Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, email [email protected] and we’ll put it right.

io.github.littlebearapps/outlook-assistant

NPM · @LITTLEBEARAPPS/OUTLOOK-ASSISTANT · SCANNED AUG 4

Microsoft Outlook MCP server — 22 tools for email, calendar, contacts, and mailbox management.

+46 this week 70 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security83
  • No malware found by supply-chain analysis.Pass
  • CVE check failed: a known medium-severity CVE affects hono 4.12.33, reached via @modelcontextprotocol/sdk > hono. A fixed version is available. View diagnostics → Fail
  • No install/post-install scripts declared.Pass
  • Only part of the dependency tree could be resolved (95 of 99), so this covers what we could see, not the whole tree. View diagnostics → Partial
Provenance & Transparency97
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to littlebearapps/outlook-assistant). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 3 days ago).Pass
  • Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability53
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 7975 tokens (~362/item across 22 items; 22 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · @littlebearapps/outlook-assistant

# add to Claude Code
claude mcp add littlebearapps-outlook-assistant -- npx -y @littlebearapps/outlook-assistant
# add to Codex CLI
codex mcp add littlebearapps-outlook-assistant -- npx -y @littlebearapps/outlook-assistant
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "littlebearapps-outlook-assistant": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@littlebearapps/outlook-assistant"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add littlebearapps-outlook-assistant --command npx --arg -y --arg @littlebearapps/outlook-assistant
# ~/.hermes/config.yaml
mcp_servers:
  littlebearapps-outlook-assistant:
    command: "npx"
    args: ["-y", "@littlebearapps/outlook-assistant"]
// mcp.json
{
  "mcpServers": {
    "littlebearapps-outlook-assistant": {
      "command": "npx",
      "args": [
        "-y",
        "@littlebearapps/outlook-assistant"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Aug 26 −1
    • CVE-2026-69207 affects this package: medium security
    • Known CVEs: partial → fail security
  • 2 Aug 26 +54
    • Install scripts: unverified → pass security
    • Provenance: unverified → pass security
    • Known CVEs: unverified → partial security
    • Malware scan: unverified → pass security
    • Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window). security
    • The attested source repository moved: littlebearapps/outlook-assistant security
    • License: unverified → pass functional
    • Dependency health: unverified → partial functional
    • Maintenance: unverified → pass functional
    • MCP protocol: unverified → pass functional
    • Schema quality: unverified → good functional
    • Licence: MIT functional
  • 1 Aug 26 +12
    • Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet. security
    • Tool coverage: unverified → 100 functional
    • First check of Schema quality: unverified functional
    • First check of Tool coverage: 100 functional
    • First check of Schema quality: fail functional
    • First check of Schema quality: fail functional
    • Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet. functional
    • Package version: 3.9.0 → 3.9.1 functional
  • 31 Jul 26 −1
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 30 Jul 26 −18
    • Malware scan: pass → unverified security
  • 27 Jul 26 24

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 4 Aug 2026 · Analysed npm/@littlebearapps/[email protected]

Provenance verified

Ecosystem: npm · Outcome: verified

Reason: verified

Source repo:
littlebearapps/outlook-assistant
Certificate issuer:
https://token.actions.githubusercontent.com
Certificate SAN:
https://github.com/littlebearapps/outlook-assistant/.github/workflows/publish.yml@refs/tags/v3.9.1
Rekor log index:
2309819618
Predicate type:
https://slsa.dev/provenance/v1
Subject digest:
sha512:e99a1fcd22a0f9cdb85e3a35811b5e14d5e5ae8f6b8b64a9aba627ab7ac5839b74c32169fa6b1e62f36eb936f848483f3cb23e2a7aed23b2a089b3234
Discovery method:
attestation_endpoint
Vulnerabilities 1 finding
ID CVE Severity Vector Fix available
GHSA-8j4g-w8fx-2239 CVE-2026-69207 medium CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L yes
Dependencies 95 packages

95 packages in the resolved dependency tree · 95 deprecated · 29 stale.

The dependency tree was only partially resolved, so these counts may be incomplete.

