microsoft-teams
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires installing the
@membranehq/clitool from the npm registry, which is the official utility for the Membrane platform. - [COMMAND_EXECUTION]: The instructions involve the agent running shell commands via the
membraneCLI to authenticate and interact with Microsoft Teams data and actions. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Microsoft Teams messages, creating a surface for indirect prompt injection. 1. Ingestion points: Message data is retrieved via the list-channel-messages and list-chat-messages actions. 2. Boundary markers: None identified; untrusted data is presented to the agent context without specific delimiters or isolation instructions. 3. Capability inventory: The skill allows the agent to send messages, manage channel and team memberships, and perform direct API requests using the membrane request command. 4. Sanitization: There is no evidence of sanitization, filtering, or content validation for the messages ingested from the Teams platform.
Audit Metadata