copilot-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches libraries and dependencies from official and well-known sources, including the GitHub organization's repositories on GitHub, the npm registry for Node.js packages, and PyPI for Python packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements an architecture that processes untrusted data which could lead to indirect prompt injection.
  • Ingestion points: The skill takes user input via interactive CLI prompts and potentially processes repository data from GitHub APIs through MCP server integrations.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are demonstrated in the provided code examples.
  • Capability inventory: The skill allows for the execution of custom tools (e.g., weather lookups), file attachments analysis, and session management.
  • Sanitization: The implementation examples do not show explicit sanitization or filtering of the input data before it is processed by the model.
  • [DYNAMIC_EXECUTION]: The skill utilizes a tool-calling mechanism where an agent can dynamically invoke handler functions (such as get_weather) based on its own reasoning at runtime.
  • [COMMAND_EXECUTION]: The instructions direct users to execute shell commands for package installation (npm install, pip install, go get) and to run the Copilot CLI in server mode (copilot --server).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 05:05 PM
Security Audit — agent-trust-hub — copilot-sdk