Join Microsoft 365 MCP Server (michelfritzschjoin/join-ms-365-mcp-server) is an MCP server listed on the M8ven Trust Index. It scores 0 out of 100, grade F. It declares 92 tools. No publisher has claimed this listing.

F
Warning
0/100

Join Microsoft 365 MCP Server

Enables AI assistants to seamlessly interact with Microsoft 365 services through the Graph API, featuring super tools, unified search, and intelligent learning.

Warning. Serious findings were identified. Review the full report before connecting. Grades reflect the full trust pyramid: code, verification depth, and reputation. New projects cap at C until adoption is earned.

How we verified

Code Verified⚡ Live Monitored: not connected

Verified is a snapshot. Live keeps it current, and builds your track record.

⚡ Connect GitHub → continuous verification on every pushwhy connect →

Who stands behind it

michelfritzschjoin

Source: Glama

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for our deepest verification, Live Monitored: read-only, revoke anytime. What we access →

Install from

The grade above is for the source repository. Registries can serve a different version, so we mark the ones we were not able to read.

// key findings
🚨
Reads files from sensitive locations
Touches: /.dockerenv, /.dockerenv
🚨
Known vulnerabilities in dependencies: 1 critical, 4 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 3 credentials: DASHBOARD_PASSWORD, MS365_MCP_CLIENT_SECRET, MS365_MCP_OAUTH_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies1 critical4 high1 medium25 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

criticalvitest@4.0.18GHSA-5xrq-8626-4rwp

When Vitest UI server is listening, arbitrary file can be read and executed

high@toon-format/toon@2.1.0GHSA-p95v-992w-h6c3

TOON: Prototype pollution when decoding untrusted TOON input

highhono@4.12.9GHSA-88fw-hqm2-52qc

hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard

highjs-yaml@4.1.1GHSA-52cp-r559-cp3m

js-yaml: YAML merge-key chains can force quadratic CPU consumption

highjs-yaml@4.1.1GHSA-5p4m-2wfm-xmqj

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// environment variables
To run this server yourself, you supply these values. They go in your own MCP client configuration and stay on your machine. The secret label means the value is sensitive, not that the server mishandles it.
🔐 secretDASHBOARD_PASSWORD
configENABLED_TOOLS
configFORCE_COLOR
configLOG_FORMAT
configLOG_LEVELLogging level / Logging-Level info
configMS365_MCP_ANONYMIZE_PIItrue
configMS365_MCP_AUTO_QUERY_OPTIMIZATION_ENABLED
configMS365_MCP_CALENDAR_DEFAULT_TIMEZONE
configMS365_MCP_CHAT_MEMORY_ENABLED
configMS365_MCP_CHAT_MEMORY_MAX_HISTORY
configMS365_MCP_CHAT_MEMORY_TTL
configMS365_MCP_CLIENT_IDRequired / Erforderlich
🔐 secretMS365_MCP_CLIENT_SECRETClient secret (confidential apps) / Client-Geheimnis (vertrauliche Apps) -
configMS365_MCP_CLOUD_TYPEglobal
configMS365_MCP_CORS_EXPOSED_HEADERS
configMS365_MCP_CORS_HEADERS
configMS365_MCP_CORS_MAX_AGE
configMS365_MCP_CORS_METHODS
configMS365_MCP_CORS_ORIGIN
configMS365_MCP_CORS_ORIGINS
configMS365_MCP_CSP
configMS365_MCP_CSP_DASHBOARD
configMS365_MCP_DEEP_RESEARCH_ITEMS_PER_ITERATION
configMS365_MCP_DEEP_RESEARCH_MAX_DEPTH
configMS365_MCP_ENABLE_DISCOVERY_TOOLS
configMS365_MCP_ENABLE_SELF_REPAIR
configMS365_MCP_FAST_MODE
configMS365_MCP_GRAPH_MAX_RETRIES
configMS365_MCP_GRAPH_REQUEST_TIMEOUT_MS
configMS365_MCP_GRAPH_RETRY_MAX_DELAY_MS
configMS365_MCP_HSTS_MAX_AGE
configMS365_MCP_INTENT_ENTITY_FILTER
configMS365_MCP_KEYVAULT_URLAzure Key Vault URL -
configMS365_MCP_KNOWLEDGE_BASE_PATH
configMS365_MCP_LEARNING_CLUSTER_ENABLED
configMS365_MCP_LEARNING_CLUSTER_THRESHOLD
configMS365_MCP_LEARNING_DECAY_DAYS
configMS365_MCP_LEARNING_DECAY_FACTOR
configMS365_MCP_LEARNING_ENABLED
configMS365_MCP_LEARNING_NLP_ENABLED
configMS365_MCP_LLM_OPTIMIZE
configMS365_MCP_MAX_AGGREGATE_ITEMS
configMS365_MCP_MAX_CONCURRENT_TOOLS
configMS365_MCP_MAX_PAGES
configMS365_MCP_MAX_QUERY_VARIANTS
configMS365_MCP_MAX_REPAIR_ATTEMPTS
configMS365_MCP_MAX_RESEARCH_ITERATIONS
configMS365_MCP_MAX_RESPONSE_CHARS
configMS365_MCP_MAX_RESULTS500
configMS365_MCP_MAX_SUMMARY_LENGTH
configMS365_MCP_MIN_RELEVANCE
configMS365_MCP_MULTIQUERY_TIMEOUT
🔐 secretMS365_MCP_OAUTH_TOKEN
configMS365_MCP_ORG_MODEfalse
configMS365_MCP_OUTPUT_FORMATjson
configMS365_MCP_PATTERN_LEARNING_ENABLED
configMS365_MCP_PATTERN_MIN_COUNT
configMS365_MCP_PERMISSIONS_POLICY
configMS365_MCP_QUERY_DECOMPOSITION_ENABLED
configMS365_MCP_QUERY_OPTIMIZATION_CONFIDENCE_THRESHOLD
configMS365_MCP_QUERY_OPTIMIZATION_MIN_PATTERN_COUNT
configMS365_MCP_RATE_LIMIT_MAX_REQUESTS
configMS365_MCP_RATE_LIMIT_WINDOW_MS
configMS365_MCP_READ_ONLY
configMS365_MCP_REFERRER_POLICY
configMS365_MCP_RELEVANCE_THRESHOLD
configMS365_MCP_REPAIR_STRATEGIES
configMS365_MCP_RESPONSE_ENVELOPE
configMS365_MCP_RESPONSE_FORMAT
configMS365_MCP_RESPONSE_SUMMARY_FIRST
configMS365_MCP_SEARCH_DEFAULT_ENTITY_TYPES
configMS365_MCP_SEARCH_LEARNED_VARIANTS
configMS365_MCP_SEARCH_MAX_CANDIDATES
configMS365_MCP_SEARCH_MAX_SYNONYM_VARIANTS
configMS365_MCP_SEARCH_PARALLEL_MERGE_COUNT
configMS365_MCP_SEARCH_SYNONYM_MERGE_THRESHOLD
configMS365_MCP_SEARCH_USE_OR_QUERY
configMS365_MCP_TENANT_IDcommon
configMS365_MCP_THINKING_ENABLED
configMS365_MCP_THINKING_LEVEL
configMS365_MCP_X_FRAME_OPTIONS
configNO_COLOR
configQUERY_STORE_DIR
configQUERY_STORE_MAX_QUERIES
configQUERY_STORE_RETENTION_DAYS
configREAD_ONLYEnglish: All Super-Tools respect the environment variable. Write operations (send, create, update, delete) are automatically blocked with clear error messages when read-only mode is enabled.
configSILENTDisable console output / Konsolenausgabe deaktivieren false
configTRUST_PROXY_COUNT
// quality suggestions

