m365-integration
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface detected due to ingestion of untrusted data from Microsoft 365 services.
- Ingestion points: The skill facilitates reading external, potentially attacker-controlled content via email triggers in
outlook-integration.md(e.g., 'When a new email arrives') and SharePoint file reads insharepoint-integration.md(e.g., 'Get file content'). - Boundary markers: No instructions are provided for using delimiters or 'ignore embedded instructions' warnings when processing this external content.
- Capability inventory: The skill grants the agent capabilities to perform actions based on this data, including sending emails via
outlook-integration.md, posting to Teams viateams-integration.md, and executing Graph API queries viagraph-api.md. - Sanitization: There is a lack of guidance on validating or sanitizing the content of ingested emails or documents before it is processed by the agent or interpolated into further prompts.
Audit Metadata