power-automate-build

Pass

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed to interact with the FlowStudio MCP service at https://mcp.flowstudio.app/mcp using standard JSON-RPC tool calls. This communication is essential for its documented purpose of managing Power Automate flows and targets the vendor's infrastructure.
  • [SAFE]: Mandatory human-in-the-loop checkpoints are included, specifically requiring agent confirmation before triggering any flow tests that could result in real-world side effects like sending emails or modifying data.
  • [SAFE]: The provided Python helper code and flow templates follow security best practices, such as instructing users to use environment variables for tokens and secure parameters for Azure AD secrets rather than hardcoding credentials.
  • [SAFE]: The skill uses standard Python libraries (json, urllib.request) for network communication and does not attempt to download or execute untrusted third-party scripts or packages.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 26, 2026, 10:29 AM
Security Audit — agent-trust-hub — power-automate-build