Tool annotations

80/92 tools have annotations

Add readOnlyHint or destructiveHint annotations to every tool so hosts can warn users before invoking.

All four hints declared on every tool

92/92 tools missing one or more hints — login (missing: idempotentHint); logout (missing: idempotentHint); verify-login (missing: idempotentHint), +89 more. OpenAI's directory rejects tools where any of the four hints are missing or non-boolean.

For every tool, set all four hints (readOnlyHint, destructiveHint, idempotentHint, openWorldHint) to explicit true/false values that match the handler’s actual behaviour.

Tool inputs are validated

67/92 tool handlers declare input schemas (73%)

Declare an inputSchema with zod/joi/yup on every tool definition.

Tool test coverage

Only 11/92 tools referenced in tests (12%)

Write tests that reference each tool by name so every tool has at least one test.

No access to sensitive paths

Reads sensitive paths: /.dockerenv, /.dockerenv

Remove reads of sensitive system paths. If you genuinely need them, document why in the README.

Shell command execution

4 calls in production code run through a shell (bin/modules/generate-mcp-tools.mjs:43, bin/check-generated.mjs:18, bin/check-generated.mjs:26)

Prefer library functions over shell-outs. If you must shell out, ensure all inputs are properly escaped.

Production dependencies are patched

0 critical, 4 high severity in production deps — @toon-format/toon@2.1.0 (high), hono@4.12.9 (high)

Run npm audit fix, or upgrade the affected packages to a non-vulnerable version.

Dev dependencies

1 critical/high in dev-only deps (does not ship to users)

Upgrade dev dependencies when convenient.

Claim the listing to review these findings one by one and send us a correction where you disagree, straight to the team. Claiming also means we tell you when the grade moves, and reach you first if we find anything urgent.

// full audit trail
The findings above are the summary. The full trail, every check we ran, each deduction, the network hosts observed and the dependency advisories, goes to verified publishers, along with an alert whenever a new one lands. Verified publishers can also review each finding and dispute it in one click. Publisher corrections have sharpened several of our checks this month, because the maintainer knows the codebase better than any scanner.
// improvement guidance — verified publishers only
We have 8 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Verified](https://m8ven.ai/badge/mcp/michelfritzschjoin/join-ms-365-mcp-server?variant=verified)](https://m8ven.ai/mcp/michelfritzschjoin/join-ms-365-mcp-server)
Shows verification status without the grade. Want the grade badge instead? Remove ?variant=verified from the URL.
commit: ebbb537ea363d4e29b6ce4064041dd61f240b71e
code hash: 2c24ac8f1c22cab50dd6a6b59560c47064208a4a3c7be68f3833512321a8697e
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client