A Model Context Protocol (MCP) server for interacting with Microsoft 365 and Office services through the Graph API
88%
Total Score
healthy
Active development, broad contributor participation, and provenance support this release despite unpinned workflow actions.
TypeScript, Vitest, tsup, and npm scripts provide established build and test tooling; the repository reports no security scanning tools, a modest hygiene gap.
Version 0.159.1 is not yet on a stable major version, but it is a regular release rather than a prerelease and recent releases have no prerelease share.
Both workflows were fully analyzed with no untrusted checkouts or script injection, but all 9 action references are unpinned and both workflows install packages outside a lockfile, creating reproducibility and workflow-hygiene concerns.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-386947 @softeria/ms-365-mcp-server is vulnerable to Code Injection in versions 0.111.0 - 0.136.0. | 0.111.0 - 0.136.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
zod Version ^3.24.2 | — | — |
open Version ^11.0.0 | — | — |
dotenv Version ^17.0.1 | — | — |
helmet Version ^8.1.0 | — | — |
parse5 Version ^8.0.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.