Back to skill

Security audit

Microsoft OneNote

Security checks across malware telemetry and agentic risk

Overview

This skill is a clearly disclosed OneNote integration that uses Maton and Microsoft Graph with appropriate cautions around authentication and write actions.

Before installing, be aware that this skill can read and modify OneNote content through a Maton-connected Microsoft account. Use OAuth where possible, approve new connections and write/delete actions only when you understand the target notebook or page, and avoid the API-key fallback unless the CLI is unavailable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.