one-drive-automation
Pass
Audited by Gen Agent Trust Hub on Mar 5, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it retrieves and processes content from OneDrive files.
- Ingestion points: Data enters the agent context through ONE_DRIVE_SEARCH_ITEMS, ONE_DRIVE_GET_ITEM, and ONE_DRIVE_ONEDRIVE_LIST_ITEMS.
- Boundary markers: No delimiters or instructions are provided to the agent to distinguish between its own instructions and content retrieved from files.
- Capability inventory: The agent has access to powerful tools such as ONE_DRIVE_DELETE_ITEM, ONE_DRIVE_INVITE_USER_TO_DRIVE_ITEM, and ONE_DRIVE_ONEDRIVE_UPLOAD_FILE.
- Sanitization: There is no mention of content sanitization or validation before the retrieved data is processed.
- [EXTERNAL_DOWNLOADS]: The skill references an external MCP server endpoint at https://rube.app/mcp.
Audit Metadata