investigating-m365-entra
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses established administrative commands from the Exchange Online and Microsoft Graph PowerShell modules to perform investigations and containment actions as part of its primary forensic purpose.\n- [DATA_EXFILTRATION]: The skill handles potential sensitive identifiers using common placeholders (e.g., contoso.com) and describes standard logging and export practices (Export-Csv) for the purpose of incident reporting.\n- [PROMPT_INJECTION]: The skill processes telemetry from audit and sign-in logs which may contain untrusted data from external actors. (Ingestion: Search-UnifiedAuditLog, SigninLogs; Boundaries: Absent; Capability Inventory: Update-MgUser, Remove-InboxRule, Set-Mailbox; Sanitization: Absent). The risk is mitigated by the skill's intended use as a forensic tool for human-in-the-loop investigation.
Audit Metadata