ms365-tenant-manager

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from CSV files for bulk user provisioning and license management workflows.
  • Ingestion points: User-supplied CSV files are read by the UserLifecycleManager class in scripts/user_management.py and used in templates within references/powershell-templates.md.
  • Boundary markers: The instructions do not define strict boundary markers or 'ignore' instructions for the data contained within the CSV fields.
  • Capability inventory: The resulting scripts execute high-privilege operations such as creating users (New-MgUser), modifying account states (Update-MgUser), and assigning licenses via Microsoft Graph.
  • Sanitization: Basic validation is performed on usernames (e.g., checking for spaces), but there is no comprehensive sanitization or escaping of PowerShell metacharacters for inputs like display names or job titles, creating a surface for command injection if the input source is malicious.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:44 PM
Security Audit — agent-trust-hub — ms365-tenant-manager