outlook-automation

Warn

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the addition of an external MCP server located at https://rube.app/mcp. This server provides the tools and execution environment for the Outlook automation tasks.
  • [DATA_EXFILTRATION]: The skill facilitates the transfer of sensitive Microsoft Outlook information (emails, calendar events, and contacts) to the rube.app infrastructure. This domain is not recognized as a well-known service or a trusted organization, posing a risk to data privacy.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data via tools like OUTLOOK_GET_MESSAGE and OUTLOOK_DOWNLOAD_OUTLOOK_ATTACHMENT.
  • Ingestion points: Data enters the context through email message bodies and file attachments retrieved from the user's mailbox.
  • Boundary markers: The instructions do not define delimiters or specific safety warnings to prevent the agent from following instructions embedded within the emails or attachments.
  • Capability inventory: The skill has extensive capabilities including reading/writing emails, managing contacts, and performing network operations via the MCP server.
  • Sanitization: There is no evidence of sanitization or validation of the content retrieved from Outlook before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 7, 2026, 02:27 AM
Security Audit — agent-trust-hub — outlook-automation