microsoft-teams-automation
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes untrusted data from Microsoft Teams messages and search results.
- Ingestion points:
MICROSOFT_TEAMS_SEARCH_MESSAGES,MICROSOFT_TEAMS_GET_CHAT_MESSAGE, andMICROSOFT_TEAMS_TEAMS_LIST_CHANNELSinSKILL.md. - Boundary markers: No explicit delimiters or instructions to ignore embedded instructions are provided in the skill definitions.
- Capability inventory: The skill possesses capabilities to post messages via
MICROSOFT_TEAMS_TEAMS_POST_CHANNEL_MESSAGEandMICROSOFT_TEAMS_TEAMS_POST_CHAT_MESSAGE, and to create meetings viaMICROSOFT_TEAMS_CREATE_MEETING. - Sanitization: There is no evidence of content sanitization or validation for the data retrieved from Teams.
- [EXTERNAL_DOWNLOADS]: The skill instructs the user to configure an external MCP server at
https://rube.app/mcp.
Audit Metadata