MCP tools — 22 exposed · ~7,975 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
access-shared-mailbox ~243

List emails from a shared mailbox the signed-in user has been granted access to (read-only). Returns paged messages from the named `sharedMailbox` (or alias `email`) and `folder` (default `inbox`) with id/subject/from/receivedDateTime/preview — same shape as `search-emails` list mode. Requires that the shared mailbox has been delegated to the signed-in user in Exchange (admin-configured). Use `outputVerbosity` to control field count and `count` (default 25, max 50) for page size. For full search/filter capability over a shared mailbox, prefer `search-emails` with a folder path scoped to the shared mailbox.

NameTypeReqDescription
countnumberNumber of emails to retrieve (default: 25, max: 50)
emailstringAlias for `sharedMailbox` (more intuitive name for the same value).
folderstringFolder to read from (default: inbox)
outputVerbositystringOutput detail level (default: standard)
sharedMailboxstringEmail address of the shared mailbox (required)

No output schema declared.

No examples provided.

apply-category ~199

Tag or untag email messages with master categories (those created via `manage-category`). action=`set` (default) replaces the message's category set with the supplied `categories` array. action=`add` appends categories to whatever's already on the message. action=`remove` removes only the named categories, leaving the rest. Accepts either `messageId` (single) or `messageIds` (batch via Graph `$batch`). `categories` are matched by display name — names must already exist in the master list (create via `manage-category` first). Returns per-message confirmation.

NameTypeReqDescription
actionstringset (replace all), add (append), remove (remove specific). Default: set
categoriesarrayyesCategory display names to apply/remove (required)
messageIdstringSingle message ID to categorise
messageIdsarrayArray of message IDs to categorise (batch operation)

No output schema declared.

No examples provided.

attachments ~225

Inspect or retrieve email attachments. action=`list` (default) returns metadata for all attachments on `messageId` (id, name, contentType, size, isInline) — read-only. action=`view` returns inline content for text/JSON/XML attachments via `attachmentId`; binary types require download. action=`download` saves the attachment to disk at `outputDir` (default system tmpdir, auto-created) and returns the saved file path. `messageId` is required for all actions; `attachmentId` is required for view/download. Use `outputVerbosity` to control list field count.

NameTypeReqDescription
actionstringAction to perform (default: list)
attachmentIdstringAttachment ID (action=view/download, required)
messageIdstringyesEmail message ID (required)
outputDirstringDirectory to save file (action=download, default: system tmpdir). Auto-created if missing.
savePathstringDEPRECATED alias for `outputDir`. Will be removed in a future release.

No output schema declared.

No examples provided.

auth ~280

Manage authentication with the Microsoft Graph API. action=`status` (default) returns the current auth state and auto-refreshes the access token if it's expired but the refresh token is still valid (~90-day window) — call this first to check before other tools. action=`authenticate` starts the OAuth flow: with `method: "device-code"` (default, works headlessly) it returns a code + URL for the user to visit; with `method: "browser"` it opens the local auth server on :3333 (run `npm run auth-server` first). Pass `force: true` to re-authenticate over an existing valid session. action=`device-code-complete` finishes device-code auth after the user enters the code in their browser — call this once authentication shows as successful in the browser. action=`about` returns server version, configured audience, scope list, and other diagnostic info. Tokens persist to `~/.outlook-assistant-tokens.json` and survive server restarts.

NameTypeReqDescription
actionstringAction to perform (default: status)
forcebooleanForce re-authentication even if already authenticated (action=authenticate only)
methodstringAuth method for action=authenticate. device-code (default): no auth server needed, works remotely. browser: traditional OAuth redirect via port 3333.

No output schema declared.

No examples provided.

create-event ~196

Create a new calendar event on the signed-in user's default calendar. Returns the created event with its `id`, `webLink`, and (if attendees are present) an auto-generated online-meeting URL — attendees receive invitations on save. Times use the configured timezone (default Australia/Melbourne; override with `OUTLOOK_DEFAULT_TIMEZONE`); omit the `Z` suffix to send local time. Use `manage-event` action=`update` to modify an event after creation, or `manage-event` action=`cancel`/`delete` to remove it.

NameTypeReqDescription
attendeesarrayList of attendee email addresses
bodystringOptional body content for the event
endstringyesThe end time of the event in ISO 8601 format
startstringyesThe start time of the event in ISO 8601 format
subjectstringyesThe subject of the event

No output schema declared.

