2
/ 100
1 month ago
glama

MCP Microsoft Office

Connects AI assistants to Microsoft 365 accounts to manage emails, calendars, files, and Teams messages. It offers 71 tools and supports multi-user environments through a secure, customizable server architecture.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
1 flow detected: CLAUDE_API_KEY. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 14 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 10 credentials: CLAUDE_API_KEY, DEVICE_REGISTRY_ENCRYPTION_KEY, JWT_SECRET, MCP_BEARER_TOKEN, MCP_ENCRYPTION_KEY, MCP_TOKEN_SECRET, MICROSOFT_CLIENT_SECRET, OPENAI_API_KEY, SESSION_SECRET, STATIC_JWT_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies14 high16 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highaxios@1.6.2GHSA-35jp-ww65-95wh

axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`

highaxios@1.6.2GHSA-3g43-6gmg-66jw

axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge

highaxios@1.6.2GHSA-43fc-jf86-j433

Axios is Vulnerable to Denial of Service via __proto__ Key in mergeConfig

highaxios@1.6.2GHSA-4hjh-wcwx-xvwj

Axios is vulnerable to DoS attack through lack of data size check

highaxios@1.6.2GHSA-6chq-wfr3-2hj9

Axios: Header Injection via Prototype Pollution

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configAPI_BASE_PATH
configAPI_HOST
configAPI_PORT
configAPI_TIMEOUT
🔐 secretCLAUDE_API_KEY
configCORS_ALLOWED_ORIGINSProduction Comma-separated allowed origins
configDEFAULT_TIMEZONE
🔐 secretDEVICE_REGISTRY_ENCRYPTION_KEYProduction 32-byte encryption key for token storage
configENABLE_HTTPS
configHOST
🔐 secretJWT_SECRETProduction Secret for signing JWT tokens
configLLM_PROVIDER
🔐 secretMCP_BEARER_TOKEN"": "paste-your-token-here",
configMCP_BEARER_TOKEN_EXPIRY
configMCP_DEBUGSet =1 in the env block to enable diagnostic logging to stderr — useful for troubleshooting tool dispatch issues.
🔐 secretMCP_ENCRYPTION_KEY
configMCP_LOG_PATH
configMCP_MODULES"": "search,mail,calendar,files,people,contacts,groups,query"
configMCP_SERVER_URL"": "http://localhost:3000",
configMCP_SILENT_MODE
configMCP_SKIP_INIT
🔐 secretMCP_TOKEN_SECRET
configMICROSOFT_CLIENT_IDyour-client-id
🔐 secretMICROSOFT_CLIENT_SECRET
configMICROSOFT_REDIRECT_URINo OAuth callback URL (default: http://localhost:3000/api/auth/callback)
configMICROSOFT_TENANT_IDyour-tenant-id
🔐 secretOPENAI_API_KEY
configPORTNo Server port (default: 3000)
configRATE_LIMIT_AUTH_MAX
configRATE_LIMIT_MAX
configRATE_LIMIT_WINDOW_MS
🔐 secretSESSION_SECRET
configSSL_CERT_PATH
configSSL_KEY_PATH
🔐 secretSTATIC_JWT_SECRET
configUSE_MOCK_DATA
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 4 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/aanerud-mcp-microsoft-office-1xmn5q)](https://m8ven.ai/mcp/aanerud-mcp-microsoft-office-1xmn5q)
commit: f5686fc37584c1ca3512a8696bfb0a64664a61bd
code hash: 4a25eca1d89196b6e00ec099b0b7fa381cb1f4fc999269fdefbacc27b5238c68
verified: 6/13/2026, 10:34:00 AM
view raw JSON →