{"id":"479dc23c-fdfa-4a05-be28-ad78b508d641","entityType":"agent","slug":"clawhub-sam2kb-m365-mcp","name":"m365-mcp","canonicalUrl":"https://www.xpersona.co/agent/clawhub-sam2kb-m365-mcp","canonicalPath":"/agent/clawhub-sam2kb-m365-mcp","generatedAt":"2026-10-11T04:34:49.380Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-11T02:26:53.929Z","emptyReason":null},"description":"Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. Skill: m365-mcp Owner: sam2kb Summary: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. Tags: latest:1.1.0 Version history: v1.1.0 | 2026-09-01T16:38:17.765Z | user Release v1.1.0 v1.0.8 | 2026-09-01T16:22:59.136Z | user Release v1.0.8 v1.0.7 | 2026-08-09T18:59:32.788Z |","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s17as61t77jh1v77gg4anjx6458arpac:m365-mcp","sourceUrl":"https://clawhub.ai/sam2kb/m365-mcp","homepage":"https://clawhub.ai/sam2kb/skills/m365-mcp","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/sam2kb/m365-mcp","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/sam2kb/skills/m365-mcp","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contact"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T02:26:53.929Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T02:26:53.929Z","emptyReason":null},"stars":null,"forks":null,"downloads":1189,"packageName":null,"latestVersion":"1.1.0","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T02:26:53.861Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T02:26:53.929Z","lastCrawledAt":"2026-10-11T02:26:53.861Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T02:26:53.861Z","lastVerifiedAt":null,"highlights":[{"version":"1.1.0","createdAt":"2026-09-01T16:38:17.765Z","changelog":"Release v1.1.0","fileCount":3,"zipByteSize":3529},{"version":"1.0.8","createdAt":"2026-09-01T16:22:59.136Z","changelog":"Release v1.0.8","fileCount":3,"zipByteSize":3373},{"version":"1.0.7","createdAt":"2026-08-09T18:59:32.788Z","changelog":"Release v1.0.7","fileCount":3,"zipByteSize":3455},{"version":"1.0.6","createdAt":"2026-07-19T14:17:07.952Z","changelog":"Release v1.0.6","fileCount":3,"zipByteSize":3287},{"version":"1.0.5","createdAt":"2026-07-19T02:41:33.613Z","changelog":"Release v1.0.5","fileCount":3,"zipByteSize":3340},{"version":"1.0.4","createdAt":"2026-07-19T02:03:44.756Z","changelog":"Release v1.0.4","fileCount":3,"zipByteSize":3173},{"version":"1.0.3","createdAt":"2026-07-19T01:31:18.825Z","changelog":"Release v1.0.3","fileCount":3,"zipByteSize":3234},{"version":"1.0.2","createdAt":"2026-07-19T00:44:51.582Z","changelog":"Release v1.0.2","fileCount":3,"zipByteSize":3164}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17as61t77jh1v77gg4anjx6458arpac:m365-mcp","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T04:34:49.377Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-sam2kb-m365-mcp/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-11T02:26:53.929Z","emptyReason":null},"readme":"Skill: m365-mcp\n\nOwner: sam2kb\n\nSummary: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\n\nTags: latest:1.1.0\n\nVersion history:\n\nv1.1.0 | 2026-09-01T16:38:17.765Z | user\n\nRelease v1.1.0\n\nv1.0.8 | 2026-09-01T16:22:59.136Z | user\n\nRelease v1.0.8\n\nv1.0.7 | 2026-08-09T18:59:32.788Z | user\n\nRelease v1.0.7\n\nv1.0.6 | 2026-07-19T14:17:07.952Z | user\n\nRelease v1.0.6\n\nv1.0.5 | 2026-07-19T02:41:33.613Z | user\n\nRelease v1.0.5\n\nv1.0.4 | 2026-07-19T02:03:44.756Z | user\n\nRelease v1.0.4\n\nv1.0.3 | 2026-07-19T01:31:18.825Z | user\n\nRelease v1.0.3\n\nv1.0.2 | 2026-07-19T00:44:51.582Z | user\n\nRelease v1.0.2\n\nv1.0.1 | 2026-07-18T23:58:02.400Z | user\n\nRelease v1.0.1\n\nv1.0.0 | 2026-07-18T19:29:05.693Z | user\n\nInitial release\n\nArchive index:\n\nArchive v1.1.0: 3 files, 3529 bytes\n\nFiles: skill-card.md (2335b), SKILL.md (4150b), _meta.json (127b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    envVars:\n      - name: M365_ACCOUNT\n        required: false\n        description: Optional account name selected from the local account store.\n      - name: M365_TIMEZONE\n        required: false\n        description: Optional IANA timezone for calendar operations; defaults to UTC.\n      - name: M365_MCP_AUTH_DIR\n        required: false\n        description: Optional absolute path for the local OAuth account and token store.\n      - name: M365_MCP_READ_ONLY\n        required: false\n        description: Set true to request read-only scopes and disable all mutating tools.\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (9 tools)\n\n- List events with organizer/response status, today view, week view, create (with Teams meeting), update, explicit organizer cancellation, attendee decline, free/busy\n\n### Contacts (12 tools)\n\n- Rich contact CRUD, exact category assignment and any/all filtering, category enumeration, folder-scoped contacts, contact-folder CRUD, and relevance-ranked People API recipient search across mailbox and optional directory sources. People results support fuzzy search, identity-type filters, relevance scores, and optional profile details. Private Outlook Contact Lists and their membership are not exposed by Microsoft Graph.\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Security and consent\n\n- The server contacts only Microsoft's OAuth and Graph services:\n  `login.microsoftonline.com` and `graph.microsoft.com`.\n- Device-code OAuth grants delegated access as the signed-in user. Read tools can\n  expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n- Send, reply, move, create, update, cancel, decline, and delete tools change real Microsoft 365\n  data. Configure the MCP client to require explicit user approval for those tools.\n- Tools publish standard MCP read-only, destructive, idempotent, and open-world\n  annotations so compatible clients can apply confirmation policies.\n- Set `M365_MCP_READ_ONLY=true` for an enforced least-privilege mode. It requests\n  read-only OAuth scopes, omits mutating tools from discovery, and rejects direct\n  calls to them.\n- Refresh and access tokens are stored as plaintext JSON under\n  `~/.m365-mcp/auth/` (or `M365_MCP_AUTH_DIR`), protected with directory mode\n  `0700` and file mode `0600` where supported. Protect that directory and revoke\n  the app's Microsoft account consent if a token or device is compromised.\n\n## Setup\n\nClawHub installs the prebuilt npm package automatically. For a manual install:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work\n```\n\nThen configure `m365-mcp` as a stdio MCP server in your client.\n\nSee the [project README](https://github.com/sam2kb/m365-mcp#readme) for the full Azure setup guide.\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1788280697765\n}\n\nFile v1.1.0:skill-card.md\n\n## Description:\n\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sam2kb](https://clawhub.ai/user/sam2kb)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to connect an MCP-capable agent to Microsoft 365 data and actions through delegated OAuth. It supports email, calendar, contacts, OneDrive, Teams, tasks, and user lookup workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The global npm executable is not pinned by the skill evidence, so installed behavior can change across releases.\n\nMitigation: Install only from the trusted npm publisher and pin the package version in managed environments when reproducibility is required.\n\nRisk: Microsoft OAuth tokens are stored as plaintext in the local auth directory.\n\nMitigation: Keep the auth directory out of synced or shared folders, restrict filesystem permissions, and revoke Microsoft app consent if the token store or device may be compromised.\n\nRisk: Granted permissions can expose or modify private Microsoft 365 mail, files, calendars, contacts, Teams chats, tasks, and user data.\n\nMitigation: Prefer M365_MCP_READ_ONLY=true unless write actions are required, and require explicit user confirmation for send, delete, update, move, cancel, and create tools.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/sam2kb/skills/m365-mcp)\n- [Project README](https://github.com/sam2kb/m365-mcp#readme)\n\n## Skill Output:\n\n**Output Type(s):** [Text, API calls, Configuration instructions]\n\n**Output Format:** [MCP tool responses and setup guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May expose or modify Microsoft 365 data depending on granted OAuth scopes, environment configuration, and selected tools.]\n\n## Skill Version(s):\n\n1.1.0 (source: release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.8: 3 files, 3373 bytes\n\nFiles: skill-card.md (2145b), SKILL.md (4059b), _meta.json (127b)\n\nFile v1.0.8:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 44 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    envVars:\n      - name: M365_ACCOUNT\n        required: false\n        description: Optional account name selected from the local account store.\n      - name: M365_TIMEZONE\n        required: false\n        description: Optional IANA timezone for calendar operations; defaults to UTC.\n      - name: M365_MCP_AUTH_DIR\n        required: false\n        description: Optional absolute path for the local OAuth account and token store.\n      - name: M365_MCP_READ_ONLY\n        required: false\n        description: Set true to request read-only scopes and disable all mutating tools.\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (7 tools)\n\n- List events, today view, week view, create (with Teams meeting), update, delete, free/busy\n\n### Contacts (12 tools)\n\n- Rich contact CRUD, exact category assignment and any/all filtering, category enumeration, folder-scoped contacts, contact-folder CRUD, and relevance-ranked People API recipient search across mailbox and optional directory sources. People results support fuzzy search, identity-type filters, relevance scores, and optional profile details. Private Outlook Contact Lists and their membership are not exposed by Microsoft Graph.\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Security and consent\n\n- The server contacts only Microsoft's OAuth and Graph services:\n  `login.microsoftonline.com` and `graph.microsoft.com`.\n- Device-code OAuth grants delegated access as the signed-in user. Read tools can\n  expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n- Send, reply, move, create, update, and delete tools change real Microsoft 365\n  data. Configure the MCP client to require explicit user approval for those tools.\n- Tools publish standard MCP read-only, destructive, idempotent, and open-world\n  annotations so compatible clients can apply confirmation policies.\n- Set `M365_MCP_READ_ONLY=true` for an enforced least-privilege mode. It requests\n  read-only OAuth scopes, omits mutating tools from discovery, and rejects direct\n  calls to them.\n- Refresh and access tokens are stored as plaintext JSON under\n  `~/.m365-mcp/auth/` (or `M365_MCP_AUTH_DIR`), protected with directory mode\n  `0700` and file mode `0600` where supported. Protect that directory and revoke\n  the app's Microsoft account consent if a token or device is compromised.\n\n## Setup\n\nClawHub installs the prebuilt npm package automatically. For a manual install:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work\n```\n\nThen configure `m365-mcp` as a stdio MCP server in your client.\n\nSee the [project README](https://github.com/sam2kb/m365-mcp#readme) for the full Azure setup guide.\n\nFile v1.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.0.8\",\n  \"publishedAt\": 1788279779136\n}\n\nFile v1.0.8:skill-card.md\n\n## Description:\n\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 44 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sam2kb](https://clawhub.ai/user/sam2kb)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to connect an MCP client to Microsoft 365 through delegated OAuth for mail, calendar, contacts, OneDrive, Teams, tasks, and user workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Delegated Microsoft 365 access can expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n\nMitigation: Install only when that account access is acceptable and use M365_MCP_READ_ONLY=true unless mutating actions are required.\n\nRisk: Send, create, update, move, and delete tools can change real Microsoft 365 data.\n\nMitigation: Require explicit confirmation for mutating tools in the MCP client.\n\nRisk: The local auth directory contains reusable OAuth tokens.\n\nMitigation: Treat the auth directory as sensitive and revoke Microsoft account consent if a token or device is compromised.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/sam2kb/skills/m365-mcp)\n- [Project README](https://github.com/sam2kb/m365-mcp#readme)\n\n## Skill Output:\n\n**Output Type(s):** [text, shell commands, configuration, API calls]\n\n**Output Format:** [MCP tool responses, Markdown setup guidance, and inline shell commands]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can read Microsoft 365 data and, unless read-only mode is enabled, perform send, create, update, move, and delete actions through delegated Microsoft Graph access.]\n\n## Skill Version(s):\n\n1.0.8 (source: release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.7: 3 files, 3455 bytes\n\nFiles: skill-card.md (2293b), SKILL.md (4059b), _meta.json (127b)\n\nFile v1.0.7:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 44 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    envVars:\n      - name: M365_ACCOUNT\n        required: false\n        description: Optional account name selected from the local account store.