outlook-hack
This skill reads and drafts emails in Outlook without sending them, ensuring safe email management and organization.
Install this skill
or
84/100
Security score
The outlook-hack skill was audited on Mar 10, 2026 and we found 4 security issues across 2 threat categories. Review the findings below before installing.
Categories Tested
Security Issues
medium line 14
Access to hidden dotfiles in home directory
SourceSKILL.md
| 14 | "security": "This skill captures Outlook Web session tokens via browser tab sharing to make direct REST calls to Microsoft's Outlook REST API v2.0. No API keys or admin approval needed. SENDING IS COD |
medium line 88
Access to hidden dotfiles in home directory
SourceSKILL.md
| 88 | **Output:** `~/.openclaw/workspace/data/outlook-emails/` |
medium line 109
Access to hidden dotfiles in home directory
SourceSKILL.md
| 109 | 4. Both this skill and `teams-hack` share `~/.openclaw/credentials/outlook-msal.json` (0600) |
low line 131
External URL reference
SourceSKILL.md
| 131 | Pair with [**whatsapp-ultimate**](https://clawhub.com/globalcaos/whatsapp-ultimate) for messaging and [**jarvis-voice**](https://clawhub.com/globalcaos/jarvis-voice) for voice. |
Scanned on Mar 10, 2026
View Security Dashboard