one-drive-automation
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires connecting to an external MCP server at
https://rube.app/mcp. This external endpoint is used to provide the underlying tools for OneDrive automation. - [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data from a remote source (OneDrive). It searches, lists, and reads file metadata/content. If an attacker places files with malicious instructions in a shared OneDrive folder or file name, it could potentially influence the agent's behavior when those items are processed.
- [COMMAND_EXECUTION]: The skill utilizes the Composio and Rube MCP toolsets to perform file operations. While these are legitimate automation tools, the agent is granted significant capability to create, delete, and modify files within the user's OneDrive environment.
Audit Metadata