microsoft-teams

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires installing the @membranehq/cli tool from the npm registry, which is the official utility for the Membrane platform.
  • [COMMAND_EXECUTION]: The instructions involve the agent running shell commands via the membrane CLI to authenticate and interact with Microsoft Teams data and actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from Microsoft Teams messages, creating a surface for indirect prompt injection. 1. Ingestion points: Message data is retrieved via the list-channel-messages and list-chat-messages actions. 2. Boundary markers: None identified; untrusted data is presented to the agent context without specific delimiters or isolation instructions. 3. Capability inventory: The skill allows the agent to send messages, manage channel and team memberships, and perform direct API requests using the membrane request command. 4. Sanitization: There is no evidence of sanitization, filtering, or content validation for the messages ingested from the Teams platform.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:22 PM
Security Audit — agent-trust-hub — microsoft-teams