one-drive-automation

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires connecting to an external MCP server at https://rube.app/mcp. This external endpoint is used to provide the underlying tools for OneDrive automation.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data from a remote source (OneDrive). It searches, lists, and reads file metadata/content. If an attacker places files with malicious instructions in a shared OneDrive folder or file name, it could potentially influence the agent's behavior when those items are processed.
  • [COMMAND_EXECUTION]: The skill utilizes the Composio and Rube MCP toolsets to perform file operations. While these are legitimate automation tools, the agent is granted significant capability to create, delete, and modify files within the user's OneDrive environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:19 AM
Security Audit — agent-trust-hub — one-drive-automation