No examples provided.

draft ~387

Full draft lifecycle for review-before-send workflows (destructive: covers `send` and `delete`). action=`create` saves a new draft in the Drafts folder and returns its id (use `dryRun: true` to preview without saving; `checkRecipients: true` runs mail-tips first). action=`update` patches an existing draft by `id` (only fields passed are changed). action=`send` dispatches an existing draft — shares the rate limit with `send-email`. action=`delete` removes a draft permanently. action=`reply`/`reply-all` creates a reply draft from a message `id` (use `comment` to prepend text — mutually exclusive with `body`). action=`forward` creates a forward draft (requires `id` and `to`). Recipient allowlist applies to create/update/forward. Returns the draft object on create/update/reply/forward; status confirmation on send/delete.

NameTypeReqDescription
actionstringyesAction to perform (required)
bccstringComma-separated BCC email addresses
bodystringEmail body (plain text or HTML)
ccstringComma-separated CC email addresses
checkRecipientsbooleanCheck recipients for out-of-office, delivery restrictions before saving (action=create, default: false)
commentstringComment text for reply/forward (prepended to original message). Cannot combine with body.
dryRunbooleanPreview draft without saving (action=create only, default: false)
idstringDraft or message ID. Required for update/send/delete/reply/reply-all/forward.
importancestringEmail importance (default: normal)
subjectstringEmail subject
tostringComma-separated recipient email addresses (optional for create/update, required for forward)

No output schema declared.

No examples provided.

export ~581

Export emails to file formats for archival, forensics, or programmatic processing. target=`message` (default) exports a single email by `id` to `savePath` — accepts `mime`/`eml`/`markdown`/`json`/`csv`. target=`messages` batch-exports either an explicit `emailIds` array or messages matching `searchQuery` (or `query` shortcut) into `outputDir` — accepts `markdown`/`json`/`csv`. target=`conversation` exports a full thread by `conversationId` into `outputDir` (chronological by default; pass `order: "reverse"` for newest-first) — accepts `eml`/`mbox`/`markdown`/`json`/`html`/`csv`. target=`mime` returns raw RFC-822 MIME bytes for `id` (use `headersOnly` for just headers, `base64` for encoded transport, `maxSize` to cap at default 1MB). `includeAttachments` defaults to true for single-message exports and false for batch. Format support varies by target — see the format param enum.

NameTypeReqDescription
base64booleanReturn base64 encoded (target=mime)
conversationIdstringConversation ID (target=conversation, required)
emailIdsarrayEmail IDs to export (target=messages)
formatstringExport format. Valid values vary by target: target=message accepts mime/eml/markdown/json/csv (mbox and html are conversation-only). target=conversation accepts eml/mbox/markdown/json/html/csv. targe…
headersOnlybooleanMIME headers only, no body (target=mime)
idstringEmail ID (target=message/mime, required)
includeAttachmentsbooleanInclude attachments (default: true for single, false for batch)
maxSizenumberMax content size in bytes (target=mime, default: 1MB)
orderstringMessage order (target=conversation, default: chronological)
outputDirstringOutput directory (target=messages/conversation, required)
querystringFree-text search shortcut (target=messages). Equivalent to passing searchQuery: { subject: <query> }. Convenience alias for callers used to search-emails.
savePathstringFile path or directory (target=message)
searchQueryobjectSearch query to find emails (target=messages, alternative to emailIds)
targetstringExport target (default: message)

No output schema declared.

No examples provided.

find-meeting-rooms ~169

Discover bookable meeting rooms in the user's organisation via the Graph rooms endpoint (read-only). Returns room resources with displayName, emailAddress, building, floor, capacity, and bookingType — suitable for piping into `create-event` as attendees. Filter by `query` (matches name/email), `building`, `floor`, or minimum `capacity`. Returns empty list on personal accounts (the rooms endpoint is M365-only). Use `outputVerbosity` to control field count.

NameTypeReqDescription
buildingstringFilter by building name
capacitynumberMinimum capacity required
floornumberFilter by floor number
outputVerbositystringOutput detail level (default: standard)
querystringSearch query (room name, email)

No output schema declared.