\n      - name: M365_TIMEZONE\n        required: false\n        description: Optional IANA timezone for calendar operations; defaults to UTC.\n      - name: M365_MCP_AUTH_DIR\n        required: false\n        description: Optional absolute path for the local OAuth account and token store.\n      - name: M365_MCP_READ_ONLY\n        required: false\n        description: Set true to request read-only scopes and disable all mutating tools.\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (7 tools)\n\n- List events, today view, week view, create (with Teams meeting), update, delete, free/busy\n\n### Contacts (12 tools)\n\n- Rich contact CRUD, exact category assignment and any/all filtering, category enumeration, folder-scoped contacts, contact-folder CRUD, and relevance-ranked People API recipient search across mailbox and optional directory sources. People results support fuzzy search, identity-type filters, relevance scores, and optional profile details. Private Outlook Contact Lists and their membership are not exposed by Microsoft Graph.\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Security and consent\n\n- The server contacts only Microsoft's OAuth and Graph services:\n  `login.microsoftonline.com` and `graph.microsoft.com`.\n- Device-code OAuth grants delegated access as the signed-in user. Read tools can\n  expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n- Send, reply, move, create, update, and delete tools change real Microsoft 365\n  data. Configure the MCP client to require explicit user approval for those tools.\n- Tools publish standard MCP read-only, destructive, idempotent, and open-world\n  annotations so compatible clients can apply confirmation policies.\n- Set `M365_MCP_READ_ONLY=true` for an enforced least-privilege mode. It requests\n  read-only OAuth scopes, omits mutating tools from discovery, and rejects direct\n  calls to them.\n- Refresh and access tokens are stored as plaintext JSON under\n  `~/.m365-mcp/auth/` (or `M365_MCP_AUTH_DIR`), protected with directory mode\n  `0700` and file mode `0600` where supported. Protect that directory and revoke\n  the app's Microsoft account consent if a token or device is compromised.\n\n## Setup\n\nClawHub installs the prebuilt npm package automatically. For a manual install:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work\n```\n\nThen configure `m365-mcp` as a stdio MCP server in your client.\n\nSee the [project README](https://github.com/sam2kb/m365-mcp#readme) for the full Azure setup guide.\n\nFile v1.0.7:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.0.7\",\n  \"publishedAt\": 1786301972788\n}\n\nFile v1.0.7:skill-card.md\n\n## Description:\n\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 44 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sam2kb](https://clawhub.ai/user/sam2kb)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nEmployees, developers, and agent operators use this skill to connect an MCP-capable agent to Microsoft 365 through delegated OAuth for mailbox, calendar, contact, OneDrive, Teams, task, and user workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Delegated Microsoft 365 access can expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n\nMitigation: Install only when delegated account access is acceptable, use least-privilege account choices, and enable M365_MCP_READ_ONLY=true when read access is sufficient.\n\nRisk: Send, update, move, create, and delete tools can change real Microsoft 365 data.\n\nMitigation: Require explicit client approval before mutating tools run, especially for send, update, delete, and move actions.\n\nRisk: OAuth tokens stored in the local auth directory can be abused if the device or token store is compromised.\n\nMitigation: Protect the auth directory, set a dedicated M365_MCP_AUTH_DIR when appropriate, and revoke Microsoft app consent after suspected compromise.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/sam2kb/skills/m365-mcp)\n- [Project README](https://github.com/sam2kb/m365-mcp#readme)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Markdown, Shell commands, Configuration]\n\n**Output Format:** [Markdown with inline shell commands and configuration guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May direct the agent to call MCP tools that read or mutate Microsoft 365 account data depending on configured permissions.]\n\n## Skill Version(s):\n\n1.0.7 (source: ClawHub release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.0.6: 3 files, 3287 bytes\n\nFiles: skill-card.md (2403b), SKILL.md (3771b), _meta.json (127b)\n\nFile v1.0.6:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 43 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    envVars:\n      - name: M365_ACCOUNT\n        required: false\n        description: Optional account name selected from the local account store.\n      - name: M365_TIMEZONE\n        required: false\n        description: Optional IANA timezone for calendar operations; defaults to UTC.\n      - name: M365_MCP_AUTH_DIR\n        required: false\n        description: Optional absolute path for the local OAuth account and token store.\n      - name: M365_MCP_READ_ONLY\n        required: false\n        description: Set true to request read-only scopes and disable all mutating tools.\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (7 tools)\n\n- List events, today view, week view, create (with Teams meeting), update, delete, free/busy\n\n### Contacts (11 tools)\n\n- Rich contact CRUD, exact category assignment and any/all filtering, category enumeration, folder-scoped contacts, and contact-folder CRUD\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Security and consent\n\n- The server contacts only Microsoft's OAuth and Graph services:\n  `login.microsoftonline.com` and `graph.microsoft.com`.\n- Device-code OAuth grants delegated access as the signed-in user. Read tools can\n  expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n- Send, reply, move, create, update, and delete tools change real Microsoft 365\n  data. Configure the MCP client to require explicit user approval for those tools.\n- Tools publish standard MCP read-only, destructive, idempotent, and open-world\n  annotations so compatible clients can apply confirmation policies.\n- Set `M365_MCP_READ_ONLY=true` for an enforced least-privilege mode. It requests\n  read-only OAuth scopes, omits mutating tools from discovery, and rejects direct\n  calls to them.\n- Refresh and access tokens are stored as plaintext JSON under\n  `~/.m365-mcp/auth/` (or `M365_MCP_AUTH_DIR`), protected with directory mode\n  `0700` and file mode `0600` where supported. Protect that directory and revoke\n  the app's Microsoft account consent if a token or device is compromised.\n\n## Setup\n\nClawHub installs the prebuilt npm package automatically. For a manual install:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work\n```\n\nThen configure `m365-mcp` as a stdio MCP server in your client.\n\nSee the [project README](https://github.com/sam2kb/m365-mcp#readme) for the full Azure setup guide.\n\nFile v1.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.0.6\",\n  \"publishedAt\": 1784470627952\n}\n\nFile v1.0.6:skill-card.md\n\n## Description: <br>\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 43 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sam2kb](https://clawhub.ai/user/sam2kb) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operators use this skill to connect an agent client to Microsoft 365 through a stdio MCP server with delegated OAuth. It supports email, calendar, contacts, OneDrive, Teams, tasks, and user-directory workflows while preserving per-user consent. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Delegated Microsoft 365 access can expose private mail, files, calendars, contacts, Teams chats, tasks, and user data. <br>\nMitigation: Install only when delegated Microsoft 365 access is appropriate for the configured account and prefer M365_MCP_READ_ONLY=true unless write actions are required. <br>\nRisk: Mutating tools can send, move, create, update, or delete real Microsoft 365 data. <br>\nMitigation: Require explicit user confirmation for mutating tools in the MCP client before execution. <br>\nRisk: Local OAuth refresh and access tokens are sensitive secrets. <br>\nMitigation: Protect the configured auth directory and revoke Microsoft account consent if token files or the device may be exposed. <br>\n\n\n## Reference(s): <br>\n- [Project README](https://github.com/sam2kb/m365-mcp#readme) <br>\n- [ClawHub skill page](https://clawhub.ai/sam2kb/skills/m365-mcp) <br>\n- [Publisher profile](https://clawhub.ai/user/sam2kb) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, shell commands, configuration] <br>\n**Output Format:** [Markdown with inline shell commands and configuration notes] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May include MCP client setup steps, environment-variable guidance, and consent-risk notes.] <br>\n\n## Skill Version(s): <br>\n1.0.6 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.5: 3 files, 3340 bytes\n\nFiles: skill-card.md (2430b), SKILL.md (3735b), _meta.json (127b)\n\nFile v1.0.5:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 42 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    envVars:\n      - name: M365_ACCOUNT\n        required: false\n        description: Optional account name selected from the local account store.\n      - name: M365_TIMEZONE\n        required: false\n        description: Optional IANA timezone for calendar operations; defaults to UTC.\n      - name: M365_MCP_AUTH_DIR\n        required: false\n        description: Optional absolute path for the local OAuth account and token store.\n      - name: M365_MCP_READ_ONLY\n        required: false\n        description: Set true to request read-only scopes and disable all mutating tools.\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (7 tools)\n\n- List events, today view, week view, create (with Teams meeting), update, delete, free/busy\n\n### Contacts (10 tools)\n\n- Rich contact CRUD, category assignment and filtering, folder-scoped contacts, and contact-folder CRUD\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Security and consent\n\n- The server contacts only Microsoft's OAuth and Graph services:\n  `login.microsoftonline.com` and `graph.microsoft.com`.\n- Device-code OAuth grants delegated access as the signed-in user. Read tools can\n  expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n- Send, reply, move, create, update, and delete tools change real Microsoft 365\n  data. Configure the MCP client to require explicit user approval for those tools.\n- Tools publish standard MCP read-only, destructive, idempotent, and open-world\n  annotations so compatible clients can apply confirmation policies.\n- Set `M365_MCP_READ_ONLY=true` for an enforced least-privilege mode. It requests\n  read-only OAuth scopes, omits mutating tools from discovery, and rejects direct\n  calls to them.\n- Refresh and access tokens are stored as plaintext JSON under\n  `~/.m365-mcp/auth/` (or `M365_MCP_AUTH_DIR`), protected with directory mode\n  `0700` and file mode `0600` where supported. Protect that directory and revoke\n  the app's Microsoft account consent if a token or device is compromised.\n\n## Setup\n\nClawHub installs the prebuilt npm package automatically. For a manual install:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work\n```\n\nThen configure `m365-mcp` as a stdio MCP server in your client.\n\nSee the [project README](https://github.com/sam2kb/m365-mcp#readme) for the full Azure setup guide.\n\nFile v1.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.0.5\",\n  \"publishedAt\": 1784428893613\n}\n\nFile v1.0.5:skill-card.md\n\n## Description: <br>\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 42 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sam2kb](https://clawhub.ai/user/sam2kb) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use this skill to connect an MCP client to Microsoft 365 with delegated OAuth, then work with email, calendar, contacts, OneDrive, Teams, tasks, and user profile data through documented tools. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Delegated Microsoft 365 access can expose private mail, files, calendars, contacts, Teams chats, tasks, and user data. <br>\nMitigation: Install only when that access is acceptable, grant only needed Microsoft Graph permissions, and use M365_MCP_READ_ONLY=true unless write actions are required. <br>\nRisk: Send, reply, move, create, update, and delete tools can modify real Microsoft 365 data. <br>\nMitigation: Require explicit client confirmation for mutating tools and prefer read-only mode for review, browsing, and retrieval workflows. <br>\nRisk: OAuth refresh and access tokens are stored locally and can be misused if the auth directory is shared, backed up, or compromised. <br>\nMitigation: Protect M365_MCP_AUTH_DIR, keep it out of backups and shared folders, and revoke app consent if the device or token store may be compromised. <br>\n\n\n## Reference(s): <br>\n- [Project README](https://github.com/sam2kb/m365-mcp#readme) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands and MCP configuration details] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Tool results may expose Microsoft 365 account data or perform account changes depending on granted scopes and client confirmation policy.] <br>\n\n## Skill Version(s): <br>\n1.0.5 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.4: 3 files, 3173 bytes\n\nFiles: skill-card.md (2244b), SKILL.md (3675b), _meta.json (127b)\n\nFile v1.0.4:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    envVars:\n      - name: M365_ACCOUNT\n        required: false\n        description: Optional account name selected from the local account store.