explicitly blocks all delete operations.
- [DATA_EXFILTRATION]: The skill performs network operations to official Microsoft Graph and authentication endpoints. These interactions are necessary for the skill's functionality as an API client and target trusted domains.
Audit Metadata