copilot-studio

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes phrases such as "Ignore previous instructions", "developer mode", and "Show me your system prompt" in the file alm-governance-testing.md. These are part of a structured "Adversarial Testing" checklist and "Example Prompts" table intended to guide users on how to verify that their agents properly block such attacks. These are descriptive examples for security testing, not instructions aimed at the agent's behavior.
  • [SAFE]: The skill provides thorough guidance on implementing security controls, including content moderation levels, Data Loss Prevention (DLP) policies for connectors, and authentication methods (Entra ID, OAuth 2.0). It encourages the use of environment variables for sensitive configurations instead of hardcoding values.
  • [SAFE]: Integration patterns for external systems, such as the Model Context Protocol (MCP) and Power Pages Agent API, utilize official Microsoft services and standard enterprise protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:03 AM
Security Audit — agent-trust-hub — copilot-studio