No examples provided.

folders ~633

Manage mail folders (tool-level destructiveHint=true because `delete` permanently removes a folder; `list` and `stats` are read-only sub-actions despite the annotation). Folders can be addressed by name, by a slash-separated PATH for nested folders (e.g. `Triage/Delete`, `Inbox/Clients/Acme`, case-insensitive), or by explicit ID; `list` output includes each folder's full path and `[id: …]`. A bare name resolves a unique top-level folder first, then searches nested folders (ambiguous names return the candidates — disambiguate with a path or ID). action=`list` (default) returns the folder tree (toggle `includeItemCounts` for unread/total, `includeChildren` for hierarchy). action=`create` makes a new folder under the root, or under `parentFolder` (name/path) / `parentFolderId`, and returns its id. action=`move` relocates emails (`emailIds`) into `targetFolder` (name/path) or `targetFolderId`. action=`stats` returns counts (totalItemCount/unreadItemCount) for `folder` (name/path) or `folderId`, suitable for pagination planning. action=`delete` removes a folder (by `folderName`/path or `folderId`) and its contents — on Outlook.com the folder is moved to Deleted Items (recoverable until you empty it); M365/Exchange accounts may hard-delete per retention policy.

NameTypeReqDescription
actionstringAction to perform (default: list)
emailIdsstringComma-separated list of email IDs to move (action=move, required)
folderstringFolder name or path (inbox, sent, "Triage/Delete", etc.). Default: inbox (action=stats)
folderIdstringFolder ID (action=stats/delete)
folderNamestringFolder name or path to delete — resolved to ID (action=delete). Cannot delete protected folders (Inbox, Drafts, Sent, etc.)
includeChildrenbooleanInclude child folders in hierarchy (action=list)
includeItemCountsbooleanInclude counts of total and unread items (action=list)
namestringName of the folder to create (action=create, required)
outputVerbositystringOutput detail level (action=stats, default: standard)
parentFolderstringParent folder name or path (e.g. "Clients/Acme"); default is root (action=create)
parentFolderIdstringParent folder ID — alternative to parentFolder for unambiguous targeting (action=create)
sourceFolderstringSource folder name, default is inbox (action=move)
targetFolderstringDestination folder name or path, e.g. "Triage/Delete" (action=move; or use targetFolderId)
targetFolderIdstringDestination folder ID — alternative to targetFolder for unambiguous/nested targeting (action=move)

No output schema declared.

No examples provided.

get-mail-tips ~237

Pre-send recipient validation via Graph `POST /me/getMailTips` (read-only; uses the existing `Mail.Read` scope — no extra permissions). Returns per-recipient tips covering automatic replies (out-of-office), mailbox full status, custom admin mail tips, delivery restrictions, moderation requirements, external-vs-internal scope, max message size, and group member counts (total + external). Use ahead of `send-email` or `draft` action=`create` to catch issues like OOO replies or external-recipient warnings before the message goes out; `send-email`/`draft` accept `checkRecipients: true` to invoke this automatically. Accepts either a comma-separated string or an array of addresses; `tipTypes` filters which tips are requested (defaults to all).

NameTypeReqDescription
recipientsyesEmail addresses to check for mail tips
tipTypesstringComma-separated tip types to request (default: all). Options: automaticReplies, mailboxFullStatus, customMailTip, externalMemberCount, totalMemberCount, maxMessageSize, deliveryRestriction, moderatio…

No output schema declared.

No examples provided.

list-events ~182

List upcoming calendar events for the signed-in user (read-only). Returns an array of events with id, subject, start/end, attendees, location, organiser, and webLink. Use `count` (default 10, max 50) to control page size; this tool does not filter — use the Outlook UI or specific date ranges via Graph for filtered queries. Each start/end is returned as a canonical UTC ISO-8601 instant (e.g. `2026-04-02T22:00:00.000Z`) followed by a labelled local rendering in the configured display timezone (default Australia/Melbourne; override with `OUTLOOK_DEFAULT_TIMEZONE`) — the UTC value is authoritative, so consumers never have to guess the zone.

NameTypeReqDescription
countnumberNumber of events to retrieve (default: 10, max: 50)

No output schema declared.

No examples provided.

mailbox-settings ~469

Read or update mailbox-level settings (idempotent — safe to retry; sets are PATCH-style and merge with existing state). action=`get` (default) returns settings — use `section` to filter (`language`, `timeZone`, `workingHours`, `automaticRepliesSetting`, or `all`). action=`set-auto-replies` configures out-of-office: `enabled` true/false, optional `startDateTime`/`endDateTime` (ISO 8601) for scheduled mode, `internalReplyMessage` and (optionally) `externalReplyMessage`. action=`set-working-hours` updates the schedule: `startTime`/`endTime` (HH:MM) and `daysOfWeek` (array of `monday`..`sunday`). Returns the updated settings object on set actions.