\n      - name: M365_TIMEZONE\n        required: false\n        description: Optional IANA timezone for calendar operations; defaults to UTC.\n      - name: M365_MCP_AUTH_DIR\n        required: false\n        description: Optional absolute path for the local OAuth account and token store.\n      - name: M365_MCP_READ_ONLY\n        required: false\n        description: Set true to request read-only scopes and disable all mutating tools.\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (7 tools)\n\n- List events, today view, week view, create (with Teams meeting), update, delete, free/busy\n\n### Contacts (6 tools)\n\n- List, search, read, create, update, delete\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Security and consent\n\n- The server contacts only Microsoft's OAuth and Graph services:\n  `login.microsoftonline.com` and `graph.microsoft.com`.\n- Device-code OAuth grants delegated access as the signed-in user. Read tools can\n  expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n- Send, reply, move, create, update, and delete tools change real Microsoft 365\n  data. Configure the MCP client to require explicit user approval for those tools.\n- Tools publish standard MCP read-only, destructive, idempotent, and open-world\n  annotations so compatible clients can apply confirmation policies.\n- Set `M365_MCP_READ_ONLY=true` for an enforced least-privilege mode. It requests\n  read-only OAuth scopes, omits mutating tools from discovery, and rejects direct\n  calls to them.\n- Refresh and access tokens are stored as plaintext JSON under\n  `~/.m365-mcp/auth/` (or `M365_MCP_AUTH_DIR`), protected with directory mode\n  `0700` and file mode `0600` where supported. Protect that directory and revoke\n  the app's Microsoft account consent if a token or device is compromised.\n\n## Setup\n\nClawHub installs the prebuilt npm package automatically. For a manual install:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work\n```\n\nThen configure `m365-mcp` as a stdio MCP server in your client.\n\nSee the [project README](https://github.com/sam2kb/m365-mcp#readme) for the full Azure setup guide.\n\nFile v1.0.4:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.0.4\",\n  \"publishedAt\": 1784426624756\n}\n\nFile v1.0.4:skill-card.md\n\n## Description: <br>\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sam2kb](https://clawhub.ai/user/sam2kb) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to connect agents to delegated Microsoft 365 workflows for email, calendar, contacts, OneDrive, Teams, tasks, and user lookup. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Delegated Microsoft 365 access can expose private mail, files, calendars, contacts, Teams chats, tasks, and user data. <br>\nMitigation: Install only when delegated Microsoft 365 access is acceptable and use read-only mode unless write actions are required. <br>\nRisk: Send, create, update, move, and delete actions can change real Microsoft 365 data. <br>\nMitigation: Require explicit user approval for mutating tools and prefer read-only scopes for routine use. <br>\nRisk: OAuth tokens are stored locally in plaintext. <br>\nMitigation: Protect the local auth directory from backups and other users, and revoke Microsoft consent if the token store or device may be compromised. <br>\n\n\n## Reference(s): <br>\n- [m365-mcp project README](https://github.com/sam2kb/m365-mcp#readme) <br>\n- [ClawHub skill page](https://clawhub.ai/sam2kb/skills/m365-mcp) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and MCP tool-response text] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Uses delegated Microsoft 365 access; mutating actions should require explicit approval.] <br>\n\n## Skill Version(s): <br>\n1.0.4 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.3: 3 files, 3234 bytes\n\nFiles: skill-card.md (2323b), SKILL.md (3675b), _meta.json (127b)\n\nFile v1.0.3:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    envVars:\n      - name: M365_ACCOUNT\n        required: false\n        description: Optional account name selected from the local account store.\n      - name: M365_TIMEZONE\n        required: false\n        description: Optional IANA timezone for calendar operations; defaults to UTC.\n      - name: M365_MCP_AUTH_DIR\n        required: false\n        description: Optional absolute path for the local OAuth account and token store.\n      - name: M365_MCP_READ_ONLY\n        required: false\n        description: Set true to request read-only scopes and disable all mutating tools.\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (7 tools)\n\n- List events, today view, week view, create (with Teams meeting), update, delete, free/busy\n\n### Contacts (6 tools)\n\n- List, search, read, create, update, delete\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Security and consent\n\n- The server contacts only Microsoft's OAuth and Graph services:\n  `login.microsoftonline.com` and `graph.microsoft.com`.\n- Device-code OAuth grants delegated access as the signed-in user. Read tools can\n  expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n- Send, reply, move, create, update, and delete tools change real Microsoft 365\n  data. Configure the MCP client to require explicit user approval for those tools.\n- Tools publish standard MCP read-only, destructive, idempotent, and open-world\n  annotations so compatible clients can apply confirmation policies.\n- Set `M365_MCP_READ_ONLY=true` for an enforced least-privilege mode. It requests\n  read-only OAuth scopes, omits mutating tools from discovery, and rejects direct\n  calls to them.\n- Refresh and access tokens are stored as plaintext JSON under\n  `~/.m365-mcp/auth/` (or `M365_MCP_AUTH_DIR`), protected with directory mode\n  `0700` and file mode `0600` where supported. Protect that directory and revoke\n  the app's Microsoft account consent if a token or device is compromised.\n\n## Setup\n\nClawHub installs the prebuilt npm package automatically. For a manual install:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work\n```\n\nThen configure `m365-mcp` as a stdio MCP server in your client.\n\nSee the [project README](https://github.com/sam2kb/m365-mcp#readme) for the full Azure setup guide.\n\nFile v1.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.0.3\",\n  \"publishedAt\": 1784424678825\n}\n\nFile v1.0.3:skill-card.md\n\n## Description: <br>\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sam2kb](https://clawhub.ai/user/sam2kb) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use this skill to connect an MCP-compatible agent to a delegated Microsoft 365 account for email, calendar, contacts, OneDrive, Teams, tasks, and user lookup workflows. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Delegated Microsoft 365 access can expose private mail, files, calendars, contacts, Teams chats, tasks, and user data. <br>\nMitigation: Install only when the agent is trusted with the selected account and use M365_MCP_READ_ONLY=true when write access is not required. <br>\nRisk: Send, delete, update, move, and create tools can change real Microsoft 365 data. <br>\nMitigation: Configure the MCP client to require explicit user confirmation before mutating tools run. <br>\nRisk: Locally stored OAuth tokens can grant usable account access if the auth directory is exposed. <br>\nMitigation: Protect or relocate the M365_MCP_AUTH_DIR token store and revoke Microsoft account consent if tokens or the device are compromised. <br>\n\n\n## Reference(s): <br>\n- [Project README](https://github.com/sam2kb/m365-mcp#readme) <br>\n- [ClawHub Skill Page](https://clawhub.ai/sam2kb/skills/m365-mcp) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, API Calls, Configuration] <br>\n**Output Format:** [MCP tool results and setup guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May read private Microsoft 365 content or perform send, delete, create, update, and move actions depending on configured scopes and user approvals.] <br>\n\n## Skill Version(s): <br>\n1.0.3 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.2: 3 files, 3164 bytes\n\nFiles: skill-card.md (2164b), SKILL.md (3675b), _meta.json (127b)\n\nFile v1.0.2:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    envVars:\n      - name: M365_ACCOUNT\n        required: false\n        description: Optional account name selected from the local account store.\n      - name: M365_TIMEZONE\n        required: false\n        description: Optional IANA timezone for calendar operations; defaults to UTC.\n      - name: M365_MCP_AUTH_DIR\n        required: false\n        description: Optional absolute path for the local OAuth account and token store.\n      - name: M365_MCP_READ_ONLY\n        required: false\n        description: Set true to request read-only scopes and disable all mutating tools.\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (7 tools)\n\n- List events, today view, week view, create (with Teams meeting), update, delete, free/busy\n\n### Contacts (6 tools)\n\n- List, search, read, create, update, delete\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Security and consent\n\n- The server contacts only Microsoft's OAuth and Graph services:\n  `login.microsoftonline.com` and `graph.microsoft.com`.\n- Device-code OAuth grants delegated access as the signed-in user. Read tools can\n  expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n- Send, reply, move, create, update, and delete tools change real Microsoft 365\n  data. Configure the MCP client to require explicit user approval for those tools.\n- Tools publish standard MCP read-only, destructive, idempotent, and open-world\n  annotations so compatible clients can apply confirmation policies.\n- Set `M365_MCP_READ_ONLY=true` for an enforced least-privilege mode. It requests\n  read-only OAuth scopes, omits mutating tools from discovery, and rejects direct\n  calls to them.\n- Refresh and access tokens are stored as plaintext JSON under\n  `~/.m365-mcp/auth/` (or `M365_MCP_AUTH_DIR`), protected with directory mode\n  `0700` and file mode `0600` where supported. Protect that directory and revoke\n  the app's Microsoft account consent if a token or device is compromised.\n\n## Setup\n\nClawHub installs the prebuilt npm package automatically. For a manual install:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work\n```\n\nThen configure `m365-mcp` as a stdio MCP server in your client.\n\nSee the [project README](https://github.com/sam2kb/m365-mcp#readme) for the full Azure setup guide.\n\nFile v1.0.2:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.0.2\",\n  \"publishedAt\": 1784421891582\n}\n\nFile v1.0.2:skill-card.md\n\n## Description: <br>\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sam2kb](https://clawhub.ai/user/sam2kb) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nEmployees, developers, and agent operators use this skill to connect an agent to delegated Microsoft 365 workflows for mail, calendar, contacts, OneDrive, Teams, tasks, and user lookup. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill can read and modify real Microsoft 365 data through delegated OAuth consent. <br>\nMitigation: Install only for accounts appropriate for agent access, prefer M365_MCP_READ_ONLY=true unless write tools are required, and require approval for send, create, update, and delete actions. <br>\nRisk: OAuth access and refresh tokens are stored in a local auth directory. <br>\nMitigation: Protect the auth directory, set a dedicated M365_MCP_AUTH_DIR when needed, and revoke Microsoft consent if the device or token store may be compromised. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill listing](https://clawhub.ai/sam2kb/skills/m365-mcp) <br>\n- [m365-mcp project README](https://github.com/sam2kb/m365-mcp#readme) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and configuration guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May return Microsoft 365 account data through MCP tools depending on granted delegated permissions and read-only configuration.] <br>\n\n## Skill Version(s): <br>\n1.0.2 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.1: 3 files, 2382 bytes\n\nFiles: skill-card.md (2001b), SKILL.md (1992b), _meta.json (127b)\n\nFile v1.0.1:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (7 tools)\n\n- List events, today view, week view, create (with Teams meeting), update, delete, free/busy\n\n### Contacts (6 tools)\n\n- List, search, read, create, update, delete\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Setup\n\nClawHub installs the prebuilt npm package automatically. For a manual install:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work\n```\n\nThen configure `m365-mcp` as a stdio MCP server in your client.\n\nSee the [project README](https://github.com/sam2kb/m365-mcp#readme) for the full Azure setup guide.\n\nFile v1.