microsoft-outlook

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by a known organization (Zapier) and interacts exclusively with the official Microsoft Graph API (graph.microsoft.com).
  • [SAFE]: Dependencies are restricted to standard, well-maintained libraries such as Zod and the Model Context Protocol SDK, along with Zapier's own connectors-sdk.
  • [SAFE]: Authentication is handled using secure methods, supporting both Zapier-managed OAuth and direct environment-based access tokens, with explicit guidance to avoid leaking credentials in logs or chat history.
  • [SAFE]: The codebase lacks any signs of obfuscation, persistence mechanisms, or unauthorized privilege escalation. The entry-point script (cli.js) performs standard environment checks (Node.js version, local dependencies) before delegating to the main tool dispatcher.
  • [SAFE]: While the skill ingests external data (emails and calendar events), it provides clear disambiguation rules to prevent unintended actions and relies on the underlying LLM's safety guardrails for processing content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 07:14 AM
Security Audit — agent-trust-hub — microsoft-outlook