Outlook MCP logo

Outlook MCP

Claimed

by ryaker

MCP server that connects Claude (and other MCP clients) to Microsoft 365 via Microsoft Graph — Outlook email/calendar, OneDrive files, and Power Automate flows.

Install

$git clone https://github.com/ryaker/outlook-mcp.git && cd outlook-mcp && npm install

Set up this server

This server needs project-specific setup. Follow the project instructions; no reusable public launch command is available yet.

Project instructions
claudeoutlookoutlook-365emailcalendarmicrosoft-365cloud-storageautomation

More in Productivity

Browse the full directory

Badge

Show this listing on your README and website

Get verified and your listing links back to your site with a do-follow link. The badge is optional while first-100 launch spots remain.

Security profile

Exposure: Extensive

Reaches several sensitive areas at once. Read the list before installing.

What this server can reach, from a static read of the shipped code. Nothing was executed and nothing here is a verdict: a browser tool has to run commands and an API wrapper has to call its API. Decide what fits your setup.

NVIDIA SkillSpector v2.11.0, MCPVault MCP-server policy. Scanned 5 days ago @ 95d6ff2.

Detected

  • Reads environment variables in bulk1 places

    Copies or enumerates the whole environment, which can include keys meant for other tools.

  • Sends conversation content outward3 places

    Logs or forwards prompts, messages or tool results to a service outside your machine.

  • Accesses credential files59 places

    References SSH keys, cloud credential files or token stores.

  • Reads local configuration files1 places

    Loads a .env, .npmrc or config file. Normal for a server that needs an API key.

  • Contains instructions aimed at AI agents1 places

    Text in code or agent-facing files that steers a model. Worth reading before you trust it.

  • Runs unpinned packages at runtime3 places

    Executes npx or uvx without a version, so a compromised upstream release would run.

Not detected: runs shell commands, reads or writes other agents' configuration, uses elevated privileges, installs itself to run later, matches a known malicious pattern.

Dependencies with known advisories

  • @modelcontextprotocol/inspector 0.10.2 Critical, CVE-2025-49596, CVE-2025-58444
  • brace-expansion 1.1.11 High, CVE-2026-13149, CVE-2026-33750, CVE-2026-14257
  • browserslist 4.28.1 High, CVE-2026-73088, CVE-2026-73089
  • express-rate-limit 8.2.1 High, CVE-2026-30827
  • fast-uri 3.1.0 High, CVE-2026-13676, CVE-2026-18446, CVE-2026-75975
  • form-data 4.0.5 High, CVE-2026-12143
  • hono 4.12.5 High, CVE-2026-56762, CVE-2026-47676, CVE-2026-47675
  • @babel/core 7.28.6 Low, CVE-2026-49356

4 more in the owner dashboard.

Left out of the profile

9 pattern matches in documentation, configuration or CI files were recorded but are not part of the profile, because they do not run when the server does. The owner dashboard lists them.

How the profile works Maintainers see file, line and a fix for each item in their dashboard.

29 of 29 tools

Documented tools (29)

From project documentation. A server handshake does not verify each tool’s description or behavior.

Tool change history

Compared across complete checks of the same configuration. Tools were listed, not invoked. Input-schema changes are not measured here.

No complete tool checks yet.

FAQ

Questions about Outlook MCP Server

How do I connect Outlook MCP Server to Claude?
The listing records `git clone https://github.com/ryaker/outlook-mcp.git && cd outlook-mcp && npm install` as its setup step. Run it, then follow the repository's instructions for the client configuration; the listing names Claude Desktop, Claude Code as compatible clients.
Is Outlook MCP Server free?
MCPVault has not verified a licence for this server. Check the upstream terms and pricing before use; connected APIs may require a paid account.
What can Outlook MCP Server do?
Outlook MCP Server documents 29 tools to the agent, including accept-event, create-event, create-folder. The descriptions above come from project documentation. A live handshake does not test individual tool behavior.