NameTypeReqDescription
actionstringAction to perform (default: get)
daysOfWeekarrayWork days, e.g. ['monday','tuesday','wednesday','thursday','friday'] (action=set-working-hours)
enabledbooleanEnable (true) or disable (false) automatic replies (action=set-auto-replies)
endDateTimestringEnd date/time for scheduled mode, ISO 8601 format (action=set-auto-replies)
endTimestringWork end time in HH:MM format, e.g. '17:00' (action=set-working-hours)
externalAudiencestringWho receives external reply (action=set-auto-replies)
externalReplyMessagestringReply message for external senders (action=set-auto-replies)
internalReplyMessagestringReply message for internal senders (action=set-auto-replies)
sectionstringSpecific section to retrieve (action=get, default: all)
startDateTimestringStart date/time for scheduled mode, ISO 8601 format (action=set-auto-replies)
startTimestringWork start time in HH:MM format, e.g. '09:00' (action=set-working-hours)
timeZonestringTime zone name, e.g. 'Australia/Melbourne' (action=set-working-hours)

No output schema declared.

No examples provided.

manage-category ~271

Manage the user's master category list (the colour-coded labels available across mail/calendar/contacts). action=`list` (default) returns categories with id/displayName/color. action=`create` adds a new category — `displayName` required, `color` optional (preset0-preset24, e.g. preset0=Red, preset7=Blue). action=`update` (alias `set` — deprecated) changes name/colour by `id`. action=`delete` removes a category — this does NOT untag messages already labelled with it; existing messages retain the orphaned label until manually cleaned. Use `apply-category` to tag/untag specific messages.

NameTypeReqDescription
actionstringAction to perform (default: list). 'set' is a deprecated alias for 'update'.
categoryIdstringDEPRECATED: alias for `id`. Will be removed in a future release.
colorstringColor preset, e.g. preset0=Red, preset7=Blue (action=create/update)
displayNamestringCategory name (action=create required, action=update optional)
idstringCategory ID (action=update/delete, required)
outputVerbositystringOutput detail level (action=list, default: standard)

No output schema declared.

No examples provided.

manage-contact ~468

Full CRUD over the signed-in user's personal Outlook contacts (destructive: covers `delete` action). action=`list` (default) returns contacts with pagination via `skip`/`count` (default 50). action=`search` returns contacts matching `query` against name/email (default 25). action=`get` returns full contact detail by `id`. action=`create` adds a new contact and returns its `id`. action=`update` patches the given fields by `id` (only fields passed are changed). action=`delete` permanently removes the contact by `id`. Use `outputVerbosity` (minimal/standard/full) on list/search to control field count. Prefer `search-people` for cross-source relevance ranking (contacts + directory + recent comms) — this tool only searches your personal contact store.

NameTypeReqDescription
actionstringAction to perform (default: list)
companyNamestringCompany name (action=create/update)
countnumberNumber of results (action=list default: 50, action=search default: 25)
displayNamestringFull name (action=create/update)
emailstringPrimary email address (action=create/update)
emailsarrayMultiple email addresses (action=create/update). First entry is primary.
firstNamestringGiven name (action=create/update). Maps to Graph `givenName`. If displayName not provided, will be combined with lastName.
folderstringContact folder ID (action=list)
idstringContact ID (action=get/update/delete, required)
jobTitlestringJob title (action=create/update)
lastNamestringSurname (action=create/update). Maps to Graph `surname`.
mobilePhonestringMobile phone number (action=create/update)
notesstringPersonal notes (action=create/update)
outputVerbositystringOutput detail level (action=list/search, default: standard)
querystringSearch query for name or email (action=search, required)
skipintegerPagination offset for action=list (default: 0). Use the value suggested by the previous page response.

No output schema declared.

