copilot-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches libraries and dependencies from official and well-known sources, including the GitHub organization's repositories on GitHub, the npm registry for Node.js packages, and PyPI for Python packages.
- [INDIRECT_PROMPT_INJECTION]: The skill implements an architecture that processes untrusted data which could lead to indirect prompt injection.
- Ingestion points: The skill takes user input via interactive CLI prompts and potentially processes repository data from GitHub APIs through MCP server integrations.
- Boundary markers: No specific delimiters or instructions to ignore embedded commands are demonstrated in the provided code examples.
- Capability inventory: The skill allows for the execution of custom tools (e.g., weather lookups), file attachments analysis, and session management.
- Sanitization: The implementation examples do not show explicit sanitization or filtering of the input data before it is processed by the model.
- [DYNAMIC_EXECUTION]: The skill utilizes a tool-calling mechanism where an agent can dynamically invoke handler functions (such as
get_weather) based on its own reasoning at runtime. - [COMMAND_EXECUTION]: The instructions direct users to execute shell commands for package installation (
npm install,pip install,go get) and to run the Copilot CLI in server mode (copilot --server).
Audit Metadata