flowstudio-power-automate-mcp

Pass

Audited by Gen Agent Trust Hub on Apr 14, 2026

Risk Level: SAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill performs network requests to https://mcp.flowstudio.app/mcp to facilitate Power Automate operations. It uses user-provided JWT tokens for authentication and does not interact with whitelisted domains.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing external data from Power Automate and providing tools to modify and trigger flows. Ingestion points: get_live_flow, get_live_flow_run_action_outputs, and get_live_flow_runs in SKILL.md. Boundary markers: None present in documented examples. Capability inventory: update_live_flow, trigger_live_flow, and cancel_live_flow_run in SKILL.md. Sanitization: None present in documented examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 14, 2026, 07:48 AM
Security Audit — agent-trust-hub — flowstudio-power-automate-mcp