Back to skill

Security audit

Outlook

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Outlook API skill, but it needs Review because it enables sensitive Outlook access and destructive or externally transmitting actions without clear confirmation guardrails.

Install only if you trust Maton with Outlook access and are prepared to supervise agent actions. Require your agent to show message/event/contact details before modifying or deleting them, preview outbound emails with recipients before sending, and use the least-privileged OAuth connection available.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill exposes broad mailbox, calendar, contacts, and sending/deletion capabilities but provides no safety guidance, confirmation requirements, or warning that these actions can access sensitive personal/business data and make irreversible changes. In an agent-skill context, omission of such warnings increases the chance of unsafe autonomous use or user surprise around privacy-sensitive and destructive operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
-H "Authorization: Bearer $MATON_API_KEY" | jq

➕ Create Connection
curl -X POST https://ctrl.maton.ai/connections \
  -H "Authorization: Bearer $MATON_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"app": "outlook"}' | jq

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The connection deletion example shows an authenticated DELETE operation without warning that it disconnects the Outlook account and may disrupt future access or automations. In a skill intended for agent use, undocumented destructive account-management actions can be triggered without adequate user understanding or confirmation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
📚 API Reference
👤 User Profile
curl https://gateway.maton.ai/outlook/v1.0/me \
  -H "Authorization: Bearer $MATON_API_KEY"

📁 Mail Folders

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The send-mail examples enable transmission of potentially sensitive user or enterprise data to external recipients without any warning, review step, or confirmation requirement. In an agent environment, this creates a meaningful risk of unintended data exfiltration, phishing-like misuse, or accidental disclosure through autonomous email sending.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The deletion examples for messages/events present irreversible or operationally disruptive data-removal actions without warning about loss of records or side effects. This is dangerous in a skill because an agent could perform destructive actions on user communications or schedules without clear consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The examples for creating/deleting contacts and creating events modify user records but do not warn that these actions change authoritative personal/business data. While less severe than direct exfiltration, unguarded record modification can still create integrity issues, confusion, and workflow disruption.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.