T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/outlook-token.sh:44- Finding
OAuth Scope Requests Permissions Beyond Implemented Functionality
- Content
View full analysis
Vulnerability Details
File Location:
scripts/outlook-token.sh:44-46
Additional Locations:SKILL.md:84-93,references/setup.md:42-51,references/setup.md:188-194
Vulnerability Type: Excessive Microsoft Graph delegated permissions
Risk Level: MediumVulnerable Code
bash # Token endpoint (tenant-specific, not /common) TOKEN_URL="https://login.microsoftonline.com/$TENANT_ID/oauth2/v2.0/token" SCOPE="offline_access User.Read Mail.ReadWrite Mail.Send Mail.ReadWrite.Shared Mail.Send.Shared Calendars.ReadWrite Calendars.ReadWrite.Shared"The same excessive permission set is documented during setup:
markdown **Basic permissions:** - `Mail.ReadWrite` — Read/write assistant's mail - `Mail.Send` — Send as assistant - `Calendars.ReadWrite` — Calendar access - `User.Read` — Read profile - `offline_access` — Refresh tokens **Delegate permissions:** - `Mail.ReadWrite.Shared` — Read/write owner's mail - `Mail.Send.Shared` — Send as/on behalf of owner - `Calendars.ReadWrite.Shared` — Owner's calendarTechnical Analysis
The Skill's implemented mail-reading and mail-management operations target the owner's shared mailbox through
/users/{owner}. Its only implemented operation involving the delegate's mailbox is sending mail through/users/{delegate}/sendMail.Despite this, the OAuth scope always requests:
Mail.ReadWrite, which permits reading and modifying the delegate's own mailbox.Calendars.ReadWrite, which permits reading and modifying the delegate's own calendars.
These permissions are not required by the audited implementation. Shared-resource functionality is already represented by
Mail.ReadWrite.Shared,Mail.Send.Shared, andCalendars.ReadWrite.Shared. Sending as the delegate requiresMail.Send, but it does not require full read/write access to the delegate's mailbox.The fixed scope is used during initial authorization and token refresh, so the unnecessary privileges remain associated with r ...[truncated 1360 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
Mail.ReadWriteunless the Skill explicitly implements and documents reading or managing the delegate's own mailbox. - Remove
Calendars.ReadWriteunless the Skill explicitly implements and documents management of the delegate's own calendar. - Retain only the scopes required by enabled features:
User.ReadMail.Sendfor sending as the delegateMail.ReadWrite.Sharedfor managing the owner's shared mailboxMail.Send.Sharedfor delegated sendingCalendars.ReadWrite.Sharedfor managing the owner's shared calendaroffline_accessonly if persistent refresh is required
- Build the authorization scope dynamically from explicitly enabled features rather than using one unconditional scope.
- Update both
SKILL.mdandreferences/setup.mdto explain why each permission is required. - Revoke the existing application consent and reauthorize after reducing the scope, because editing the script alone does not remove permissions from previously issued grants.
- Consider separate application registrations or authorization profiles for read-only, mail-management, calendar-management, and delegated-send use cases.
- Remove
