onenote-debug-bundle
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a 'redact-first' approach, providing explicit instructions to exclude access tokens, bearer tokens, secrets, and raw notebook content from diagnostic bundles.
- [SAFE]: All external references point to official Microsoft Graph documentation at
learn.microsoft.com, which is an established and trusted source for API information. - [SAFE]: The skill incorporates security validation steps, such as using 'canaries' (known secrets or content) to verify that the redaction process is effective before any artifact is shared.
- [SAFE]: The instructions clearly define approval boundaries, requiring authorization from both incident and data owners before collection or external sharing occurs.
- [SAFE]: Tool discipline guidelines restrict the AI agent's actions to local file inspection and writing, explicitly stating that invocation does not grant network access or permission to use delegated credentials.
Audit Metadata