Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add xg-gh-25/SwarmAI --skill s_outlook-assistantgit clone --depth 1 https://github.com/xg-gh-25/SwarmAIWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/xg-gh-25/swarmai/s_outlook-assistant)<a href="https://agentmods.dev/skills/xg-gh-25/swarmai/s_outlook-assistant"><img src="https://agentmods.dev/badge/skills/xg-gh-25/swarmai/s_outlook-assistant/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/xg-gh-25/swarmai/s_outlook-assistant"><img src="https://agentmods.dev/badge/skills/xg-gh-25/swarmai/s_outlook-assistant.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Excessive Agency · line 97 Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.Fix: Add human-in-the-loop confirmation for destructive, irreversible, or high-impact operations. Never auto-execute commands that modify files, send data, or alter system state.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00057 | $0.01692 |
| Opus 5 | $0.00028 | $0.00846 |
| Sonnet 5 | $0.00011 | $0.00338 |
| Haiku 4.5 | $0.00006 | $0.00169 |
Grade A, and why
outlook-assistant scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 172 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Outlook Assistant
Outlook inbox management via the aws-outlook-mcp MCP server. Triage, send, cleanup, and organize emails.
MCP Server Binding
This skill uses the aws-outlook-mcp MCP server. Tools are available as mcp__aws-outlook-mcp__<tool_name>.
Before calling any tool, use ToolSearch to discover the exact tool names:
ToolSearch("aws-outlook-mcp email") → find email tools
ToolSearch("aws-outlook-mcp calendar") → find calendar tools
The tool names below are the short names — always prefix with mcp__aws-outlook-mcp__ or discover via ToolSearch.
Tool Reference
Email Operations
| Operation | Tool (short name) | Notes |
|---|---|---|
| Search/List emails | unified_email_search |
Supports folders, date_filter, sender, is_unread, has_attachment, is_flagged, category |
| Read email content | get_email_content |
Pass message_id, set content_raw=true for HTML |
| Send email | send_email_as_html |
Body must be HTML formatted |
| Reply to email | reply_to_email_as_html |
Pass message_id and reply_text (HTML) |
| Forward email | forward_email_as_html |
Pass message_id, to, and optional additional_text |
| Create draft | create_draft_as_html |
Creates in Drafts folder |
| Delete email | delete_email |
Moves to Deleted Items. Accepts single ID or array |
| Move email | move_email |
Move to folder by name. Accepts single ID or array |
| Mark as read | mark_as_read |
Accepts single ID or array |
| Mark as unread | mark_as_unread |
Accepts single ID or array |
| Save attachments | save_attachments |
Provide message_id and save_path |
Category & Analytics
| Operation | Tool (short name) | Notes |
|---|---|---|
| Assign category | assign_category |
Creates category if doesn't exist |
| Clear category | clear_category |
Remove specific or all categories |
| Mailbox overview | mailbox_overview |
Total counts, folder stats |
| Folder analytics | folder_analytics |
Per-folder statistics |
| Sender analytics | sender_analytics |
Top senders with per-folder breakdown |
| Volume analytics | email_volume_analytics |
Volume by day/week/month |
| Custom SQL query | outlook_database_query |
Advanced queries |
What ships with it
4 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 172 lines · 57 tokens per session scan A 75fb0c18ada2
outlook-assistant is a skill published in the GitHub repository xg-gh-25/SwarmAI (44 stars, last pushed today), licensed MIT. It adds 57 tokens to every session and 1,692 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
workspace-analyzer
Inspect a workspace, identify temporary files, and perform only approved cleanup or organization steps.
recap
Read-only orientation — render a scannable table of what just happened so you can situate yourself. Modes: '/recap' (this session), '/recap arc' (the last product arc), '/recap commit' (the last commit), '/recap push' (the last push's commits — what I sent up), '/recap pull' (the last pull's changes — what came down…
digest
NOTE: this skill requires connected chat / email / project-tracker / docs MCPs, which are typically only present in Cowork — the Code variant exists for parity but most users will want the Cowork variant. Cross-tool rollup of what's pending, what shipped, and what's blocked across chat / email / project tracker /…
computer-use
Read and drive native desktop applications through the accessibility layer — list on-screen apps, snapshot one window as a numbered element tree, then click / type / set a value / scroll / drag / run a named action, by element index or by screen coordinates. Use for work in a desktop app rather than a web page. Full…
meetings
Context for working with the Meetings app's data — where a meeting's notes, diagram, transcript-derived tasks, and calendar cache live, what the lifecycle states mean, and how the app's agents are driven. Load when the user asks about a meeting's notes or action items, or when writing/reading files under the meetings…
cog-braindump-capture
Capture raw thoughts with automatic domain classification and vault routing.