Security audit
Microsoft OneNote
Security checks across malware telemetry and agentic risk
Overview
This skill is a clearly disclosed OneNote integration that uses Maton and Microsoft Graph with appropriate cautions around authentication and write actions.
Before installing, be aware that this skill can read and modify OneNote content through a Maton-connected Microsoft account. Use OAuth where possible, approve new connections and write/delete actions only when you understand the target notebook or page, and avoid the API-key fallback unless the CLI is unavailable.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
64/64 vendors flagged this skill as clean.
Static analysis
No suspicious patterns detected.
