ms365-tenant-manager

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides comprehensive Microsoft 365 administration capabilities, including tenant setup, user lifecycle management, and security policy configuration. The implementation uses official Microsoft modules and APIs.
  • [SAFE]: Documentation and instructions consistently follow security best practices, such as recommending Multi-Factor Authentication (MFA), advising against hardcoded credentials, and suggesting the use of Azure Key Vault and Privileged Identity Management (PIM).
  • [DYNAMIC_EXECUTION]: The skill generates PowerShell automation scripts by interpolating user input (such as domain names, email addresses, and policy configurations) into predefined templates in powershell_generator.py and user_management.py. This is the primary intended function of the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data sources, such as CSV files for bulk user creation, and interpolate these values into administrative scripts.
  • Ingestion points: CSV files processed in user_management.py and powershell_generator.py for bulk operations.
  • Boundary markers: None explicitly implemented; the skill relies on the administrator's review of the generated output.
  • Capability inventory: The generated scripts have the capability to modify tenant-wide security settings, manage user accounts, and assign licenses.
  • Sanitization: user_management.py includes a validate_user_data method that checks for spaces and username length, though it does not implement specific escaping for PowerShell special characters during string interpolation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 01:54 PM
Security Audit — agent-trust-hub — ms365-tenant-manager