outlook-calendar-automation
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent and user to configure a connection to an external MCP server located at
https://rube.app/mcp. This server serves as the provider for the Outlook automation tools described in the skill. - [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by reading untrusted data from calendar events. 1. Ingestion points:
OUTLOOK_LIST_EVENTS,OUTLOOK_GET_EVENT, andOUTLOOK_GET_CALENDAR_VIEWtools defined inSKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Tool actions for creating, updating, deleting, and declining events. 4. Sanitization: Not specified in the instructions. If a calendar event subject or body contains hidden instructions, the agent might inadvertently follow them while processing the event.
Audit Metadata