microsoft-teams-automation

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes untrusted data from Microsoft Teams messages and search results.
  • Ingestion points: MICROSOFT_TEAMS_SEARCH_MESSAGES, MICROSOFT_TEAMS_GET_CHAT_MESSAGE, and MICROSOFT_TEAMS_TEAMS_LIST_CHANNELS in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded instructions are provided in the skill definitions.
  • Capability inventory: The skill possesses capabilities to post messages via MICROSOFT_TEAMS_TEAMS_POST_CHANNEL_MESSAGE and MICROSOFT_TEAMS_TEAMS_POST_CHAT_MESSAGE, and to create meetings via MICROSOFT_TEAMS_CREATE_MEETING.
  • Sanitization: There is no evidence of content sanitization or validation for the data retrieved from Teams.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to configure an external MCP server at https://rube.app/mcp.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 06:59 AM