purview-records-management

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is entirely documentation-based and contains no executable code, scripts, or command-line operations.- [SAFE]: All referenced URLs point to learn.microsoft.com, which is the official documentation portal for Microsoft and is a trusted source for configuration guidance.- [METADATA_POISONING]: The skill metadata identifies "Microsoft" as the author, which conflicts with the actual author attribution to "vinayaklatthe". While deceptive, this misattribution does not introduce functional security vulnerabilities.- [INDIRECT_PROMPT_INJECTION]: The instructions describe processes for importing external data, which represents a potential attack surface.- Ingestion points: CSV file plan imports and Microsoft Graph event triggers (File: SKILL.md).- Boundary markers: Absent; there are no instructions for delimiting or isolating external data.- Capability inventory: None detected as the skill contains no scripts or tools.- Sanitization: No validation or escaping steps are provided for the imported content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 05:04 AM
Security Audit — agent-trust-hub — purview-records-management