T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Execution of Unpinned Third-Party Source and Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent Microsoft 365 helper, but it asks the agent to install and run mutable third-party code while enabling persistent authenticated access and mailbox/calendar changes without clear approval boundaries.
Install only if you are comfortable giving this tool access to your Microsoft 365 mailbox and calendar. Prefer a pinned, reviewed revision, use a dedicated or contained profile where possible, avoid persistent keepalive unless you need it, and require explicit confirmation before sending mail, replying/forwarding, deleting events, moving mail, or downloading attachments.
SKILL.md:13Execution of Unpinned Third-Party Source and Dependencies
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
clippy calendar --details
### Create Events
```bash
clippy create-event "Title" 09:00 10:00
The skill explicitly exposes state-changing actions for a user's mailbox and calendar, including sending mail, deleting events, moving messages, and marking items read, but it does not warn that these operations modify user data or require explicit confirmation. In an agent setting, this increases the chance of unintended destructive or privacy-impacting actions being taken on behalf of the user through ambiguous prompts or automation mistakes.
No suspicious patterns detected.