copilot-studio-workflow

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • Command Execution: The skill utilizes shell tools such as git and the Power Platform CLI (pac) to manage repository state and environment synchronization. These operations are limited to local project management and authenticated environment interactions.
  • Local File Access: PowerShell scripts included in the skill read local YAML configuration files (such as agent.mcs.yml, topics, and variables) to perform pre-push validations and health checks. This is standard behavior for development tooling.
  • Security Best Practices: The skill explicitly advises users to review connectors and tools for their access surface and provides guidance on scrubbing environment-specific data before committing to source control.
  • Trusted External Sources: The skill references official Microsoft resources, including the Power Platform CLI and the Copilot Studio extension. Downloads and installations are directed to well-known, trusted domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 09:18 PM
Security Audit — agent-trust-hub — copilot-studio-workflow