outlook-calendar-automation

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent and user to configure a connection to an external MCP server located at https://rube.app/mcp. This server serves as the provider for the Outlook automation tools described in the skill.
  • [PROMPT_INJECTION]: The skill exposes a surface for indirect prompt injection by reading untrusted data from calendar events. 1. Ingestion points: OUTLOOK_LIST_EVENTS, OUTLOOK_GET_EVENT, and OUTLOOK_GET_CALENDAR_VIEW tools defined in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Tool actions for creating, updating, deleting, and declining events. 4. Sanitization: Not specified in the instructions. If a calendar event subject or body contains hidden instructions, the agent might inadvertently follow them while processing the event.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:34 PM
Security Audit — agent-trust-hub — outlook-calendar-automation