
Security News
Attackers Are Hunting High-Impact Node.js Maintainers in a Coordinated Social Engineering Campaign
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.
@microsoft/workiq
Advanced tools
Query your Microsoft 365 data with natural language — emails, meetings, documents, Teams messages, and more.
Work IQ is a CLI and an MCP (Model Context Protocol) server that connects AI assistants to your Microsoft 365 Copilot data. Ask questions like "What did my manager say about the project deadline?" or "Find my recent documents about Q4 planning."
See project README for usage details.
--noCors option to the A2A server command to disable CORS restrictions.enableMacBroker support in the config set command for macOS broker opt-in.Trace log level that surfaces MSAL SDK logging for auth diagnostics.os_current_account.DefaultAccount to enable cached token retrieval.logout command.--fileUrls parameter to the ask command and the ask MCP tool.mcpName to packages.json to enable publishing to the mcp registry.--account property for selecting between different loginsexperimental flag in the config.By using this package, you accept the license agreement. See NOTICES.TXT and EULA within the package or at this repository for legal terms.
This project may contain trademarks or logos for projects, products, or services. Authorized use of Microsoft trademarks or logos is subject to and must follow Microsoft’s Trademark & Brand Guidelines. Use of Microsoft trademarks or logos in modified versions of this project must not cause confusion or imply Microsoft sponsorship. Any use of third-party trademarks or logos are subject to those third-party’s policies.
FAQs
MCP server for Microsoft 365 Copilot
The npm package @microsoft/workiq receives a total of 25,051 weekly downloads. As such, @microsoft/workiq popularity was classified as popular.
We found that @microsoft/workiq demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
Multiple high-impact npm maintainers confirm they have been targeted in the same social engineering campaign that compromised Axios.

Security News
Axios compromise traced to social engineering, showing how attacks on maintainers can bypass controls and expose the broader software supply chain.

Security News
Node.js has paused its bug bounty program after funding ended, removing payouts for vulnerability reports but keeping its security process unchanged.