ms365-tenant-manager
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from CSV files for bulk user provisioning and license management workflows.
- Ingestion points: User-supplied CSV files are read by the UserLifecycleManager class in scripts/user_management.py and used in templates within references/powershell-templates.md.
- Boundary markers: The instructions do not define strict boundary markers or 'ignore' instructions for the data contained within the CSV fields.
- Capability inventory: The resulting scripts execute high-privilege operations such as creating users (New-MgUser), modifying account states (Update-MgUser), and assigning licenses via Microsoft Graph.
- Sanitization: Basic validation is performed on usernames (e.g., checking for spaces), but there is no comprehensive sanitization or escaping of PowerShell metacharacters for inputs like display names or job titles, creating a surface for command injection if the input source is malicious.
Audit Metadata