power-automate

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill provides clear guidance on managing authentication and API interactions.
  • [COMMAND_EXECUTION]: The skill provides curl command examples for interacting with Microsoft's Dataverse Web API. These commands are standard for the described operations and use trusted endpoints (microsoftonline.com and Dynamics environments).
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of FlowStudio MCP (mcp.flowstudio.app/mcp) for advanced debugging. This is an external third-party service, and the skill explicitly flags it as non-Microsoft affiliated, requiring manual user setup and awareness.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles flow definitions (clientdata) as JSON strings sent to an external API. This represents a potential surface for indirect injection if the definitions are sourced from untrusted inputs.
  • Ingestion points: Flow definitions are processed and assigned to the clientdata property in SKILL.md and references/dataverse-web-api.md.
  • Boundary markers: None; there are no specific instructions to the agent to treat the flow definition content as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill uses curl to perform POST, PATCH, and DELETE operations on Dataverse resources.
  • Sanitization: The skill correctly recommends using JSON.stringify to escape payloads into strings before transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — power-automate