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.0.1\",\n  \"publishedAt\": 1784419082400\n}\n\nFile v1.0.1:skill-card.md\n\n## Description: <br>\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sam2kb](https://clawhub.ai/user/sam2kb) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operators use this skill to connect an agent to Microsoft 365 through an MCP server for email, calendar, contacts, OneDrive, Teams, tasks, and user-profile workflows. It is intended for environments where delegated OAuth and Microsoft Graph permissions are configured for the connected account. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Connected agents may read, send, delete, or update Microsoft 365 data depending on granted Graph permissions. <br>\nMitigation: Use least-privilege delegated permissions, avoid unnecessary highly privileged accounts, and require explicit user confirmation before sending messages, deleting items, or updating organizational data. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/sam2kb/skills/m365-mcp) <br>\n- [Project README](https://github.com/sam2kb/m365-mcp#readme) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Guidance, Configuration instructions, Shell commands] <br>\n**Output Format:** [Markdown with inline shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The skill guides setup of an MCP server and account authentication for Microsoft 365 access.] <br>\n\n## Skill Version(s): <br>\n1.0.1 (source: release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v1.0.0: 28 files, 66187 bytes\n\nFiles: LICENSE (1065b), package-lock.json (93930b), package.json (1086b), README.md (7795b), skill-card.md (2374b), SKILL.md (1610b), src/__tests__/auth.test.ts (11227b), src/__tests__/calendar.test.ts (4913b), src/__tests__/contacts.test.ts (2895b), src/__tests__/files.test.ts (4308b), src/__tests__/graph.test.ts (11265b), src/__tests__/mail.test.ts (6023b), src/__tests__/teams-tasks-users.test.ts (7818b), src/auth-cli.ts (4634b), src/auth.ts (11663b), src/graph.ts (6882b), src/index.ts (6922b), src/tools/calendar.ts (12205b), src/tools/contacts.ts (6417b), src/tools/files.ts (4958b), src/tools/mail.ts (10539b), src/tools/tasks.ts (5351b), src/tools/teams.ts (2836b), src/tools/users.ts (2601b), src/types.ts (3421b), tsconfig.json (470b), vitest.config.ts (196b), _meta.json (127b)\n\nFile v1.0.0:SKILL.md\n\n---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (7 tools)\n- List events, today view, week view, create (with Teams meeting), update, delete, free/busy\n\n### Contacts (6 tools)\n- List, search, read, create, update, delete\n\n### OneDrive (5 tools)\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n- List org users, profile lookup, manager lookup\n\n## Setup\n\n```bash\ncd m365-mcp\nnpm install\nnpm run build\n\n# Add account\nnode dist/auth-cli.js add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nnode dist/auth-cli.js login --account=work\n```\n\nThen configure as an MCP server in your mcporter config.\n\nSee [README.md](README.md) for full Azure setup guide.\n\n## License\n\nMIT\n\nFile v1.0.0:README.md\n\n# m365-mcp\n\n**Production-grade Microsoft 365 MCP server** — Email, Calendar, Contacts, OneDrive, Teams, Tasks, and Users via delegated OAuth.\n\nBuilt from the best of both `office365-connector` (delegated OAuth, multi-account) and `mcp-microsoft365` (MCP protocol, full scope), with all the gaps fixed: pagination, rate limiting, retry logic, proper timezone handling, and TypeScript throughout.\n\n## Why this exists\n\n| Feature | mcp-microsoft365 | office365-connector | **m365-mcp** |\n|---|---|---|---|\n| Auth model | Client credentials (tenant-wide) | Delegated (device code) | **Delegated (device code)** ✅ |\n| MCP server | ✅ | ❌ (CLI scripts) | ✅ |\n| Multi-account | ❌ | ✅ | ✅ |\n| Pagination | ❌ | ❌ | ✅ |\n| Rate limit handling | ❌ | Partial | ✅ |\n| Email | ✅ | ✅ | ✅ |\n| Calendar | ✅ | ✅ | ✅ |\n| Contacts | ❌ | ✅ | ✅ |\n| OneDrive | ✅ | ❌ | ✅ |\n| Teams | ✅ | ❌ | ✅ |\n| Tasks | ✅ | ❌ | ✅ |\n| Users | ✅ | ❌ | ✅ |\n| TypeScript | ✅ | ❌ (JS) | ✅ |\n| **Total tools** | 19 | ~12 (CLI) | **38** |\n\n## Scope\n\n**Delegated permissions** — the app acts AS YOU, not as the tenant. It can only access YOUR data:\n\n- `Mail.Read` / `Mail.ReadWrite` / `Mail.Send`\n- `Calendars.Read` / `Calendars.ReadWrite`\n- `Contacts.Read` / `Contacts.ReadWrite`\n- `Files.Read.All` (your OneDrive)\n- `Tasks.ReadWrite` (To Do)\n- `Chat.Read` / `Chat.ReadWrite` (Teams)\n- `User.Read` + `offline_access`\n\nNo tenant-wide `Mail.Read.All` or `Files.Read.All` needed.\n\n## Setup\n\n### 1. Create Azure Entra ID App Registration\n\n1. Go to [Azure Portal → App registrations](https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationsListBlade)\n2. **New registration**\n   - Name: `m365-mcp`\n   - Supported account types: **Single tenant** (or multi-tenant if you manage your own tenant)\n   - Redirect URI: `http://localhost` (not used for device code, but required)\n3. Click **Register**\n4. Go to **Authentication** → **Advanced settings** → set **\"Allow public client flows\"** to **Yes** → **Save**\n   > This is required for device-code OAuth to work without a client secret.\n\n### 2. Add API Permissions\n\nUnder **API Permissions** → **Add a permission** → **Microsoft Graph** → **Delegated permissions**:\n\n```\noffline_access\nUser.Read\nMail.Read\nMail.ReadWrite\nMail.Send\nCalendars.Read\nCalendars.ReadWrite\nContacts.Read\nContacts.ReadWrite\nFiles.Read.All\nTasks.ReadWrite\nChat.Read\nChat.ReadWrite\n```\n\nClick **Grant admin consent** (or each user will consent individually during login).\n\n> Organization-wide user listing and lookup additionally requires delegated `User.Read.All` with admin consent. This broader scope is not requested by default.\n\n### 3. Install\n\nInstall the published command-line tools:\n\n```bash\nnpm install --global @sam2kb/m365-mcp\n```\n\nOr build from source:\n\n```bash\n# Clone\ngit clone https://github.com/sam2kb/m365-mcp.git\ncd m365-mcp\n\n# Install dependencies\nnpm install\n\n# Build\nnpm run build\n```\n\n### 4. Add Your Account & Authenticate\n\n```bash\nm365-mcp-auth add work <tenant-id> <client-id> you@company.com \"Work account\"\nm365-mcp-auth login --account=work\n```\n\nWhen running from a source checkout, use `node dist/auth-cli.js` instead of\n`m365-mcp-auth`.\n\nFollow the on-screen URL + code to sign in. Tokens are stored securely in `~/.m365-mcp/auth/` by default. Set `M365_MCP_AUTH_DIR` to use another location.\n\n### 5. Configure an MCP Client\n\nThe server uses standard MCP over stdio and works with any MCP client (Claude Desktop, Cursor, Continue, etc.).\n\n#### OpenClaw\n\nFor the global npm installation, add this to your mcporter config at `~/.openclaw/mcporter.json`:\n\n```json\n{\n  \"mcpServers\": {\n    \"m365\": {\n      \"command\": \"m365-mcp\",\n      \"args\": [],\n      \"env\": {\n        \"M365_ACCOUNT\": \"work\",\n        \"M365_TIMEZONE\": \"America/Chicago\"\n      }\n    }\n  }\n}\n```\n\nOr via mcporter CLI:\n\n```bash\nmcporter config add m365 --stdio \"m365-mcp\" \\\n  --env M365_ACCOUNT=work \\\n  --env M365_TIMEZONE=America/Chicago\n```\n\nFor a source checkout, use `\"command\": \"node\"` with\n`\"args\": [\"/absolute/path/to/m365-mcp/dist/index.js\"]`.\n\nThen restart OpenClaw for the server to load.\n\n#### Other MCP Clients\n\nUse the same JSON config in your client's MCP server configuration — `m365-mcp` is a standard stdio MCP server with no client-specific requirements.\n\n## Multi-Account\n\n```bash\n# Add more accounts\nnode dist/auth-cli.js add personal <tenant2> <client2> you@outlook.com \"Personal\"\nnode dist/auth-cli.js add client <tenant3> <client3> you@client.com \"Consulting\"\n\n# Authenticate each\nnode dist/auth-cli.js login --account=personal\nnode dist/auth-cli.js login --account=client\n\n# Set default\nnode dist/auth-cli.js default work\n\n# List\nnode dist/auth-cli.js list\n```\n\nEach account needs its own App Registration in its respective tenant. Tokens are isolated per account.\n\n## Available Tools (38)\n\n### 📧 Mail (9 tools)\n| Tool | Description |\n|---|---|\n| `m365_mail_list` | List emails (folder, filter, search, paginated) |\n| `m365_mail_read` | Read full email by ID |\n| `m365_mail_send` | Send email (to/cc/bcc, HTML or plain) |\n| `m365_mail_reply` | Reply / reply-all to an email |\n| `m365_mail_search` | Search emails across folders |\n| `m365_mail_move` | Move email to another folder |\n| `m365_mail_delete` | Delete email |\n| `m365_mail_mark_read` | Mark as read/unread |\n| `m365_mail_folders` | List all mail folders with counts |\n\n### 📅 Calendar (7 tools)\n| Tool | Description |\n|---|---|\n| `m365_calendar_list` | Events in a date range (paginated) |\n| `m365_calendar_today` | Today's events, nicely formatted |\n| `m365_calendar_week` | Week view grouped by day |\n| `m365_calendar_create` | Create event (optional Teams meeting) |\n| `m365_calendar_update` | Update event |\n| `m365_calendar_delete` | Cancel event with message |\n| `m365_calendar_availability` | Free/busy lookup |\n\n### 👤 Contacts (6 tools)\n| Tool | Description |\n|---|---|\n| `m365_contacts_list` | List contacts |\n| `m365_contacts_search` | Search by name/email/company |\n| `m365_contacts_read` | Full contact details |\n| `m365_contacts_create` | Create contact |\n| `m365_contacts_update` | Update contact |\n| `m365_contacts_delete` | Delete contact |\n\n### 📁 OneDrive (5 tools)\n| Tool | Description |\n|---|---|\n| `m365_files_list` | List files/folders (paginated) |\n| `m365_files_search` | Search files |\n| `m365_files_read` | Read text file content |\n| `m365_files_info` | File/folder metadata |\n| `m365_files_create_folder` | Create folder |\n\n### 💬 Teams (3 tools)\n| Tool | Description |\n|---|---|\n| `m365_teams_chats` | List your chats |\n| `m365_teams_messages` | Get chat messages |\n| `m365_teams_send` | Send chat message |\n\n### ✅ Tasks (5 tools)\n| Tool | Description |\n|---|---|\n| `m365_tasks_lists` | List To Do lists |\n| `m365_tasks_list` | List tasks in a list |\n| `m365_tasks_create` | Create task |\n| `m365_tasks_update` | Update task |\n| `m365_tasks_delete` | Delete task |\n\n### 👥 Users (3 tools)\n| Tool | Description |\n|---|---|\n| `m365_users_list` | List org users |\n| `m365_users_profile` | Get user profile |\n| `m365_users_manager` | Get user's manager |\n\n## Development\n\n```bash\nnpm install\nnpm run dev    # tsx watch mode\nnpm run build  # compile TypeScript\n```\n\n## Security\n\n- **Delegated OAuth** — app acts as the authenticated user. No tenant-wide access.\n- **Device code flow** — you never type your password into anything but Microsoft's login page.\n- **Tokens stored with 0600 permissions** in `~/.m365-mcp/auth/` by default, configurable with `M365_MCP_AUTH_DIR`.\n- **Auto-refresh** — tokens refreshed before expiry, expired refresh tokens trigger re-auth.\n- **No telemetry, no analytics, no third-party calls** besides `login.microsoftonline.com` and `graph.microsoft.com`.\n\n## License\n\nMIT\n\nFile v1.0.0:_meta.json\n\n{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.0.0\",\n  \"publishedAt\": 1784402945693\n}\n\nFile v1.0.0:skill-card.md\n\n## Description: <br>\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 38 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[sam2kb](https://clawhub.ai/user/sam2kb) <br>\n\n### License/Terms of Use: <br>\nMIT <br>\n\n\n## Use Case: <br>\nDevelopers and employees use m365-mcp to connect MCP clients to Microsoft 365 through delegated OAuth. It lets an agent work with user-scoped mail, calendar, contacts, OneDrive, Teams, tasks, and profile data. