What problem does it solve? In CTF and sandboxed enterprise-mail scenarios, it is hard to connect identity artifacts (tokens, consent grants, delegate edges) to concrete mailbox effects like silent forwarding, deletion, or rerouting. This Skill provides a structured workflow for proving exactly which rule, token, or transport configuration caused an observed mail behavior. ## Core Features & Use Cases - Mail Trust Path Mapping: Identifies principals, mailboxes, tokens, consent grants, delegate edges, shared mailbox relationships, and app registrations involved in an abuse chain. - Mailbox Effect Proof: Correlates consent logs, sign-ins, message traces, inbox rules, transport rules, and audit events to show which mechanism produced forwarding, deletion, marking read, or rerouting. - Abuse Chain Reduction: Compresses findings into the smallest replayable sequence proving persistence, exfiltration, or delegate access. - Use Case: During a CTF, you obtain an OAuth token and suspect inbox-rule persistence. Use this Skill to tie the consent scope, rule predicate, forwarding target, and message IDs into one evidence block that proves the exfiltration path. ## Quick Start Ask the assistant to trace how the captured OAuth consent grant and inbox rule produce silent forwarding for the target mailbox, keeping message IDs aligned across logs.