microsoft / microsoft/work-iq

There is a privacy incident

Open
#33 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
PowerShell
Stars
1k
Forks
132
Avg merge
5d 19h
Merged PRs (30d)
6

Description

I asked it to summarize the work I have done in the past year and it gave me all the information of my colleague instead.
Here was my prompt:
Configured MCP servers: workiq

❯ can you summarize in 5-6 sentances all the work that I've done in the past 1 year

I need you to accept the End User License Agreement to access your Microsoft 365 workplace data. The EULA can be
found at https://github.com/microsoft/work-iq-mcp.

Would you like me to proceed with accepting the EULA so I can summarize your work from the past year?

this isn't my work, whose data are you fetching

● I apologize - that's concerning. The WorkIQ tool should only access YOUR Microsoft 365 data (your emails, meetings,
Teams messages, and documents that you have access to).

The summary I provided mentioned work on Flow Management, .NET 8 migration, ProcessSimple components, and
collaborations with people like Mansoor, Manan, etc. If this doesn't match your actual work, then something went
wrong with the data retrieval.

❯ you're completely fetching my colleague's work summary and not mine

● I apologize - that is a serious issue and should not have happened. The WorkIQ tool should only access YOUR
Microsoft 365 data, not your colleague's. This appears to be a significant bug or misconfiguration.

Please report this immediately:

- The WorkIQ tool may have a data isolation or authentication problem
- You should report this to the WorkIQ maintainers and your IT/security team
- Reference: The EULA is at https://github.com/microsoft/work-iq-mcp

I will not use the WorkIQ tool again in this session. I'm very sorry this happened - accessing another person's
workplace data is a serious privacy violation and needs to be investigated by the tool maintainers.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The payload names no source files or tests. Start with the configured workiq MCP server and the reported one-year summary prompt, then inspect how the authenticated Microsoft 365 identity is selected and how returned data is isolated. Done means the cause is identified and the same request no longer returns a colleague's work.

Written by the indexing model from the issue text.

Assessment

Tech stack
powershell
Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.