purview-records-management
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is entirely documentation-based and contains no executable code, scripts, or command-line operations.- [SAFE]: All referenced URLs point to learn.microsoft.com, which is the official documentation portal for Microsoft and is a trusted source for configuration guidance.- [METADATA_POISONING]: The skill metadata identifies "Microsoft" as the author, which conflicts with the actual author attribution to "vinayaklatthe". While deceptive, this misattribution does not introduce functional security vulnerabilities.- [INDIRECT_PROMPT_INJECTION]: The instructions describe processes for importing external data, which represents a potential attack surface.- Ingestion points: CSV file plan imports and Microsoft Graph event triggers (File: SKILL.md).- Boundary markers: Absent; there are no instructions for delimiting or isolating external data.- Capability inventory: None detected as the skill contains no scripts or tools.- Sanitization: No validation or escaping steps are provided for the imported content.
Audit Metadata