sharepoint-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSPRIVILEGE_ESCALATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides code templates that ingest parameters like list names and search queries which are then interpolated into SharePoint API requests. This represents a standard vulnerability surface for the domain.
- Ingestion points:
references/EXAMPLES.md(e.g.,listNameproperty andqueryTextargument). - Boundary markers: None present in the code snippets, which is common for technical templates.
- Capability inventory: Interaction with SharePoint data via
fetchcalls and@pnp/splibraries. - Sanitization: Employs
encodeURIComponentfor search query parameters. - [EXTERNAL_DOWNLOADS]: The instructions and examples reference official development tools and libraries from Microsoft and the PnP community.
- Evidence:
SKILL.md(mentions@microsoft/generator-sharepoint),references/EXAMPLES.md(uses@microsoft/sp-core-libraryand@pnp/sp). - [PRIVILEGE_ESCALATION]: The provisioning examples demonstrate how to manage site permissions, which is an expected function for administrative scripts.
- Evidence:
references/EXAMPLES.md(containsBreak-PnPListInheritanceandSet-PnPListPermissioncommands).
Audit Metadata