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill grants delegated Microsoft 365 authority that can read, write, delete, move, send, or update email, calendar, files, Teams, contacts, tasks, and user data. <br>\nMitigation: Use the least Microsoft Graph permissions needed for the account, avoid tenant-wide or admin scopes unless required, and configure the MCP client to ask before sending, deleting, moving, or updating data. <br>\nRisk: OAuth tokens are stored locally for the configured account and can preserve delegated access until revoked or expired. <br>\nMitigation: Protect the token directory, use a controlled authentication directory when needed, periodically revoke stored tokens, and remove accounts that are no longer in use. <br>\n\n\n## Reference(s): <br>\n- [README](artifact/README.md) <br>\n- [Azure App registrations](https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationsListBlade) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, JSON, API Calls, Shell commands, Configuration] <br>\n**Output Format:** [Markdown guidance with inline shell commands and MCP tool responses as text or JSON] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires Node.js 18+, Azure Entra ID delegated Microsoft Graph permissions, and locally stored OAuth tokens.] <br>\n\n## Skill Version(s): <br>\n1.0.0 (source: package.json and ClawHub release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.0.0:package-lock.json\n\n{\n  \"name\": \"@sam2kb/m365-mcp\",\n  \"version\": \"1.0.0\",\n  \"lockfileVersion\": 3,\n  \"requires\": true,\n  \"packages\": {\n    \"\": {\n      \"name\": \"@sam2kb/m365-mcp\",\n      \"version\": \"1.0.0\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"@modelcontextprotocol/sdk\": \"^1.0.0\"\n      },\n      \"bin\": {\n        \"m365-mcp\": \"dist/index.js\",\n        \"m365-mcp-auth\": \"dist/auth-cli.js\"\n      },\n      \"devDependencies\": {\n        \"@types/node\": \"^20.10.0\",\n        \"tsx\": \"^4.7.0\",\n        \"typescript\": \"^5.3.0\",\n        \"vitest\": \"^3.2.4\"\n      },\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/aix-ppc64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/aix-ppc64/-/aix-ppc64-0.28.1.tgz\",\n      \"integrity\": \"sha512-Svl7tq8k/08+p6CXPpRjQ1fKX+1odH/BQbb48fV6fj3CWHhsoIOoY87w1oHXm0qEpkIK3ZfVgp0hed3XBXzXMQ==\",\n      \"cpu\": [\n        \"ppc64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"aix\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/android-arm\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/android-arm/-/android-arm-0.28.1.tgz\",\n      \"integrity\": \"sha512-0k2F129Xdio1TdJfzJ8sy1Q47vUD2NnwdhiAf7drUN1EBTfPf4hsFCtmMgu/6m8JSzsBrlmVjudMBQqOfG8usQ==\",\n      \"cpu\": [\n        \"arm\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"android\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/android-arm64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/android-arm64/-/android-arm64-0.28.1.tgz\",\n      \"integrity\": \"sha512-34EGEbCIAgosYz6goLcopX6Mo7NyGv9tfwEM2/7Ce2VcVRk568iSvniGWcUXIy7wEDR1wzolcxcriFVrWYcwBg==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"android\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/android-x64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/android-x64/-/android-x64-0.28.1.tgz\",\n      \"integrity\": \"sha512-dbwY7ltSMDWsRatcRpCnES4F+im88OCUgGZjy52shC7GqHRE/cYlxNbB4Z4UpJswpcc4Qxd2oE/ufM0p61IKng==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"android\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/darwin-arm64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/darwin-arm64/-/darwin-arm64-0.28.1.tgz\",\n      \"integrity\": \"sha512-TZbWkQY7kvTAXbXUT7uVACR5cMHsDiSz9z7ZKAX/RTq/WJEk3QyRr0wZpNhBDX+/0CtdqUIJlOiodQcta6tY3Q==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"darwin\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/darwin-x64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/darwin-x64/-/darwin-x64-0.28.1.tgz\",\n      \"integrity\": \"sha512-zfdzgK9ACBNZLI/CyHTOx81SyNbM6YXn7rxSgX97VjyiPl9W1i4Ka4fgKECEoFCKGpvBj5qArWIGgQjOwkgskQ==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"darwin\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/freebsd-arm64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/freebsd-arm64/-/freebsd-arm64-0.28.1.tgz\",\n      \"integrity\": \"sha512-wG2EA8ENdEI0qhkSZMjfqrdY+ziCYCPMmtZjjIwOmXFjmyzEHn+UUxk5of+SYsjtfs3VpnlC7QLzSI5hY/rOAw==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"freebsd\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/freebsd-x64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/freebsd-x64/-/freebsd-x64-0.28.1.tgz\",\n      \"integrity\": \"sha512-i7dZ9vQgnvSCzi/rYCXNgtF/U+eKZNJBzu3eTQbRgHnM7tNSizLOkRFAl3qzVc/Op/u5YkHHa4pf/3DOYHthLQ==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"freebsd\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/linux-arm\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/linux-arm/-/linux-arm-0.28.1.tgz\",\n      \"integrity\": \"sha512-qVXBOHQS+d5Y722GwJzJUtOLlX7km3CraOaGormF1pDtPd2C/l1SHRPgjLunLGe51Sh5YYWKMFDyV4SxgMQYTQ==\",\n      \"cpu\": [\n        \"arm\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/linux-arm64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/linux-arm64/-/linux-arm64-0.28.1.tgz\",\n      \"integrity\": \"sha512-yHs+0uc8+nvEAfAfxrWQKK5peSNzBc4PegcMO0EJ2hT71uA7vB8Ihg2e77R2P7SG5uYjPbHlLLmve4LLLRCf0g==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/linux-ia32\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/linux-ia32/-/linux-ia32-0.28.1.tgz\",\n      \"integrity\": \"sha512-d1z4ZuP0ajrfz/FhGT4vv278rX8KnPPJx8i5+AtK7TYbx9Le9F1hyzurZpkEyjkGa9dUGhQow4C1NmeGvqxN2w==\",\n      \"cpu\": [\n        \"ia32\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/linux-loong64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/linux-loong64/-/linux-loong64-0.28.1.tgz\",\n      \"integrity\": \"sha512-M5sRjUVZrkm1OAPR3dlOYzNmN+loZKGVi1VUQGrwuqLcbR6qeAz+famMhjASeH3YVKvZz+zT1jlh/keC3Rj/lg==\",\n      \"cpu\": [\n        \"loong64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/linux-mips64el\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/linux-mips64el/-/linux-mips64el-0.28.1.tgz\",\n      \"integrity\": \"sha512-mRObBZeHh2OxcBFPWE/FjylkRgZdYuiTR3vaTozquCGOH14iP9oN4x4Ge81CoIDYQrXmIxpFumJBu5MtZpnQJQ==\",\n      \"cpu\": [\n        \"mips64el\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/linux-ppc64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/linux-ppc64/-/linux-ppc64-0.28.1.tgz\",\n      \"integrity\": \"sha512-slScBsMAb3GFDcdrCgLwZtPYRoH2H/youv10QiZyRjmsP48fznoveWytSgCI/R0ZcUgpc0ZhIUEx6LHts8yrfQ==\",\n      \"cpu\": [\n        \"ppc64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/linux-riscv64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/linux-riscv64/-/linux-riscv64-0.28.1.tgz\",\n      \"integrity\": \"sha512-kw0owk1o0GFETUJyW0jc0G4Yzs0BHZn0JDZ8JRT088vjJYX777BAs1fDGxAC+q831qOs2DTC96mNsG2opdfyyQ==\",\n      \"cpu\": [\n        \"riscv64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/linux-s390x\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/linux-s390x/-/linux-s390x-0.28.1.tgz\",\n      \"integrity\": \"sha512-/lAIjX8aYFRByhh6L5rYtPEDRqa9de/4V/juOXcta5frjvzXO4/sqEtyytse0g3zZFuWu5cDN0MkLz2qRDD2Ag==\",\n      \"cpu\": [\n        \"s390x\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/linux-x64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/linux-x64/-/linux-x64-0.28.1.tgz\",\n      \"integrity\": \"sha512-u/anNYF2mmVOEDwLtnQ1wOr3EZ9sTNGLWrsYGYwHWzGA3Si84IOkHXlbWTD1NB+9/1lcnweYKO54uhxZydNzfA==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/netbsd-arm64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/netbsd-arm64/-/netbsd-arm64-0.28.1.tgz\",\n      \"integrity\": \"sha512-oks0DYbLwWMmaakTsCb+zL4E+aHRVLom9IJZOAthMQEPiQmydXHkziYEsGYRx0uNV/IjEKGAV941JzH02pflqw==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"netbsd\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/netbsd-x64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/netbsd-x64/-/netbsd-x64-0.28.1.tgz\",\n      \"integrity\": \"sha512-aeL6lAnN89Hz43Mlh1G8ARasbuoYvSITDEx0tHh5b7jJnHcssqgjy9Yx430GDpmCa6OyrKoS0aNRjKundRizGg==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"netbsd\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/openbsd-arm64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/openbsd-arm64/-/openbsd-arm64-0.28.1.tgz\",\n      \"integrity\": \"sha512-MEFJe5C3R8pwXdZ5Y21oo6m7ePiS0d9pWucn99O/wvyJZChoIQKrQDxKrGeW8F5+T0okTHesAmDeiHDTIq0V/Q==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"openbsd\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/openbsd-x64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/openbsd-x64/-/openbsd-x64-0.28.1.tgz\",\n      \"integrity\": \"sha512-i/ZLIOafE0Z8cI/XANJAixoJL/uRAoS2xOA3rb0xN+KK0K177cMAsQYkzHtBrtMXAKuAc7HGgcWiZ/sRC1Nxgw==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"openbsd\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/openharmony-arm64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/openharmony-arm64/-/openharmony-arm64-0.28.1.tgz\",\n      \"integrity\": \"sha512-ge+Z7EXFNt2BO1oAMsVpiQ8EwndV9i1xXerAeTIK7AtPs3bKFXQM7nlRxDSIUIMeueR1CNXxqztLzdNeReKBJg==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"openharmony\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/sunos-x64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/sunos-x64/-/sunos-x64-0.28.1.tgz\",\n      \"integrity\": \"sha512-BEjgtECkL3vY+SaSQ6nzVfiALUeFxpawyp8Jmf5PtYhf1Ug40N1h/hxlhts+f1FvSvarEigdxS3BlSMI2PJLcQ==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"sunos\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/win32-arm64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/win32-arm64/-/win32-arm64-0.28.1.tgz\",\n      \"integrity\": \"sha512-lCv9eK/H6ZJWbE7bh2nw54CZ9M2nupBxJcTsdk/QQnWkdSjKGuxmmH8/GWrlT1eMmZfn4dGcCjRte397WqfQXA==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"win32\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/win32-ia32\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/win32-ia32/-/win32-ia32-0.28.1.tgz\",\n      \"integrity\": \"sha512-zvb/mB2bSCoJOpoCBgYKKpX6YM6mJBlBUVUtVj41DlZJVEB6/0CKlRYxP5wWl1C1ILiCoAU5wZZ4q1P3qeS6Eg==\",\n      \"cpu\": [\n        \"ia32\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"win32\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@esbuild/win32-x64\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/@esbuild/win32-x64/-/win32-x64-0.28.1.tgz\",\n      \"integrity\": \"sha512-bm4Mowrv+GXMlpWX++EcXw/iLyd1o3+bJkC2DkWXYVvgZCqD/bSj9ctZeAMC3cIxgjRVR2Dufaiu4YPxr5gW1A==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"win32\"\n      ],\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/@hono/node-server\": {\n      \"version\": \"1.19.14\",\n      \"resolved\": \"https://registry.npmjs.org/@hono/node-server/-/node-server-1.19.14.tgz\",\n      \"integrity\": \"sha512-GwtvgtXxnWsucXvbQXkRgqksiH2Qed37H9xHZocE5sA3N8O8O8/8FA3uclQXxXVzc9XBZuEOMK7+r02FmSpHtw==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">=18.14.1\"\n      },\n      \"peerDependencies\": {\n        \"hono\": \"^4\"\n      }\n    },\n    \"node_modules/@jridgewell/sourcemap-codec\": {\n      \"version\": \"1.5.5\",\n      \"resolved\": \"https://registry.npmjs.org/@jridgewell/sourcemap-codec/-/sourcemap-codec-1.5.5.tgz\",\n      \"integrity\": \"sha512-cYQ9310grqxueWbl+WuIUIaiUaDcj7WOq5fVhEljNVgRfOUhY9fy2zTvfoqWsnebh8Sl70VScFbICvJnLKB0Og==\",\n      \"dev\": true,\n      \"license\": \"MIT\"\n    },\n    \"node_modules/@modelcontextprotocol/sdk\": {\n      \"version\": \"1.29.0\",\n      \"resolved\": \"https://registry.npmjs.org/@modelcontextprotocol/sdk/-/sdk-1.29.0.tgz\",\n      \"integrity\": \"sha512-zo37mZA9hJWpULgkRpowewez1y6ML5GsXJPY8FI0tBBCd77HEvza4jDqRKOXgHNn867PVGCyTdzqpz0izu5ZjQ==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"@hono/node-server\": \"^1.19.9\",\n        \"ajv\": \"^8.17.1\",\n        \"ajv-formats\": \"^3.0.1\",\n        \"content-type\": \"^1.0.5\",\n        \"cors\": \"^2.8.5\",\n        \"cross-spawn\": \"^7.0.5\",\n        \"eventsource\": \"^3.0.2\",\n        \"eventsource-parser\": \"^3.0.0\",\n        \"express\": \"^5.2.1\",\n        \"express-rate-limit\": \"^8.2.1\",\n        \"hono\": \"^4.11.4\",\n        \"jose\": \"^6.1.3\",\n        \"json-schema-typed\": \"^8.0.2\",\n        \"pkce-challenge\": \"^5.0.0\",\n        \"raw-body\": \"^3.0.0\",\n        \"zod\": \"^3.25 || ^4.0\",\n        \"zod-to-json-schema\": \"^3.25.1\"\n      },\n      \"engines\": {\n        \"node\": \">=18\"\n      },\n      \"peerDependencies\": {\n        \"@cfworker/json-schema\": \"^4.1.1\",\n        \"zod\": \"^3.25 || ^4.0\"\n      },\n      \"peerDependenciesMeta\": {\n        \"@cfworker/json-schema\": {\n          \"optional\": true\n        },\n        \"zod\": {\n          \"optional\": false\n        }\n      }\n    },\n    \"node_modules/@rollup/rollup-android-arm-eabi\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-android-arm-eabi/-/rollup-android-arm-eabi-4.62.2.tgz\",\n      \"integrity\": \"sha512-6o7ZLZK+BeenkZCFNDXqpbjw9bD6nuWonvS/lwQJp7NoVVxm6p3qE7qQ5jGuBjiFsgvqjD8mZAU5oWxTmbOeOg==\",\n      \"cpu\": [\n        \"arm\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"android\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-android-arm64\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-android-arm64/-/rollup-android-arm64-4.62.2.tgz\",\n      \"integrity\": \"sha512-BaH7BllCACHoH1LguOU56UItGfUWjujlO65kS9LAodViaN4bwIKd7oeW/ZHJ/4ljr/7MIiENnNy3HJ0zXv8Zkw==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"android\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-darwin-arm64\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-darwin-arm64/-/rollup-darwin-arm64-4.62.2.tgz\",\n      \"integrity\": \"sha512-v39RCCvj4He82I9sFmk+M1VZ0PLM9sfsLVikjfx2hYBNALhrrOR2D3JjQA6AhlaSOgcR+RzrKY7e1+bT6SUO/A==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"darwin\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-darwin-x64\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-darwin-x64/-/rollup-darwin-x64-4.62.2.tgz\",\n      \"integrity\": \"sha512-yl0y2vq3S3lHeuXhEdss6TWfKW8vkujImO12tn4ZkG/4oghr09LvdYm2RElVjokTQiUvDUGXLGsYeLqUMCKpGA==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"darwin\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-freebsd-arm64\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-freebsd-arm64/-/rollup-freebsd-arm64-4.62.2.tgz\",\n      \"integrity\": \"sha512-tT4pvt4qXD+vEoezupCWi+a1F0vvDiksiHc+PxRlYTOH1I6/X4id9jPxTP+Fg+545euaFT1jJVs4CEdHZAU1vw==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"freebsd\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-freebsd-x64\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-freebsd-x64/-/rollup-freebsd-x64-4.62.2.tgz\",\n      \"integrity\": \"sha512-6nU5F2wCW+qvCBhTn1pdIU3bzsIoF7EUwsCDRxilWGprQR6yd508YnH9+OKFCwpfS8pjZqDUmnCAr7exax0XCg==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"freebsd\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-arm-gnueabihf\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-arm-gnueabihf/-/rollup-linux-arm-gnueabihf-4.62.2.tgz\",\n      \"integrity\": \"sha512-n1GJHPOvpIfhi3TmrCeh6S6URt9BFCt0KQE3qvexyGCTAKpR4Lg+eWvNZEqu7epxwus/8ElT3hacYEucm49SZg==\",\n      \"cpu\": [\n        \"arm\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"glibc\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-arm-musleabihf\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-arm-musleabihf/-/rollup-linux-arm-musleabihf-4.62.2.tgz\",\n      \"integrity\": \"sha512-JqgflS8wEB+UXV/vS1RpRbifGBeN4D5lz8D8oOFbFZw4vedvdOgCFAjfBmIMdW3yL10XpQQ0Ambepw6MXrhOnA==\",\n      \"cpu\": [\n        \"arm\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"musl\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-arm64-gnu\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-arm64-gnu/-/rollup-linux-arm64-gnu-4.62.2.tgz\",\n      \"integrity\": \"sha512-wnFJkogWvN4jm/hQRF2UBaeUmk20j5+DmHvoyWii2b8HJDyvz1MF2OU/6ynXt2KR63rbZLWkFpoytpdc/yBuSA==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"glibc\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-arm64-musl\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-arm64-musl/-/rollup-linux-arm64-musl-4.62.2.tgz\",\n      \"integrity\": \"sha512-HVu2bp0zhvJ8xHEV9+UUs7S90VadmBSY3LcIMvozbPo4AuMGDWlz3ymHLHZPX4hR67TKTt8Qp5PJ5RBg/i+RMQ==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"musl\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-loong64-gnu\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-loong64-gnu/-/rollup-linux-loong64-gnu-4.62.2.tgz\",\n      \"integrity\": \"sha512-mQqqAV8QaoSgr9I2fKDLY2BAVvmKjWoGiu/cSYQonsLvtqwEn1E4QYfnCOcp5zoEqNhsDYin1s6jx/VJmrxlZg==\",\n      \"cpu\": [\n        \"loong64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"glibc\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-loong64-musl\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-loong64-musl/-/rollup-linux-loong64-musl-4.62.2.tgz\",\n      \"integrity\": \"sha512-IxKLoxCQ2IWi6bT2akyDUBGsOImDKB+sPp4EsTmwFQ/fMwpCKm8uLSSgP/Kx/QYUgKis6SEZ5/Nlhup0DIA0PQ==\",\n      \"cpu\": [\n        \"loong64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"musl\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-ppc64-gnu\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-ppc64-gnu/-/rollup-linux-ppc64-gnu-4.62.2.tgz\",\n      \"integrity\": \"sha512-Mk5ha2RQSgyFfmYYLkBpPnUk8D8FriBxesO1u9O75X0mHgXL1UQcH5Itl2lurWL2tj0RxV9b9tJgipac0hRY9A==\",\n      \"cpu\": [\n        \"ppc64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"glibc\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-ppc64-musl\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-ppc64-musl/-/rollup-linux-ppc64-musl-4.62.2.tgz\",\n      \"integrity\": \"sha512-CjvEnqJL/0/TQ3TXX3OPIJ/kmBellrWd4heXUmHeJlTnmwjKpSJzoehLaL6Xk0ZnMHBu9dZuFADNOrtjF4v+2w==\",\n      \"cpu\": [\n        \"ppc64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"musl\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-riscv64-gnu\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-riscv64-gnu/-/rollup-linux-riscv64-gnu-4.62.2.tgz\",\n      \"integrity\": \"sha512-1SiZbzwdkaDURsew/tSOrooKiYy7EQGT6m8ufavAi9NEyQb/6VuIxFXAL1fqa4iZe3g4NbNk4P7J32z2tw5Mgg==\",\n      \"cpu\": [\n        \"riscv64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"glibc\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-riscv64-musl\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-riscv64-musl/-/rollup-linux-riscv64-musl-4.62.2.tgz\",\n      \"integrity\": \"sha512-nQts12zJ3NQRoE6uYljOH89v7szzLDvG2JD/vsX+vGXU8w/At1GowTZ5/7qeFQ8m7L55rpR8Okugnuo5bgjy2Q==\",\n      \"cpu\": [\n        \"riscv64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"musl\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-s390x-gnu\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-s390x-gnu/-/rollup-linux-s390x-gnu-4.62.2.tgz\",\n      \"integrity\": \"sha512-E9/ll019jhPIJgpzfZoIkBGhcz+kKNgVWYRY0zr9srBdPPFVpvOKW8VaJKUbeK+eZXyQF9ltME+Kk6affeaPgg==\",\n      \"cpu\": [\n        \"s390x\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"glibc\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-x64-gnu\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-x64-gnu/-/rollup-linux-x64-gnu-4.62.2.tgz\",\n      \"integrity\": \"sha512-5BqxR/pshjey51iliyzTD5Xi3EN0aLmQ2lZ3lvefVV9c82BvrLo2/6OT55iifpWBufs6kdwWbuOKS841DrmK9A==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"glibc\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-linux-x64-musl\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-linux-x64-musl/-/rollup-linux-x64-musl-4.62.2.tgz\",\n      \"integrity\": \"sha512-uNN83XxQrRAh/w0/pmAfibcwyb6YWt4gP+dpnQKPVJshAloQ785ii8CT8ZCIxkGg9opVsvAlGhFitSm6D1Jjpg==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"libc\": [\n        \"musl\"\n      ],\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"linux\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-openbsd-x64\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-openbsd-x64/-/rollup-openbsd-x64-4.62.2.tgz\",\n      \"integrity\": \"sha512-srjEIxSH3LRnJN6THczDHWQplqEMFiAJrTab0msUryh9kwNpkICf3Ea6q6MN/2cZwRFUNx5w+h6Hpi4QuHS6Zg==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"openbsd\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-openharmony-arm64\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-openharmony-arm64/-/rollup-openharmony-arm64-4.62.2.tgz\",\n      \"integrity\": \"sha512-8hOJnxgbyObnCm5AlRA3A931xX19xq80RjVTKgJOvEKWqJruP/Uf12IbAOaDjjEXYRewwHLfmF0YRIdK3OwKWA==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"openharmony\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-win32-arm64-msvc\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-win32-arm64-msvc/-/rollup-win32-arm64-msvc-4.62.2.tgz\",\n      \"integrity\": \"sha512-mmF4AY1i0hG/bLWUctUq59gtmgaSIRa3cu/A3JFRp/sCNEme2bgDEiDS22P9FbnJB8NJNF4jPJiSP5RHQpUTDg==\",\n      \"cpu\": [\n        \"arm64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"win32\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-win32-ia32-msvc\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-win32-ia32-msvc/-/rollup-win32-ia32-msvc-4.62.2.tgz\",\n      \"integrity\": \"sha512-DZgkknc6jhHrk46V25vbAM0zZkyP0nSDkJB8/dRkLTxv470dOmWDqGoEJl/9A0dFfS7yE3REOwNDxpHwSLSt0Q==\",\n      \"cpu\": [\n        \"ia32\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"win32\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-win32-x64-gnu\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-win32-x64-gnu/-/rollup-win32-x64-gnu-4.62.2.tgz\",\n      \"integrity\": \"sha512-T6xr6ucWSFto+VGajA8YH26LdpHRuP4YLHEKAtCWvJDOlnmWcDZVCI2Jmjr+IFHDlt2zRaTAKE4tfjTaWLgJBg==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"win32\"\n      ]\n    },\n    \"node_modules/@rollup/rollup-win32-x64-msvc\": {\n      \"version\": \"4.62.2\",\n      \"resolved\": \"https://registry.npmjs.org/@rollup/rollup-win32-x64-msvc/-/rollup-win32-x64-msvc-4.62.2.tgz\",\n      \"integrity\": \"sha512-BfzEnDJOt9T8M989/lA37EcJgat01wLRnoi5dQf3QzOH7jzpqTAzdDbVfRljVr5r+jzKqpbHeyOfAaXxAd0PAA==\",\n      \"cpu\": [\n        \"x64\"\n      ],\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"optional\": true,\n      \"os\": [\n        \"win32\"\n      ]\n    },\n    \"node_modules/@types/chai\": {\n      \"version\": \"5.2.3\",\n      \"resolved\": \"https://registry.npmjs.org/@types/chai/-/chai-5.2.3.tgz\",\n      \"integrity\": \"sha512-Mw558oeA9fFbv65/y4mHtXDs9bPnFMZAL/jxdPFUpOHHIXX91mcgEHbS5Lahr+pwZFR8A7GQleRWeI6cGFC2UA==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"@types/deep-eql\": \"*\",\n        \"assertion-error\": \"^2.0.1\"\n      }\n    },\n    \"node_modules/@types/deep-eql\": {\n      \"version\": \"4.0.2\",\n      \"resolved\": \"https://registry.npmjs.org/@types/deep-eql/-/deep-eql-4.0.2.tgz\",\n      \"integrity\": \"sha512-c9h9dVVMigMPc4bwTvC5dxqtqJZwQPePsWjPlpSOnojbor6pGqdk541lfA7AqFQr5pB1BRdq0juY9db81BwyFw==\",\n      \"dev\": true,\n      \"license\": \"MIT\"\n    },\n    \"node_modules/@types/estree\": {\n      \"version\": \"1.0.9\",\n      \"resolved\": \"https://registry.npmjs.org/@types/estree/-/estree-1.0.9.tgz\",\n      \"integrity\": \"sha512-GhdPgy1el4/ImP05X05Uw4cw2/M93BCUmnEvWZNStlCzEKME4Fkk+YpoA5OiHNQmoS7Cafb8Xa3Pya8m1Qrzeg==\",\n      \"dev\": true,\n      \"license\": \"MIT\"\n    },\n    \"node_modules/@types/node\": {\n      \"version\": \"20.19.43\",\n      \"resolved\": \"https://registry.npmjs.org/@types/node/-/node-20.19.43.tgz\",\n      \"integrity\": \"sha512-6oYBAi5ikg4Pl+kGsoYtawUMBT2zZMCvPNF7pVLnHZfd1zf38DRiWn/gT01RYCdUqkv7Fhr+C9ot4/tb+2sVvA==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"undici-types\": \"~6.21.0\"\n      }\n    },\n    \"node_modules/@vitest/expect\": {\n      \"version\": \"3.2.7\",\n      \"resolved\": \"https://registry.npmjs.org/@vitest/expect/-/expect-3.2.7.tgz\",\n      \"integrity\": \"sha512-E8eBXaKibuvH2pSZErOjdVb5vF4PbKYcrnluBTYxEk1l/VhhwZg1kZQsdtjq+CsF5CFydf2Rdkz7jDHKSisi3w==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"@types/chai\": \"^5.2.2\",\n        \"@vitest/spy\": \"3.2.7\",\n        \"@vitest/utils\": \"3.2.7\",\n        \"chai\": \"^5.2.0\",\n        \"tinyrainbow\": \"^2.0.0\"\n      },\n      \"funding\": {\n        \"url\": \"https://opencollective.com/vitest\"\n      }\n    },\n    \"node_modules/@vitest/mocker\": {\n      \"version\": \"3.2.7\",\n      \"resolved\": \"https://registry.npmjs.org/@vitest/mocker/-/mocker-3.2.7.tgz\",\n      \"integrity\": \"sha512-Trr0hYO9CM3Wj6ksWHRhK9IZpIY6wTMO5u/MqXurMxT57sWBaOPEtP3Oq60ihZuh5JsiagKfz95OcxdEP6dBrA==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"@vitest/spy\": \"3.2.7\",\n        \"estree-walker\": \"^3.0.3\",\n        \"magic-string\": \"^0.30.17\"\n      },\n      \"funding\": {\n        \"url\": \"https://opencollective.com/vitest\"\n      },\n      \"peerDependencies\": {\n        \"msw\": \"^2.4.9\",\n        \"vite\": \"^5.0.0 || ^6.0.0 || ^7.0.0-0\"\n      },\n      \"peerDependenciesMeta\": {\n        \"msw\": {\n          \"optional\": true\n        },\n        \"vite\": {\n          \"optional\": true\n        }\n      }\n    },\n    \"node_modules/@vitest/pretty-format\": {\n      \"version\": \"3.2.7\",\n      \"resolved\": \"https://registry.npmjs.org/@vitest/pretty-format/-/pretty-format-3.2.7.tgz\",\n      \"integrity\": \"sha512-KUHlwqVu0sRlhCdyPdQ/wBoTfRahjUky1MubOmYw9fWfIZy1gNoHpuaaQBPAaMaVYdQYHJLurzj8ECCj5OwTqA==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"tinyrainbow\": \"^2.0.0\"\n      },\n      \"funding\": {\n        \"url\": \"https://opencollective.com/vitest\"\n      }\n    },\n    \"node_modules/@vitest/runner\": {\n      \"version\": \"3.2.7\",\n      \"resolved\": \"https://registry.npmjs.org/@vitest/runner/-/runner-3.2.7.tgz\",\n      \"integrity\": \"sha512-sB9y4ovltoQP+WaUPwmSxO9WIg9Ig694Di5PalVPsYHklAdE027mehpWF2SQSVq+k6sFgaivbTjTJwZLSHbedA==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"@vitest/utils\": \"3.2.7\",\n        \"pathe\": \"^2.0.3\",\n        \"strip-literal\": \"^3.0.0\"\n      },\n      \"funding\": {\n        \"url\": \"https://opencollective.com/vitest\"\n      }\n    },\n    \"node_modules/@vitest/snapshot\": {\n      \"version\": \"3.2.7\",\n      \"resolved\": \"https://registry.npmjs.org/@vitest/snapshot/-/snapshot-3.2.7.tgz\",\n      \"integrity\": \"sha512-7C+MwShwtBSI5Buwoyg3s/iY1eHL9PKAf+O1wVh/TdnjXUtkoL/9YQtre90i4MtNXM6edP1wJ2zOBpfCyhIS7g==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"@vitest/pretty-format\": \"3.2.7\",\n        \"magic-string\": \"^0.30.17\",\n        \"pathe\": \"^2.0.3\"\n      },\n      \"funding\": {\n        \"url\": \"https://opencollective.com/vitest\"\n      }\n    },\n    \"node_modules/@vitest/spy\": {\n      \"version\": \"3.2.7\",\n      \"resolved\": \"https://registry.npmjs.org/@vitest/spy/-/spy-3.2.7.tgz\",\n      \"integrity\": \"sha512-Q2eQGI6d2L/hBtZ0qNuKcAGid68XK6cv1xsoaIma6PaJhHPoqcEJhYpXZ/5myCMqkNgtP6UKuBhbc0nHKnrkuQ==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"tinyspy\": \"^4.0.3\"\n      },\n      \"funding\": {\n        \"url\": \"https://opencollective.com/vitest\"\n      }\n    },\n    \"node_modules/@vitest/utils\": {\n      \"version\": \"3.2.7\",\n      \"resolved\": \"https://registry.npmjs.org/@vitest/utils/-/utils-3.2.7.tgz\",\n      \"integrity\": \"sha512-x6BDOd7dyo3PFLY3I9/HJ25X/6OurhGXk2/B9gOZNPF7XDVjeBK4k01lQE5uvDpbuheErh91qYuE1E2OEjK3Rw==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"@vitest/pretty-format\": \"3.2.7\",\n        \"loupe\": \"^3.1.4\",\n        \"tinyrainbow\": \"^2.0.0\"\n      },\n      \"funding\": {\n        \"url\": \"https://opencollective.com/vitest\"\n      }\n    },\n    \"node_modules/accepts\": {\n      \"version\": \"2.0.0\",\n      \"resolved\": \"https://registry.npmjs.org/accepts/-/accepts-2.0.0.tgz\",\n      \"integrity\": \"sha512-5cvg6CtKwfgdmVqY1WIiXKc3Q1bkRqGLi+2W/6ao+6Y7gu/RCwRuAhGEzh5B4KlszSuTLgZYuqFqo5bImjNKng==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"mime-types\": \"^3.0.0\",\n        \"negotiator\": \"^1.0.0\"\n      },\n      \"engines\": {\n        \"node\": \">= 0.6\"\n      }\n    },\n    \"node_modules/ajv\": {\n      \"version\": \"8.20.0\",\n      \"resolved\": \"https://registry.npmjs.org/ajv/-/ajv-8.20.0.tgz\",\n      \"integrity\": \"sha512-Thbli+OlOj+iMPYFBVBfJ3OmCAnaSyNn4M1vz9T6Gka5Jt9ba/HIR56joy65tY6kx/FCF5VXNB819Y7/GUrBGA==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"fast-deep-equal\": \"^3.1.3\",\n        \"fast-uri\": \"^3.0.1\",\n        \"json-schema-traverse\": \"^1.0.0\",\n        \"require-from-string\": \"^2.0.2\"\n      },\n      \"funding\": {\n        \"type\": \"github\",\n        \"url\": \"https://github.com/sponsors/epoberezkin\"\n      }\n    },\n    \"node_modules/ajv-formats\": {\n      \"version\": \"3.0.1\",\n      \"resolved\": \"https://registry.npmjs.org/ajv-formats/-/ajv-formats-3.0.1.tgz\",\n      \"integrity\": \"sha512-8iUql50EUR+uUcdRQ3HDqa6EVyo3docL8g5WJ3FNcWmu62IbkGUue/pEyLBW8VGKKucTPgqeks4fIU1DA4yowQ==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"ajv\": \"^8.0.0\"\n      },\n      \"peerDependencies\": {\n        \"ajv\": \"^8.0.0\"\n      },\n      \"peerDependenciesMeta\": {\n        \"ajv\": {\n          \"optional\": true\n        }\n      }\n    },\n    \"node_modules/assertion-error\": {\n      \"version\": \"2.0.1\",\n      \"resolved\": \"https://registry.npmjs.org/assertion-error/-/assertion-error-2.0.1.tgz\",\n      \"integrity\": \"sha512-Izi8RQcffqCeNVgFigKli1ssklIbpHnCYc6AknXGYoB6grJqyeby7jv12JUQgmTAnIDnbck1uxksT4dzN3PWBA==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">=12\"\n      }\n    },\n    \"node_modules/body-parser\": {\n      \"version\": \"2.3.0\",\n      \"resolved\": \"https://registry.npmjs.org/body-parser/-/body-parser-2.3.0.tgz\",\n      \"integrity\": \"sha512-2cGmJupaNgg+QUwVLAucDuWuoMZ6EX9iHDRswZ5lsNYEmwPaRknMPCLZz07yTzVq/83p4o/wzbDZbBrTvGGTIw==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"bytes\": \"^3.1.2\",\n        \"content-type\": \"^2.0.0\",\n        \"debug\": \"^4.4.3\",\n        \"http-errors\": \"^2.0.1\",\n        \"iconv-lite\": \"^0.7.2\",\n        \"on-finished\": \"^2.4.1\",\n        \"qs\": \"^6.15.2\",\n        \"raw-body\": \"^3.0.2\",\n        \"type-is\": \"^2.1.0\"\n      },\n      \"engines\": {\n        \"node\": \">=18\"\n      },\n      \"funding\": {\n        \"type\": \"opencollective\",\n        \"url\": \"https://opencollective.com/express\"\n      }\n    },\n    \"node_modules/body-parser/node_modules/content-type\": {\n      \"version\": \"2.0.0\",\n      \"resolved\": \"https://registry.npmjs.org/content-type/-/content-type-2.0.0.tgz\",\n      \"integrity\": \"sha512-j/O/d7GcZCyNl7/hwZAb606rzqkyvaDctLmckbxLzHvFBzTJHuGEdodATcP3yIRoDrLHkIATJuvzbFlp/ki2cQ==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">=18\"\n      },\n      \"funding\": {\n        \"type\": \"opencollective\",\n        \"url\": \"https://opencollective.com/express\"\n      }\n    },\n    \"node_modules/bytes\": {\n      \"version\": \"3.1.2\",\n      \"resolved\": \"https://registry.npmjs.org/bytes/-/bytes-3.1.2.tgz\",\n      \"integrity\": \"sha512-/Nf7TyzTx6S3yRJObOAV7956r8cr2+Oj8AC5dt8wSP3BQAoeX58NoHyCU8P8zGkNXStjTSi6fzO6F0pBdcYbEg==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">= 0.8\"\n      }\n    },\n    \"node_modules/cac\": {\n      \"version\": \"6.7.14\",\n      \"resolved\": \"https://registry.npmjs.org/cac/-/cac-6.7.14.tgz\",\n      \"integrity\": \"sha512-b6Ilus+c3RrdDk+JhLKUAQfzzgLEPy6wcXqS7f/xe1EETvsDP6GORG7SFuOs6cID5YkqchW/LXZbX5bc8j7ZcQ==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">=8\"\n      }\n    },\n    \"node_modules/call-bind-apply-helpers\": {\n      \"version\": \"1.0.2\",\n      \"resolved\": \"https://registry.npmjs.org/call-bind-apply-helpers/-/call-bind-apply-helpers-1.0.2.tgz\",\n      \"integrity\": \"sha512-Sp1ablJ0ivDkSzjcaJdxEunN5/XvksFJ2sMBFfq6x0ryhQV/2b/KwFe21cMpmHtPOSij8K99/wSfoEuTObmuMQ==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"es-errors\": \"^1.3.0\",\n        \"function-bind\": \"^1.1.2\"\n      },\n      \"engines\": {\n        \"node\": \">= 0.4\"\n      }\n    },\n    \"node_modules/call-bound\": {\n      \"version\": \"1.0.4\",\n      \"resolved\": \"https://registry.npmjs.org/call-bound/-/call-bound-1.0.4.tgz\",\n      \"integrity\": \"sha512-+ys997U96po4Kx/ABpBCqhA9EuxJaQWDQg7295H4hBphv3IZg0boBKuwYpt4YXp6MZ5AmZQnU/tyMTlRpaSejg==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"call-bind-apply-helpers\": \"^1.0.2\",\n        \"get-intrinsic\": \"^1.3.0\"\n      },\n      \"engines\": {\n        \"node\": \">= 0.4\"\n      },\n      \"funding\": {\n        \"url\": \"https://github.com/sponsors/ljharb\"\n      }\n    },\n    \"node_modules/chai\": {\n      \"version\": \"5.3.3\",\n      \"resolved\": \"https://registry.npmjs.org/chai/-/chai-5.3.3.tgz\",\n      \"integrity\": \"sha512-4zNhdJD/iOjSH0A05ea+Ke6MU5mmpQcbQsSOkgdaUMJ9zTlDTD/GYlwohmIE2u0gaxHYiVHEn1Fw9mZ/ktJWgw==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"assertion-error\": \"^2.0.1\",\n        \"check-error\": \"^2.1.1\",\n        \"deep-eql\": \"^5.0.1\",\n        \"loupe\": \"^3.1.0\",\n        \"pathval\": \"^2.0.0\"\n      },\n      \"engines\": {\n        \"node\": \">=18\"\n      }\n    },\n    \"node_modules/check-error\": {\n      \"version\": \"2.1.3\",\n      \"resolved\": \"https://registry.npmjs.org/check-error/-/check-error-2.1.3.tgz\",\n      \"integrity\": \"sha512-PAJdDJusoxnwm1VwW07VWwUN1sl7smmC3OKggvndJFadxxDRyFJBX/ggnu/KE4kQAB7a3Dp8f/YXC1FlUprWmA==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">= 16\"\n      }\n    },\n    \"node_modules/content-disposition\": {\n      \"version\": \"1.1.0\",\n      \"resolved\": \"https://registry.npmjs.org/content-disposition/-/content-disposition-1.1.0.tgz\",\n      \"integrity\": \"sha512-5jRCH9Z/+DRP7rkvY83B+yGIGX96OYdJmzngqnw2SBSxqCFPd0w2km3s5iawpGX8krnwSGmF0FW5Nhr0Hfai3g==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">=18\"\n      },\n      \"funding\": {\n        \"type\": \"opencollective\",\n        \"url\": \"https://opencollective.com/express\"\n      }\n    },\n    \"node_modules/content-type\": {\n      \"version\": \"1.0.5\",\n      \"resolved\": \"https://registry.npmjs.org/content-type/-/content-type-1.0.5.tgz\",\n      \"integrity\": \"sha512-nTjqfcBFEipKdXCv4YDQWCfmcLZKm81ldF0pAopTvyrFGVbcR6P/VAAd5G7N+0tTr8QqiU0tFadD6FK4NtJwOA==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">= 0.6\"\n      }\n    },\n    \"node_modules/cookie\": {\n      \"version\": \"0.7.2\",\n      \"resolved\": \"https://registry.npmjs.org/cookie/-/cookie-0.7.2.tgz\",\n      \"integrity\": \"sha512-yki5XnKuf750l50uGTllt6kKILY4nQ1eNIQatoXEByZ5dWgnKqbnqmTrBE5B4N7lrMJKQ2ytWMiTO2o0v6Ew/w==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">= 0.6\"\n      }\n    },\n    \"node_modules/cookie-signature\": {\n      \"version\": \"1.2.2\",\n      \"resolved\": \"https://registry.npmjs.org/cookie-signature/-/cookie-signature-1.2.2.tgz\",\n      \"integrity\": \"sha512-D76uU73ulSXrD1UXF4KE2TMxVVwhsnCgfAyTg9k8P6KGZjlXKrOLe4dJQKI3Bxi5wjesZoFXJWElNWBjPZMbhg==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">=6.6.0\"\n      }\n    },\n    \"node_modules/cors\": {\n      \"version\": \"2.8.6\",\n      \"resolved\": \"https://registry.npmjs.org/cors/-/cors-2.8.6.tgz\",\n      \"integrity\": \"sha512-tJtZBBHA6vjIAaF6EnIaq6laBBP9aq/Y3ouVJjEfoHbRBcHBAHYcMh/w8LDrk2PvIMMq8gmopa5D4V8RmbrxGw==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"object-assign\": \"^4\",\n        \"vary\": \"^1\"\n      },\n      \"engines\": {\n        \"node\": \">= 0.10\"\n      },\n      \"funding\": {\n        \"type\": \"opencollective\",\n        \"url\": \"https://opencollective.com/express\"\n      }\n    },\n    \"node_modules/cross-spawn\": {\n      \"version\": \"7.0.6\",\n      \"resolved\": \"https://registry.npmjs.org/cross-spawn/-/cross-spawn-7.0.6.tgz\",\n      \"integrity\": \"sha512-uV2QOWP2nWzsy2aMp8aRibhi9dlzF5Hgh5SHaB9OiTGEyDTiJJyx0uy51QXdyWbtAHNua4XJzUKca3OzKUd3vA==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"path-key\": \"^3.1.0\",\n        \"shebang-command\": \"^2.0.0\",\n        \"which\": \"^2.0.1\"\n      },\n      \"engines\": {\n        \"node\": \">= 8\"\n      }\n    },\n    \"node_modules/debug\": {\n      \"version\": \"4.4.3\",\n      \"resolved\": \"https://registry.npmjs.org/debug/-/debug-4.4.3.tgz\",\n      \"integrity\": \"sha512-RGwwWnwQvkVfavKVt22FGLw+xYSdzARwm0ru6DhTVA3umU5hZc28V3kO4stgYryrTlLpuvgI9GiijltAjNbcqA==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"ms\": \"^2.1.3\"\n      },\n      \"engines\": {\n        \"node\": \">=6.0\"\n      },\n      \"peerDependenciesMeta\": {\n        \"supports-color\": {\n          \"optional\": true\n        }\n      }\n    },\n    \"node_modules/deep-eql\": {\n      \"version\": \"5.0.2\",\n      \"resolved\": \"https://registry.npmjs.org/deep-eql/-/deep-eql-5.0.2.tgz\",\n      \"integrity\": \"sha512-h5k/5U50IJJFpzfL6nO9jaaumfjO/f2NjK/oYB2Djzm4p9L+3T9qWpZqZ2hAbLPuuYq9wrU08WQyBTL5GbPk5Q==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">=6\"\n      }\n    },\n    \"node_modules/depd\": {\n      \"version\": \"2.0.0\",\n      \"resolved\": \"https://registry.npmjs.org/depd/-/depd-2.0.0.tgz\",\n      \"integrity\": \"sha512-g7nH6P6dyDioJogAAGprGpCtVImJhpPk/roCzdb3fIh61/s/nPsfR6onyMwkCAR/OlC3yBC0lESvUoQEAssIrw==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">= 0.8\"\n      }\n    },\n    \"node_modules/dunder-proto\": {\n      \"version\": \"1.0.1\",\n      \"resolved\": \"https://registry.npmjs.org/dunder-proto/-/dunder-proto-1.0.1.tgz\",\n      \"integrity\": \"sha512-KIN/nDJBQRcXw0MLVhZE9iQHmG68qAVIBg9CqmUYjmQIhgij9U5MFvrqkUL5FbtyyzZuOeOt0zdeRe4UY7ct+A==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"call-bind-apply-helpers\": \"^1.0.1\",\n        \"es-errors\": \"^1.3.0\",\n        \"gopd\": \"^1.2.0\"\n      },\n      \"engines\": {\n        \"node\": \">= 0.4\"\n      }\n    },\n    \"node_modules/ee-first\": {\n      \"version\": \"1.1.1\",\n      \"resolved\": \"https://registry.npmjs.org/ee-first/-/ee-first-1.1.1.tgz\",\n      \"integrity\": \"sha512-WMwm9LhRUo+WUaRN+vRuETqG89IgZphVSNkdFgeb6sS/E4OrDIN7t48CAewSHXc6C8lefD8KKfr5vY61brQlow==\",\n      \"license\": \"MIT\"\n    },\n    \"node_modules/encodeurl\": {\n      \"version\": \"2.0.0\",\n      \"resolved\": \"https://registry.npmjs.org/encodeurl/-/encodeurl-2.0.0.tgz\",\n      \"integrity\": \"sha512-Q0n9HRi4m6JuGIV1eFlmvJB7ZEVxu93IrMyiMsGC0lrMJMWzRgx6WGquyfQgZVb31vhGgXnfmPNNXmxnOkRBrg==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">= 0.8\"\n      }\n    },\n    \"node_modules/es-define-property\": {\n      \"version\": \"1.0.1\",\n      \"resolved\": \"https://registry.npmjs.org/es-define-property/-/es-define-property-1.0.1.tgz\",\n      \"integrity\": \"sha512-e3nRfgfUZ4rNGL232gUgX06QNyyez04KdjFrF+LTRoOXmrOgFKDg4BCdsjW8EnT69eqdYGmRpJwiPVYNrCaW3g==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">= 0.4\"\n      }\n    },\n    \"node_modules/es-errors\": {\n      \"version\": \"1.3.0\",\n      \"resolved\": \"https://registry.npmjs.org/es-errors/-/es-errors-1.3.0.tgz\",\n      \"integrity\": \"sha512-Zf5H2Kxt2xjTvbJvP2ZWLEICxA6j+hAmMzIlypy4xcBg1vKVnx89Wy0GbS+kf5cwCVFFzdCFh2XSCFNULS6csw==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">= 0.4\"\n      }\n    },\n    \"node_modules/es-module-lexer\": {\n      \"version\": \"1.7.0\",\n      \"resolved\": \"https://registry.npmjs.org/es-module-lexer/-/es-module-lexer-1.7.0.tgz\",\n      \"integrity\": \"sha512-jEQoCwk8hyb2AZziIOLhDqpm5+2ww5uIE6lkO/6jcOCusfk6LhMHpXXfBLXTZ7Ydyt0j4VoUQv6uGNYbdW+kBA==\",\n      \"dev\": true,\n      \"license\": \"MIT\"\n    },\n    \"node_modules/es-object-atoms\": {\n      \"version\": \"1.1.2\",\n      \"resolved\": \"https://registry.npmjs.org/es-object-atoms/-/es-object-atoms-1.1.2.tgz\",\n      \"integrity\": \"sha512-HWcBoN6NileqtSydK2FqHbS/LoDd2pqrnQHLyJzBj4kOp/ky2MWMN694xOfkK8/SnUsW2DH7EfyVlydKCsm1Zw==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"es-errors\": \"^1.3.0\"\n      },\n      \"engines\": {\n        \"node\": \">= 0.4\"\n      }\n    },\n    \"node_modules/esbuild\": {\n      \"version\": \"0.28.1\",\n      \"resolved\": \"https://registry.npmjs.org/esbuild/-/esbuild-0.28.1.tgz\",\n      \"integrity\": \"sha512-HrJrvZv5ayxBzPfwphOoNzkzOIIlifzk0KJrGK2c8R4+LKpMtpYLQeUdjnwjWv/LZlkH2laZk+4w78pi99D4Vw==\",\n      \"dev\": true,\n      \"hasInstallScript\": true,\n      \"license\": \"MIT\",\n      \"bin\": {\n        \"esbuild\": \"bin/esbuild\"\n      },\n      \"engines\": {\n        \"node\": \">=18\"\n      },\n      \"optionalDependencies\": {\n        \"@esbuild/aix-ppc64\": \"0.28.1\",\n        \"@esbuild/android-arm\": \"0.28.1\",\n        \"@esbuild/android-arm64\": \"0.28.1\",\n        \"@esbuild/android-x64\": \"0.28.1\",\n        \"@esbuild/darwin-arm64\": \"0.28.1\",\n        \"@esbuild/darwin-x64\": \"0.28.1\",\n        \"@esbuild/freebsd-arm64\": \"0.28.1\",\n        \"@esbuild/freebsd-x64\": \"0.28.1\",\n        \"@esbuild/linux-arm\": \"0.28.1\",\n        \"@esbuild/linux-arm64\": \"0.28.1\",\n        \"@esbuild/linux-ia32\": \"0.28.1\",\n        \"@esbuild/linux-loong64\": \"0.28.1\",\n        \"@esbuild/linux-mips64el\": \"0.28.1\",\n        \"@esbuild/linux-ppc64\": \"0.28.1\",\n        \"@esbuild/linux-riscv64\": \"0.28.1\",\n        \"@esbuild/linux-s390x\": \"0.28.1\",\n        \"@esbuild/linux-x64\": \"0.28.1\",\n        \"@esbuild/netbsd-arm64\": \"0.28.1\",\n        \"@esbuild/netbsd-x64\": \"0.28.1\",\n        \"@esbuild/openbsd-arm64\": \"0.28.1\",\n        \"@esbuild/openbsd-x64\": \"0.28.1\",\n        \"@esbuild/openharmony-arm64\": \"0.28.1\",\n        \"@esbuild/sunos-x64\": \"0.28.1\",\n        \"@esbuild/win32-arm64\": \"0.28.1\",\n        \"@esbuild/win32-ia32\": \"0.28.1\",\n        \"@esbuild/win32-x64\": \"0.28.1\"\n      }\n    },\n    \"node_modules/escape-html\": {\n      \"version\": \"1.0.3\",\n      \"resolved\": \"https://registry.npmjs.org/escape-html/-/escape-html-1.0.3.tgz\",\n      \"integrity\": \"sha512-NiSupZ4OeuGwr68lGIeym/ksIZMJodUGOSCZ/FSnTxcrekbvqrgdUxlJOMpijaKZVjAJrWrGs/6Jy8OMuyj9ow==\",\n      \"license\": \"MIT\"\n    },\n    \"node_modules/estree-walker\": {\n      \"version\": \"3.0.3\",\n      \"resolved\": \"https://registry.npmjs.org/estree-walker/-/estree-walker-3.0.3.tgz\",\n      \"integrity\": \"sha512-7RUKfXgSMMkzt6ZuXmqapOurLGPPfgj6l9uRZ7lRGolvk0y2yocc35LdcxKC5PQZdn2DMqioAQ2NoWcrTKmm6g==\",\n      \"dev\": true,\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"@types/estree\": \"^1.0.0\"\n      }\n    },\n    \"node_modules/etag\": {\n      \"version\": \"1.8.1\",\n      \"resolved\": \"https://registry.npmjs.org/etag/-/etag-1.8.1.tgz\",\n      \"integrity\": \"sha512-aIL5Fx7mawVa300al2BnEE4iNvo1qETxLrPI/o05L7z6go7fCw1J6EQmbK4FmJ2AS7kgVF/KEZWufBfdClMcPg==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">= 0.6\"\n      }\n    },\n    \"node_modules/eventsource\": {\n      \"version\": \"3.0.7\",\n      \"resolved\": \"https://registry.npmjs.org/eventsource/-/eventsource-3.0.7.tgz\",\n      \"integrity\": \"sha512-CRT1WTyuQoD771GW56XEZFQ/ZoSfWid1alKGDYMmkt2yl8UXrVR4pspqWNEcqKvVIzg6PAltWjxcSSPrboA4iA==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"eventsource-parser\": \"^3.0.1\"\n      },\n      \"engines\": {\n        \"node\": \">=18.0.0\"\n      }\n    },\n    \"node_modules/eventsource-parser\": {\n      \"version\": \"3.1.0\",\n      \"resolved\": \"https://registry.npmjs.org/eventsource-parser/-/eventsource-parser-3.1.0.tgz\",\n      \"integrity\": \"sha512-kJezFj9YFAMLeORyi7aCLxLbD5/qWMQnoMVlVPyHIll7lgRJCc3JVln9Vgl9nwQi0YkMnhdGTMNn7CkRRAptMg==\",\n      \"license\": \"MIT\",\n      \"engines\": {\n        \"node\": \">=18.0.0\"\n      }\n    },\n    \"node_modules/expect-type\": {\n      \"version\": \"1.4.0\",\n      \"resolved\": \"https://registry.npmjs.org/expect-type/-/expect-type-1.4.0.tgz\",\n      \"integrity\": \"sha512-KfYbmpRm0VbLjEvVa9yGwCi9GI34xvi7A/HXYWQO65CSD2u3MczUJSuwXKFIxlGsgBQizV9q5J9NHj4VG0n+pA==\",\n      \"dev\": true,\n      \"license\": \"Apache-2.0\",\n      \"engines\": {\n        \"node\": \">=12.0.0\"\n      }\n    },\n    \"node_modules/express\": {\n      \"version\": \"5.2.1\",\n      \"resolved\": \"https://registry.npmjs.org/express/-/express-5.2.1.tgz\",\n      \"integrity\": \"sha512-hIS4idWWai69NezIdRt2xFVofaF4j+6INOpJlVOLDO8zXGpUVEVzIYk12UUi2JzjEzWL3IOAxcTubgz9Po0yXw==\",\n      \"license\": \"MIT\",\n      \"dependencies\": {\n        \"accepts\": \"^2.0.0\",\n        \"body-parser\": \"^2.2.1\",\n        \"content-disposition\": \"^1.0.0\",\n        \"content-type\": \"^1.0.5\",\n        \"cookie\": \"^0.7.1\",\n        \"cookie-signature\": \"^1.2.1\",\n        \"debug\": \"^4.4.0\",\n        \"depd\": \"^2.0.0\",\n        \"encodeurl\": \"^2.0.0\",\n        \"escape-html\": \"^1.0.3\",\n        \"etag\": \"^1.8.1\",\n        \"finalhandler\": \"^2.1.0\",\n        \"fresh\": \"^2.0.0\",\n        \"http-errors\": \"^2.0.0\",\n        \"merge-descriptors\": \"^2.0.0\",\n        \"mime-types\": \"^3.0.0\",\n        \"on-finished\": \"^2.4.1\",\n        \"once\": \"^1.4.0\",\n        \"parseurl\": \"^1.3.3\",\n        \"proxy-addr\": \"^2.0.7\",\n        \"qs\": \"^6.14.0\",\n        \"range-parser\": \"^1.2.1\",\n        \"router\": \"^2.2.0\",\n        \"send\": \"^1.1.0\",\n        \"serve-static\": \"^2.2.0\",\n        \"statuses\": \"^2.0.1\",\n        \"type-is\": \"^2.0.1\",\n        \"vary\": \"^1.1.2\"\n      },\n      \"engines\": {\n        \"node\": \">= 18\"\n      },\n      \"funding\": {\n        \"type\": \"opencollective\",\n        \"url\": \"https://opencollective.com/express\"\n      }\n    },\n    \"node_modules/express-rate-limit\": {\n      \"version\": \"8.6.0\",\n      \"resolved\": \"https://registry.npmjs.org/express-rate-limit/-/express-rate-limit-8.6.0.tgz\",\n      \"integrity\": \"sha512-XKJXDsASUOo0LLtFwW5hCcQGH0N4WQc/Rn8/Pvoia+TJFOkkFPvrtW9lZOeeNcxQJspvOIERMwiRLsVFlhHEkA==\",\n      \"license\": \"MIT\",\n      \"dependencies\n\nFile v1.0.0:package.json\n\n{\n  \"name\": \"@sam2kb/m365-mcp\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Production-grade Microsoft 365 MCP server — email, calendar, contacts, OneDrive, Teams, tasks, and users via delegated OAuth\",\n  \"type\": \"module\",\n  \"main\": \"dist/index.js\",\n  \"bin\": {\n    \"m365-mcp\": \"dist/index.js\",\n    \"m365-mcp-auth\": \"dist/auth-cli.js\"\n  },\n  \"scripts\": {\n    \"build\": \"tsc\",\n    \"start\": \"node dist/index.js\",\n    \"dev\": \"tsx src/index.ts\",\n    \"auth\": \"tsx src/auth-cli.ts\",\n    \"test\": \"vitest run\",\n    \"test:watch\": \"vitest\"\n  },\n  \"keywords\": [\n    \"mcp\",\n    \"microsoft365\",\n    \"outlook\",\n    \"teams\",\n    \"onedrive\",\n    \"graph-api\"\n  ],\n  \"author\": \"Alex Kay <info@wittyfinch.com>\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"https://github.com/sam2kb/m365-mcp\"\n  },\n  \"publishConfig\": {\n    \"access\": \"public\"\n  },\n  \"dependencies\": {\n    \"@modelcontextprotocol/sdk\": \"^1.0.0\"\n  },\n  \"devDependencies\": {\n    \"@types/node\": \"^20.10.0\",\n    \"tsx\": \"^4.7.0\",\n    \"typescript\": \"^5.3.0\",\n    \"vitest\": \"^3.2.4\"\n  },\n  \"engines\": {\n    \"node\": \">=18\"\n  }\n}\n\nFile v1.0.0:tsconfig.json\n\n{\n  \"compilerOptions\": {\n    \"target\": \"ES2022\",\n    \"module\": \"NodeNext\",\n    \"moduleResolution\": \"NodeNext\",\n    \"outDir\": \"./dist\",\n    \"rootDir\": \"./src\",\n    \"strict\": true,\n    \"esModuleInterop\": true,\n    \"skipLibCheck\": true,\n    \"forceConsistentCasingInFileNames\": true,\n    \"resolveJsonModule\": true,\n    \"declaration\": true,\n    \"sourceMap\": true,\n    \"types\": [\"node\"]\n  },\n  \"include\": [\"src/**/*\"],\n  \"exclude\": [\"node_modules\", \"dist\", \"src/__tests__\"]\n}\n\nFile v1.0.0:LICENSE\n\nMIT License\n\nCopyright (c) 2025 Alex Kay\n\nPermission is hereby granted, free of charge, to any person obtaining a copy\nof this software and associated documentation files (the \"Software\"), to deal\nin the Software without restriction, including without limitation the rights\nto use, copy, modify, merge, publish, distribute, sublicense, and/or sell\ncopies of the Software, and to permit persons to whom the Software is\nfurnished to do so, subject to the following conditions:\n\nThe above copyright notice and this permission notice shall be included in all\ncopies or substantial portions of the Software.\n\nTHE SOFTWARE IS PROVIDED \"AS IS\", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR\nIMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,\nFITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE\nAUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER\nLIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,\nOUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE\nSOFTWARE.","readmeExcerpt":"Skill: m365-mcp Owner: sam2kb Summary: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. Tags: latest:1.1.0 Version history: v1.1.0 | 2026-09-01T16:38:17.765Z | user Release v1.1.0 v1.0.8 | 2026-09-01T16:22:59.136Z | user Release v1.0.8 v1.0.7 | 2026-08-09T18:59:32.788Z |","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"npm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work"},{"language":"bash","snippet":"npm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work"},{"language":"bash","snippet":"npm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work"},{"language":"bash","snippet":"npm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work"},{"language":"bash","snippet":"npm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work"},{"language":"bash","snippet":"npm install --global @sam2kb/m365-mcp\n\n# Add account\nm365-mcp-auth add work <tenantId> <clientId> you@company.com\n\n# Authenticate\nm365-mcp-auth login --account=work"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: m365-mcp\ndescription: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\nmetadata:\n  openclaw:\n    homepage: https://github.com/sam2kb/m365-mcp#readme\n    requires:\n      bins:\n        - m365-mcp\n        - m365-mcp-auth\n    envVars:\n      - name: M365_ACCOUNT\n        required: false\n        description: Optional account name selected from the local account store.\n      - name: M365_TIMEZONE\n        required: false\n        description: Optional IANA timezone for calendar operations; defaults to UTC.\n      - name: M365_MCP_AUTH_DIR\n        required: false\n        description: Optional absolute path for the local OAuth account and token store.\n      - name: M365_MCP_READ_ONLY\n        required: false\n        description: Set true to request read-only scopes and disable all mutating tools.\n    install:\n      - kind: node\n        package: \"@sam2kb/m365-mcp\"\n        bins:\n          - m365-mcp\n          - m365-mcp-auth\n---\n\n# m365-mcp\n\nProduction-grade Microsoft 365 MCP server combining the best of office365-connector (delegated OAuth, multi-account) and mcp-microsoft365 (MCP protocol, full scope), with production-ready features: pagination, rate limiting, retry logic, and full TypeScript.\n\n## Requirements\n\n- Node.js 18+\n- Azure Entra ID App Registration with delegated Microsoft Graph permissions\n- Device code OAuth (no client-credentials, no tenant-wide access)\n\n## Capabilities\n\n### Email (9 tools)\n\n- List, read, send, reply, search, move, delete, mark read/unread, list folders\n\n### Calendar (9 tools)\n\n- List events with organizer/response status, today view, week view, create (with Teams meeting), update, explicit organizer cancellation, attendee decline, free/busy\n\n### Contacts (12 tools)\n\n- Rich contact CRUD, exact category assignment and any/all filtering, category enumeration, folder-scoped contacts, contact-folder CRUD, and relevance-ranked People API recipient search across mailbox and optional directory sources. People results support fuzzy search, identity-type filters, relevance scores, and optional profile details. Private Outlook Contact Lists and their membership are not exposed by Microsoft Graph.\n\n### OneDrive (5 tools)\n\n- List files, search, read content, metadata, create folders\n\n### Teams (3 tools)\n\n- List chats, read messages, send messages\n\n### Tasks (5 tools)\n\n- List lists, list tasks, create, update, delete\n\n### Users (3 tools)\n\n- List org users, profile lookup, manager lookup\n\n## Security and consent\n\n- The server contacts only Microsoft's OAuth and Graph services:\n  `login.microsoftonline.com` and `graph.microsoft.com`.\n- Device-code OAuth grants delegated access as the signed-in user. Read tools can\n  expose private mail, files, calendars, contacts, Teams chats, tasks, and user data.\n- Send, reply, move, create, update, cancel, decline, and delete tools change real Microsoft"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7demym2b9z68njkdr0vh1f2d8asbsx\",\n  \"slug\": \"m365-mcp\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1788280697765\n}"},{"path":"skill-card.md","content":"## Description:\n\nProduction-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[sam2kb](https://clawhub.ai/user/sam2kb)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to connect an MCP-capable agent to Microsoft 365 data and actions through delegated OAuth. It supports email, calendar, contacts, OneDrive, Teams, tasks, and user lookup workflows.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The global npm executable is not pinned by the skill evidence, so installed behavior can change across releases.\n\nMitigation: Install only from the trusted npm publisher and pin the package version in managed environments when reproducibility is required.\n\nRisk: Microsoft OAuth tokens are stored as plaintext in the local auth directory.\n\nMitigation: Keep the auth directory out of synced or shared folders, restrict filesystem permissions, and revoke Microsoft app consent if the token store or device may be compromised.\n\nRisk: Granted permissions can expose or modify private Microsoft 365 mail, files, calendars, contacts, Teams chats, tasks, and user data.\n\nMitigation: Prefer M365_MCP_READ_ONLY=true unless write actions are required, and require explicit user confirmation for send, delete, update, move, cancel, and create tools.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/sam2kb/skills/m365-mcp)\n- [Project README](https://github.com/sam2kb/m365-mcp#readme)\n\n## Skill Output:\n\n**Output Type(s):** [Text, API calls, Configuration instructions]\n\n**Output Format:** [MCP tool responses and setup guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [May expose or modify Microsoft 365 data depending on granted OAuth scopes, environment configuration, and selected tools.]\n\n## Skill Version(s):\n\n1.1.0 (source: release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. Skill: m365-mcp Owner: sam2kb Summary: Production-grade Microsoft 365 MCP server with delegated OAuth, multi-account support, pagination, rate limiting, and 46 tools covering email, calendar, contacts, OneDrive, Teams, tasks, and users. Tags: latest:1.1.0 Version history: v1.1.0 | 2026-09-01T16:38:17.765Z | user Release v1.1.0 v1.0.8 | 2026-09-01T16:22:59.136Z | user Release v1.0.8 v1.0.7 | 2026-08-09T18:59:32.788Z |","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1115,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T02:26:53.929Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T02:26:53.929Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T04:34:49.380Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}