No examples provided.

manage-event ~504

Manage an existing calendar event (destructive: covers update/decline/cancel/delete — use dryRun where supported to preview). action=`update` edits fields in place via PATCH (subject, start, end, attendees, body, location, isOnlineMeeting, sensitivity, showAs, importance, categories, reminderMinutesBeforeStart) — only fields you pass are changed; pass `dryRun: true` to preview the PATCH payload. action=`decline` declines an invitation (optional `comment`). action=`cancel` cancels an event you organised and notifies attendees. action=`delete` permanently removes the event. Returns the updated event on update; status confirmation otherwise. Note: there is no `accept` action — accept invitations in the Outlook UI (Graph's accept verb is unreliable across personal/M365).

NameTypeReqDescription
actionstringyesAction to perform (required)
attendeesarrayFull replacement attendee list — pass complete desired list, or [] to clear (action=update only)
bodystringNew body content (action=update only)
categoriesarrayFull replacement category list — pass [] to clear (action=update only)
commentstringOptional comment for declining or cancelling the event
dryRunbooleanPreview the PATCH without applying it (action=update only). Returns the body that would be sent to Graph.
endNew end time as ISO 8601 string or {dateTime, timeZone} object (action=update only)
eventIdstringThe ID of the event
idstringAlias for `eventId` (canonical per the v3.7.3 alias pass).
importancestringEvent importance flag (action=update only)
isOnlineMeetingbooleanToggle online meeting flag (action=update only)
locationstringNew location display name (action=update only)
reminderMinutesBeforeStartnumberMinutes before start to fire the reminder (action=update only)
sensitivitystringEvent sensitivity classification (action=update only)
showAsstringFree/busy status shown to others (action=update only)
startNew start time as ISO 8601 string or {dateTime, timeZone} object (action=update only)
subjectstringNew subject (action=update only)

No output schema declared.

No examples provided.

manage-focused-inbox ~211

Manage Focused Inbox sender overrides — explicit rules that force messages from a given sender into Focused or Other regardless of the ML classifier. action=`list` (default) returns existing overrides with id/sender/classifyAs. action=`set` creates or updates an override for `emailAddress` (optional `name`), routing future mail to `focused` (default) or `other`. action=`delete` removes the override for `emailAddress`. Note: this only works on accounts that have Focused Inbox enabled — personal Outlook.com accounts without it return an empty list.

NameTypeReqDescription
actionstringAction to perform (default: list)
classifyAsstringWhere to put emails from this sender (action=set, default: focused)
emailAddressstringSender email address (action=set/delete, required)
namestringSender display name (action=set)
outputVerbositystringOutput detail level (action=list, default: standard)

No output schema declared.

No examples provided.

manage-rules ~961

Server-side inbox rule CRUD (destructive: covers `delete`; supports `dryRun` on create/update for preview). Rules run on the Exchange server regardless of which client is open. action=`list` (default) returns rules with id/name/sequence — pass `includeDetails: true` to expand conditions/actions/exceptions. action=`create` builds a new rule from condition params (12 supported: fromAddresses, containsSubject, bodyContains, hasAttachments, importance, sentTo, sensitivity, etc.), action params (9 supported: moveToFolder, forwardTo, redirectTo, assignCategories, markAsRead, delete, etc.), and optional `except*` exceptions. action=`update` patches the named fields by `ruleId`. action=`reorder` changes execution priority via `sequence` (lower = earlier). action=`delete` removes a rule. Recipient allowlist applies to forwardTo/redirectTo. `permanentDelete` action is intentionally omitted (too dangerous for AI use — use the Outlook UI). Subject to session rate limits (`OUTLOOK_MAX_MANAGE_RULES_PER_SESSION`).

