Back to skill

Security audit

bshio

Security checks for vulnerabilities and agentic risk

Overview

This Outlook skill requests persistent access to email and calendar data, but the package omits the executable it says will run, so its real behavior cannot be verified.

Review carefully before installing. Only use this if you are comfortable granting a local CLI persistent Microsoft Graph access to your mailbox and calendar, and do not install it until the missing ./outlook executable is provided and reviewed. Prefer least-privilege Azure permissions and protect or revoke the token file if exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:7
Finding

Unpinned Python Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 5–8
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code Snippet:

markdown
## Prerequisites

- Python 3.6+
- `requests` library: `pip install requests`

Technical Analysis

The documented installation command retrieves the latest available version of requests from the package index configured in the user's environment. It does not constrain the dependency to a reviewed version or verify its integrity with a cryptographic hash.

Consequently, dependency resolution is not reproducible and can change after the skill has been audited. Although requests is the correct name of a well-established package, installation may still be influenced by a compromised release, a compromised or malicious package mirror, package-index configuration, or future dependency changes. Python packages and their installation mechanisms can execute code during installation, and the installed package later executes in the context of the Outlook client.

The same unpinned dependency is also declared as python_packages: ["requests"] in SKILL.md at line 16.

Attack Path

  1. An attacker compromises an upstream package release or a package index or mirror configured on the target system.
  2. The attacker supplies a malicious or modified version that satisfies the unconstrained package name requests.
  3. A user follows the project documentation and runs pip install requests, or the skill framework installs the declared Python package automatically.
  4. The malicious package executes installation-time code or is loaded when the Outlook client imports it.
  5. The payload operates with the privileges of the installing or executing user.

Impact Assessment

Successful exploitation could permit arbitrary code execution with the privileges of the user running pip or the skill. This may expose local files, application config ...[truncated 426 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the unconstrained installation instruction with a dependency lock file containing a reviewed, exact version.
  2. Add cryptographic hashes and require their verification during installation, for example:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Define requests and all transitive dependencies in the lock file using exact versions and SHA-256 hashes.
  4. Use a trusted package index explicitly and prevent unintended fallback to untrusted mirrors.
  5. Install dependencies inside a dedicated virtual environment under an unprivileged account rather than using system-wide or administrative installation.
  6. Update the python_packages declaration in SKILL.md so automated installation uses the same reviewed version constraints.
  7. Establish a controlled dependency-update process that includes vulnerability scanning, provenance review, testing, and regenerated hashes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Ae3

High
Category
analysis-evasion
Confidence
90% confidence
Finding

Text artifact contains embedded NUL bytes

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 129)May include surrounding context.

md
If you get authentication errors:

1. Delete token file: `rm ~/.config/outlook-cli/token.json`
2. Re-authenticate: `./outlook auth`

### Permission Errors

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 287)May include surrounding context.

md
If you get authentication errors:

1. Delete token file: `rm ~/.config/outlook-cli/token.json`
2. Re-authenticate: `./outlook auth`

### Permission Errors

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 155)May include surrounding context.

md
## Security Notes

- Never share your Client Secret or token files
- The token file contains sensitive access tokens
- Consider using App-only authentication for production use

## License

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

md
- `SKILL.md` - This documentation

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 13)May include surrounding context.

md
## Setup

### 1. Create Azure AD App

1. Go to https://portal.azure.com
2. Navigate to **App registrations** → **New registration**

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises reply functionality that goes beyond the declared skill description of listing, searching, reading, and sending email plus calendar operations. Capability drift like this is dangerous because users and reviewers may grant trust or permissions based on the manifest while the implementation/documentation suggests broader message-handling behavior, reducing transparency and enabling unreviewed actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to grant Mail.ReadWrite even though the described core operations only require reading and sending mail. Requesting broader OAuth scopes than necessary violates least privilege and increases the blast radius if the CLI, token store, or host is compromised, because an attacker could modify or delete mailbox contents rather than only read/send.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The skill explicitly supports device-code authentication and stores OAuth tokens locally, enabling persistent delegated access to mail and calendar data across sessions. If the local token file is stolen, copied, or insufficiently protected, an attacker may gain ongoing access without re-prompting for credentials until revocation or expiry.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: outlook
emoji: f4e7
description: Microsoft Outlook/Live.com email and calendar client via Microsoft Graph API. List, search, read, send emails. View and create calendar events. Supports device code auth for servers.
license: MIT
compatibility: [openclaw, openclaw-cli, openclaw-web, claude-desktop, claude-api, claude-cli]
allowed-tools: [Bash, Read, Write, Python]

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains operational and safety-critical instructions in Chinese while the rest of the document is primarily in English. That creates a language-policy issue because users are forced into a specific language for important guidance without opt-in or an explicit statement that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The warning at these lines contains important verification steps about obtaining credentials from the official Azure portal, but it is written only in Chinese. Because this is key security guidance and no language choice is offered, it violates the natural-language policy criterion on forced language/locale.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

  1. Secure token file (Critical!):
    bash
    # Set restrictive permissions
    chmod 600 ~/.config/outlook-cli/token.json
    
    # Verify (should show: -rw-------)
    ls -l ~/.config/outlook-cli/token.json
    

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

  1. Secure token file (Critical!):
    bash
    # Set restrictive permissions
    chmod 600 ~/.config/outlook-cli/token.json
    
    # Verify (should show: -rw-------)
    ls -l ~/.config/outlook-cli/token.json
    

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

chmod 600 ~/.config/outlook-cli/token.json

Verify (should show: -rw-------)

ls -l ~/.config/outlook-cli/token.json

text
> ⚠️ **Important**: Never commit this file to version control or share it with others!

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · SKILL.md (reported line 248)May include surrounding context.

chmod 600 ~/.config/outlook-cli/token.json

Verify (should show: -rw-------)

ls -l ~/.config/outlook-cli/token.json

text
> ⚠️ **Important**: Never commit this file to version control or share it with others!

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

outlook calendar list --days 14

text

**Create event:**
```bash
# Simple event
outlook calendar create \

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 289)May include surrounding context.

md
1. Revoke access at https://account.microsoft.com/privacy/app-access
2. Delete the exposed token file: `rm ~/.config/outlook-cli/token.json`
3. Re-authenticate: `outlook auth --device-code`
4. Set proper permissions: `chmod 600 ~/.config/outlook-cli/token.json`
5. If committed to git, remove from history: `git filter-branch` or BFG Repo-Cleaner

### Q: How to create recurring meetings?

Static analysis

No suspicious patterns detected.