Introduction

When developing AI agents in a Windows environment, interacting with Outlook directly is a common requirement. However, enterprise environments often prohibit registering Graph API applications or do not provide tenant administrator privileges, making OAuth-based solutions difficult to implement. The dsh-outlook plugin for DSH Harness directly drives the locally logged-in desktop version of Outlook through COM interfaces, requiring no application registration or credential storage. It enables agents to read emails, manage calendars, and perform actions, while ensuring that all outbound content is manually confirmed.

Plugin Overview

dsh-outlook is a DSH plugin designed specifically for Windows environments. It uses COM technology to control the local Outlook client and achieve zero-credential automated operations. The plugin is maintained by UnknowCao and is licensed under MIT.

Core Features

The plugin provides 18 tools covering email, calendar, and contact operations. Read operations can be executed automatically; any outbound action (such as sending emails or creating meetings) must pass a three-layer human confirmation gate.

  • Email Management
    • outlook_check_new: Synchronize the sidebar badge when new emails arrive.
    • outlook_search_mail: Search emails by number of days, folder, sender, and date range.
    • outlook_read_mail: Read the full email body and attachment names.
    • outlook_open_mail: Open the email in desktop Outlook and mark it as read.
    • outlook_draft_mail: Create a draft (never sent automatically).
    • outlook_send_mail: Send an email.
    • outlook_reply_mail: Reply to or forward an email (automatically quotes the original message).
  • Calendar Management
    • outlook_calendar_query: Query schedules for the next N days.
    • outlook_calendar_create: Create a personal appointment or a meeting invitation.
    • outlook_meeting_requests: View meeting invitations that are awaiting a response.
    • outlook_respond_meeting: Accept or decline a meeting invitation.
    • outlook_meeting_update: Update a meeting.
    • outlook_meeting_cancel: Cancel a meeting or delete a personal appointment.
  • Resource Lookup
    • outlook_search_people: Search for people in the Global Address List (GAL).
    • outlook_freebusy: Query a colleague’s free and busy times.
    • outlook_search_rooms: Search for meeting rooms and their availability during a specified time slot.
  • Attachments and Account
    • outlook_save_attachment: Save an attachment locally.
    • outlook_account: Retrieve the current account name and SMTP settings.

Installation and Enabling

Ensure that the environment meets the following prerequisites:
* Windows operating system.
* Classic Outlook (Win32 OUTLOOK.EXE) is installed and logged in.
* Windows PowerShell 5.1 is available on the system.

The installation command is as follows:

dsh plugin --profile web add dsh-outlook

After installation, no additional credential configuration or application registration is required. Restart the profile to use it.

Typical Usage

Agents can invoke the above tools using natural language. Examples include:
1. “What new emails are there?”
2. “Search for the email Zhangsan sent last week about deliverables”
3. “Forward this one to Lisi, with a note asking him to confirm”
4. “Schedule a meeting with Wangwu next Wednesday; first check when he is free”
5. “Find a meeting room in Ningbo that is free from 2:00 p.m. to 3:00 p.m. tomorrow”

Use Cases and Notes

This plugin is suitable for permission-restricted enterprise environments where direct control of desktop Outlook is required.

  • Security Mechanism: All outbound operations (sending emails, meeting invitations, and similar actions) must pass three layers of human confirmation: a two-round confirmation protocol, content-hash binding, and independent bridge-layer token verification.
  • Runtime Behavior: The plugin runs with the permissions of the current DSH process and does not store or transmit mailbox credentials. Drafts are not sent automatically, nor is any content sent silently.
  • System Requirements: Only Windows with Classic Outlook is supported. Web-based Outlook is not supported. A PowerShell 5.1 environment is required.

Conclusion

dsh-outlook addresses the pain points of using the Graph API in restricted enterprise environments by providing a secure automation solution based on the local desktop Outlook client. All outbound content is subject to human review, making it suitable for automation scenarios with high security requirements.