NameTypeReqDescription
actionstringAction to perform (default: list)
assignCategoriesstringComma-separated Outlook categories to assign (action=create/update)
bodyContainsstringComma-separated body text keywords (OR logic) (action=create/update)
bodyOrSubjectContainsstringComma-separated keywords matching body OR subject (OR logic) (action=create/update)
containsSubjectstringComma-separated subject keywords (OR logic). e.g. "invoice, receipt, payment" (action=create/update)
copyToFolderstringFolder name to copy matching emails to (action=create/update)
deleteMessagebooleanMove matching emails to Deleted Items (action=create/update)
displayNamestringAlias for `name` (matches Graph's own `displayName` field).
dryRunbooleanPreview rule without creating/updating (action=create, action=update)
exceptBodyContainsstringComma-separated body keywords to exclude (action=create/update)
exceptFromAddressesstringComma-separated sender emails to exclude (action=create/update)
exceptHasAttachmentsbooleanExclude emails with attachments (action=create/update)
exceptSenderContainsstringComma-separated partial sender matches to exclude (action=create/update)
exceptSubjectContainsstringComma-separated subject keywords to exclude (action=create/update)
forwardTostringComma-separated emails to forward matching messages to (action=create/update)
fromAddressesstringComma-separated sender emails to match (action=create/update)
hasAttachmentsbooleanMatch emails with attachments (action=create/update)
importancestringMatch emails with this importance (action=create/update)
includeDetailsbooleanInclude detailed conditions, actions, and exceptions (action=list)
isAutomaticReplybooleanMatch automatic reply emails (action=create/update)
isEnabledbooleanEnable/disable rule (action=create default: true, action=update)
markAsReadbooleanMark matching emails as read (action=create/update)
markImportancestringSet importance on matching emails (action=create/update)
moveToFolderstringFolder name to move matching emails to (action=create/update)
namestringRule name (action=create required, action=update to rename)
recipientContainsstringComma-separated partial recipient matches (action=create/update)
redirectTostringComma-separated emails to redirect matching messages to (action=create/update)
ruleIdstringID of existing rule (action=update/delete)
ruleNamestringName of existing rule (action=update/reorder/delete)
senderContainsstringComma-separated partial sender matches (action=create/update)
sensitivitystringMatch emails with this sensitivity (action=create/update)
sentCcMebooleanMatch emails where I am in CC (action=create/update)
sentOnlyToMebooleanMatch emails where I am the only recipient (action=create/update)
sentToAddressesstringComma-separated recipient emails to match (action=create/update)
sentToMebooleanMatch emails sent to me (action=create/update)
sequencenumberExecution order, lower = higher priority (action=create default: auto, action=reorder required)
stopProcessingRulesbooleanStop evaluating subsequent rules (action=create/update)

No output schema declared.

No examples provided.

read-email ~295

Read a single email by id (read-only). Default: returns the full message body (HTML stripped to text by default), subject, from/to/cc, receivedDateTime, conversationId, attachments metadata, and webLink as Markdown. With `headersMode: true`: returns RFC-822 forensic headers instead (DKIM, SPF, DMARC, Received chain, Message-ID, Authentication-Results) — pair with `importantOnly: true` for the security-relevant subset, `groupByType: true` for category-bucketed view, or `raw: true` for JSON instead of Markdown. With `includeHeaders: true` (non-headers-mode): adds basic headers alongside body. Use `outputVerbosity` (minimal/standard/full) to control field count.

NameTypeReqDescription
groupByTypebooleanGroup headers by category (headersMode only, default: false)
headersModebooleanReturn forensic headers instead of email content (default: false)
idstringyesID of the email to read
importantOnlybooleanShow only important headers (headersMode only, default: false)
includeHeadersbooleanInclude basic headers alongside email content (default: false)
outputVerbositystringOutput detail level (default: standard)
rawbooleanReturn raw JSON instead of Markdown (headersMode only, default: false)

No output schema declared.

No examples provided.

search-emails ~757

Search, list, delta-sync, or thread-group emails — six modes selected by parameters (read-only). With no params: lists recent emails in `folder` (default `inbox`). With `query`/`from`/`to`/`subject`/date filters: full search (combines via OData filter). With `searchExpression` (deprecated alias `kqlQuery`): a raw Microsoft Graph `$search` expression for advanced server-side search. With `deltaMode: true`: returns current state plus a `deltaToken`; pass the token back on the next call for incremental changes only — ideal for inbox monitoring. With `groupByConversation: true`: returns conversation threads. With `conversationId`: returns all messages in a single thread. With `internetMessageId`: looks up a message by its RFC Message-ID header. Personal Outlook.com accounts have limited `$search` support — this tool falls back through OData filters / boolean filters / recent listing automatically, but structured filters (`from`/`subject`/`receivedAfter`/`hasAttachments`/`unreadOnly`) return cleaner results. Returns paged messages with id/subject/from/receivedDateTime/preview by default; use `outputVerbosity` to expand.

