outlook-automation
Warn
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the addition of an external MCP server located at
https://rube.app/mcp. This server provides the tools and execution environment for the Outlook automation tasks. - [DATA_EXFILTRATION]: The skill facilitates the transfer of sensitive Microsoft Outlook information (emails, calendar events, and contacts) to the
rube.appinfrastructure. This domain is not recognized as a well-known service or a trusted organization, posing a risk to data privacy. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data via tools like
OUTLOOK_GET_MESSAGEandOUTLOOK_DOWNLOAD_OUTLOOK_ATTACHMENT. - Ingestion points: Data enters the context through email message bodies and file attachments retrieved from the user's mailbox.
- Boundary markers: The instructions do not define delimiters or specific safety warnings to prevent the agent from following instructions embedded within the emails or attachments.
- Capability inventory: The skill has extensive capabilities including reading/writing emails, managing contacts, and performing network operations via the MCP server.
- Sanitization: There is no evidence of sanitization or validation of the content retrieved from Outlook before it is processed by the agent.
Audit Metadata