copilot-studio-topic-blueprint

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFE
Full Analysis
  • Standard Design Capability: The skill functions as a structured template generator for agent design. It does not request or require access to the file system, environment variables, or external network resources.
  • No-Code Implementation: The skill only produces design specifications (such as Adaptive Card JSON and topic outlines) and does not attempt to automate deployment or modify a user's Microsoft 365 tenant.
  • Structured Output Constraints: The instructions include specific guardrails to prevent the hallucination of product features and require grounding in Microsoft Learn guidance, which promotes safe and accurate technical advice.
  • Input Processing: While the skill processes user-provided use cases (Indirect Prompt Injection surface), it is limited to generating text-based blueprints and lacks the tools or permissions (e.g., shell execution, network tools) necessary to escalate a potential injection into a security threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 11:55 PM
Security Audit — agent-trust-hub — copilot-studio-topic-blueprint