NameTypeReqDescription
conversationIdstringGet all messages in a conversation thread by conversationId.
countnumberNumber of results (list default: 25, search default: 10, max: 50)
deltaModebooleanEnable delta sync mode. Returns only changes since last sync. Use deltaToken for subsequent calls.
deltaTokenstringToken from previous delta call for incremental sync (deltaMode only)
folderstringEmail folder (default: 'inbox')
fromstringFilter by sender email/name
groupByConversationbooleanList conversations (threads) grouped by conversationId instead of individual emails.
hasAttachmentsbooleanFilter to emails with attachments
includeHeadersbooleanInclude email headers for each message (conversationId only)
internetMessageIdstringLook up email by Message-ID header (e.g. <[email protected]>). For threading/deduplication.
kqlQuerystringDEPRECATED alias for `searchExpression` (this was never full KQL — it is a Graph `$search` expression). Prefer `searchExpression`.
maxResultsnumberMax results per page for delta sync (default: 100, max: 200)
outputVerbositystringOutput detail level (default: standard)
querystringSearch query text. Omit for list mode.
receivedAfterstringFilter emails received after date (ISO 8601)
receivedBeforestringFilter emails received before date (ISO 8601)
searchAllFoldersbooleanSearch across all mail folders
searchExpressionstringRaw Microsoft Graph `$search` expression for advanced server-side search, e.g. `subject:"invoice"`, `from:github.com`, or `foo OR bar`. Quote your own phrases; a single bare token is auto-quoted. Pai…
subjectstringFilter by subject
tostringFilter by recipient email/name
unreadOnlybooleanFilter to unread emails only

No output schema declared.

No examples provided.

search-people ~134

Relevance-ranked search across personal contacts, organisation directory, and recent communications via the Microsoft Graph People API (read-only). Returns people objects with `displayName`, `emailAddresses`, `companyName`, `jobTitle`, and relevance metadata — ideal for "who is X?" or "who do I email about Y?" lookups. Use `manage-contact` action=`search` instead when you specifically need entries from your personal contact store only.

NameTypeReqDescription
countnumberMaximum results to return (default: 25, max: 50)
querystringyesSearch query (name, email, company)

No output schema declared.

No examples provided.

send-email ~331

Compose and send an email immediately (destructive: sends external comms). Returns a confirmation with the saved-message id. Safety controls: `dryRun: true` returns the composed message for review without sending; `checkRecipients: true` runs `get-mail-tips` first to flag out-of-office / mailbox-full / delivery-restricted / external recipients; combine both for a full pre-send review. Subject to session rate limits (`OUTLOOK_MAX_EMAILS_PER_SESSION` env) and recipient allowlist (`OUTLOOK_ALLOWED_RECIPIENTS` env) when configured — calls outside the allowlist fail before any Graph request. For multi-step compose/review workflows prefer `draft` (action=`create` → `update` → `send`) since drafts can be inspected in Outlook before sending. Comma-separated recipient strings or arrays both accepted.

NameTypeReqDescription
bccstringComma-separated BCC email addresses
bodystringyesEmail body (plain text or HTML)
ccstringComma-separated CC email addresses
checkRecipientsbooleanCheck recipients for out-of-office, mailbox full, delivery restrictions before sending (default: false). Combine with dryRun=true for pre-send review.
dryRunbooleanPreview email without sending (default: false). Returns composed email for review.
importancestringEmail importance (default: normal)
saveToSentItemsbooleanSave to sent items (default: true)
subjectstringyesEmail subject
tostringyesComma-separated recipient email addresses

No output schema declared.

No examples provided.

update-email ~242

Update message state without modifying content (idempotent — safe to retry). action=`mark-read`/`mark-unread` toggles the `isRead` flag on a single message by `id`. action=`flag` sets a follow-up flag with optional `dueDateTime`/`startDateTime` (ISO 8601). action=`unflag` clears the flag. action=`complete` marks the flag as done. Flag/unflag/complete accept either `id` (single) or `ids` (batch array) — batch operations use Graph `$batch` for efficiency. Returns status confirmation per message.

NameTypeReqDescription
actionstringyesAction to perform (required)
dueDateTimestringDue date/time for follow-up, ISO 8601 (action=flag)
idstringSingle message ID (required for mark-read/mark-unread, or use instead of ids for flag actions)
idsarrayArray of message IDs for batch flag/unflag/complete operations
startDateTimestringStart date/time for follow-up, ISO 8601 (action=flag)

No output schema declared.

No examples provided.