AGENT LAB: SKILLS

outlook-calendar-automation

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • Indirect Prompt Injection (LOW): The skill is vulnerable to instructions embedded in calendar event data.
  • Ingestion points: OUTLOOK_LIST_EVENTS, OUTLOOK_GET_EVENT, and OUTLOOK_GET_CALENDAR_VIEW ingest event subjects and bodies.
  • Boundary markers: Absent; the skill does not define delimiters for untrusted calendar content.
  • Capability inventory: Includes tool calls to create, modify, and delete events (OUTLOOK_CALENDAR_CREATE_EVENT, OUTLOOK_UPDATE_CALENDAR_EVENT, OUTLOOK_DELETE_EVENT).
  • Sanitization: Absent; no input validation or escaping for external event data is specified.
  • External Dependency (LOW): The skill directs users to connect to https://rube.app/mcp, which is an external third-party service not included in the trusted source list.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:03 PM