Back to skill

Security audit

Outlook

Security checks for vulnerabilities and agentic risk

Overview

This Outlook skill is coherent and disclosed, but it asks users to install an unpinned third-party CLI that will handle highly sensitive Microsoft 365 mail, calendar, and credential access.

Review the porteden CLI and its publisher before installing. Prefer browser login over direct-token login, use the narrowest Microsoft Graph scopes and an isolated profile, confirm every write/delete/send operation, and revoke Microsoft access plus clear the keyring entry when finished or if package integrity is uncertain.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:6
Finding

Unpinned Third-Party CLI Receives Access to Sensitive Microsoft 365 Data

Content
View full analysis
` — stored in system keyring - **Verify:** `porteden auth status` - If `PE_API_KEY` is set in the environment, the CLI uses it automatically (no login needed). ``` ### Technical Analysis The Skill instructs users to install the `porteden` CLI from a custom Homebrew tap or through the mutable Go module reference `github.com/porteden/cli/cmd/porteden@latest`. Neither installation method shown in the Skill pins an audited version, immutable commit, or cryptographic checksum. The installed executable is subsequently entrusted with Microsoft authentication tokens, the `PE_API_KEY`, system-keyring entries, Outlook messages, message bodies, recipients, and calendar information. It can also perform user-visible mutations such as sending or deleting messages and creating, updating, or deleting events. The network access itself is consist ...[truncated 2897 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: outlook-cli
description: Outlook / Microsoft 365 Secure API CLI for mail and calendar. Use when the user wants to read, search, or triage Outlook mail or calendar; sending, replying, forwarding, deleting, modifying, creating, updating, or responding require explicit user confirmation (m365-cli & Microsoft Graph secure outlook firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📧","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden outlook

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
name: outlook-cli
description: Outlook / Microsoft 365 Secure API CLI for mail and calendar. Use when the user wants to read, search, or triage Outlook mail or calendar; sending, replying, forwarding, deleting, modifying, creating, updating, or responding require explicit user confirmation (m365-cli & Microsoft Graph secure outlook firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📧","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden outlook

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
name: outlook-cli
description: Outlook / Microsoft 365 Secure API CLI for mail and calendar. Use when the user wants to read, search, or triage Outlook mail or calendar; sending, replying, forwarding, deleting, modifying, creating, updating, or responding require explicit user confirmation (m365-cli & Microsoft Graph secure outlook firewall alternative).
version: 1.0.8
metadata: {"openclaw":{"emoji":"📧","homepage":"https://porteden.com","requires":{"bins":["porteden"]},"primaryEnv":"PE_API_KEY","envVars":[{"name":"PE_API_KEY","required":false,"description":"API key; if unset, credentials are read from the system keyring via `porteden auth login`"}],"install":[{"id":"brew","kind":"brew","formula":"porteden/tap/porteden","bins":["porteden"],"label":"Install porteden (brew)"},{"id":"go","kind":"go","module":"github.com/porteden/cli/cmd/porteden@latest","bins":["porteden"],"label":"Install porteden (go)"}]}}
---

# porteden outlook

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The documented porteden auth login --token <key> pattern encourages passing a secret directly on the command line. Command-line arguments can be exposed via shell history, process listings, audit logs, or terminal recordings, which can leak long-lived API tokens to other local users or monitoring systems.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
## Setup (once)

- **Browser login (recommended):** `porteden auth login` — opens browser, sign in with the Microsoft account (personal, work, or school), credentials stored in system keyring
- **Direct token:** `porteden auth login --token <key>` — stored in system keyring
- **Verify:** `porteden auth status`
- If `PE_API_KEY` is set in the environment, the CLI uses it automatically (no login needed).

Static analysis

No suspicious patterns detected.