Microsoft Onenote

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed OneNote integration, but users should be careful because it can read, create, copy, delete, and proxy requests to OneNote through Membrane.

Install only if you trust Membrane and the Membrane CLI with the Microsoft account you connect. Review the OAuth permissions, avoid connecting highly sensitive notebooks unless needed, and require the agent to show the exact notebook, section, page, and operation before delete, copy, create, or raw proxy requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill exposes destructive OneNote capabilities such as deleting pages and copying or creating content without any guidance to require user confirmation, preview the target resource, or verify intent before execution. In an agent setting, this increases the risk of accidental or unauthorized destructive actions caused by ambiguous prompts, mis-selection of resources, or over-eager automation.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal