investigating-m365-entra

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses established administrative commands from the Exchange Online and Microsoft Graph PowerShell modules to perform investigations and containment actions as part of its primary forensic purpose.\n- [DATA_EXFILTRATION]: The skill handles potential sensitive identifiers using common placeholders (e.g., contoso.com) and describes standard logging and export practices (Export-Csv) for the purpose of incident reporting.\n- [PROMPT_INJECTION]: The skill processes telemetry from audit and sign-in logs which may contain untrusted data from external actors. (Ingestion: Search-UnifiedAuditLog, SigninLogs; Boundaries: Absent; Capability Inventory: Update-MgUser, Remove-InboxRule, Set-Mailbox; Sanitization: Absent). The risk is mitigated by the skill's intended use as a forensic tool for human-in-the-loop investigation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:46 PM
Security Audit — agent-trust-hub — investigating-m365-entra