Back to skill

Security audit

Outlook Mailbox — app-only Graph access scoped to named Exchange mailboxes

Security checks for vulnerabilities and agentic risk

Overview

This skill handles sensitive Outlook mailbox access, but its instructions are coherent, scoped, and focused on limiting Graph access rather than expanding it.

Install only if you intend to administer Microsoft 365 mailbox access and can approve the listed lawful basis, mailbox list, folder and field minimization, retention, and owner-notice requirements. Keep Graph credentials out of the agent, use the allowlist script for runtime calls, and treat the curl checks as manual admin verification only.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
# Outlook Mailbox Access (app-only, scoped)

A scoped mailbox grant is an Exchange object, not an Entra consent. Consent `Mail.*` in Entra and the scope stops scoping anything, with no error and no warning.

## Personal Data: Settle This Before Any Setup

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

The skill instructs use of raw curl with a bearer token supplied via generated config input, which creates a path for arbitrary network requests if an agent follows the pattern outside the stated one-off admin probe. Even though the example targets Graph, passing authentication material into generic HTTP tooling expands the blast radius of token misuse, SSRF-like misuse, or accidental calls beyond the closed allowlist model the skill otherwise advocates.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
# token must carry NO mail role; a Mail.* entry here proves an Entra grant (union trap)
python3 -c 'import sys,json,base64;p=sys.stdin.read().split(".")[1];p+="="*(-len(p)%4);print(json.loads(base64.urlsafe_b64decode(p)).get("roles",[]))' <<<"$TOKEN"
# Output: []
printf 'header = "Authorization: Bearer %s"\n' "$TOKEN" | curl -s -o /dev/null -w '%{http_code}\n' -K - \
  "https://graph.microsoft.com/v1.0/users/relay@contoso.com/mailFolders/inbox/messages?\$top=1&\$select=id"
# Output: 200
printf 'header = "Authorization: Bearer %s"\n' "$TOKEN" | curl -s -o /dev/null -w '%{http_code}\n' -K - \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

This second curl example repeats the same unsafe pattern: a generic HTTP client is given a live bearer token and a user mailbox URL, relying on operator discipline instead of technical enforcement. Because the skill's purpose is mailbox access, misuse here is especially sensitive: the token can expose personal communications and mailbox metadata if repurposed or redirected.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

printf 'header = "Authorization: Bearer %s"\n' "$TOKEN" | curl -s -o /dev/null -w '%{http_code}\n' -K -
"https://graph.microsoft.com/v1.0/users/relay@contoso.com/mailFolders/inbox/messages?\$top=1&\$select=id"

Output: 200

printf 'header = "Authorization: Bearer %s"\n' "$TOKEN" | curl -s -o /dev/null -w '%{http_code}\n' -K -
"https://graph.microsoft.com/v1.0/users/ceo@contoso.com/mailFolders/inbox/messages?\$top=1&\$select=id"

Output: 403

text

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly contains network-capable operations (curl, Graph API access, PowerShell modules that call external services) but does not declare any tool scope such as permissions or allowed-tools. That mismatch weakens containment and review because an agent may invoke networked behavior without an explicit, machine-readable restriction boundary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.