power-automate

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents legitimate development patterns for Microsoft Power Automate and Dataverse. It provides technical instructions for cloud flows, desktop flows (RPA), and programmatic flow creation via official Microsoft APIs.
  • [DATA_EXFILTRATION]: Analysis of the HTTP connector patterns and Dataverse actions shows no malicious intent. The skill correctly instructs users to use environment variables for sensitive endpoints and tokens, following security best practices for credential management.
  • [EXTERNAL_DOWNLOADS]: The skill references Microsoft Learn documentation and official Microsoft code samples as authoritative sources for verification. These are well-known, trusted services.
  • [REMOTE_CODE_EXECUTION]: While the skill describes programmatic flow creation and the use of Desktop Flows (RPA), these are documented features of the Power Platform intended for automation. The instructions include appropriate guardrails, such as 'human-in-the-loop' requirements for high-risk operations and 'Automation Center' governance.
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or secrets were found. All authentication patterns use placeholders or dynamic expressions (e.g., Bearer tokens retrieved from previous actions).
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:03 AM
Security Audit — agent-trust-hub — power-automate