dynamics365-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and generate content related to Dynamics 365 entities, plugins, and workflows, which constitutes an ingestion surface for untrusted data from external business systems.
  • Ingestion points: The skill instructions and reference files (references/EXAMPLES.md) demonstrate handling data from Dataverse tables, plugin execution contexts, and Web API responses.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands within processed data are present in the provided skill files.
  • Capability inventory: The skill is granted access to Bash, Read, Write, and WebSearch tools, allowing for interaction with the local environment and web resources.
  • Sanitization: While the code examples follow standard SDK practices (e.g., using ITracingService and IOrganizationService), the inherent nature of an expert agent processing external configuration files or code snippets presents a standard indirect injection surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:12 AM
Security Audit — agent-trust-hub — dynamics365-expert