security-copilot-agents

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional text and documentation for managing AI agents within the Microsoft Security Copilot ecosystem. It does not contain any executable code, scripts, or suspicious commands.
  • [EXTERNAL_DOWNLOADS]: The file contains multiple links to the official Microsoft Learn documentation domain (learn.microsoft.com). These references are used for legitimate technical guidance and target a well-known service.
  • [PROMPT_INJECTION]: The skill demonstrates high security awareness by explicitly warning users about the risk of indirect prompt injection. It highlights that agents processing external data, such as user-submitted emails, should treat those inputs as untrusted and rely on built-in platform mitigations.
  • [COMMAND_EXECUTION]: Instructions promote secure identity management by advising against the use of Global Admin privileges for agent identities and recommending the rotation of secrets and regular auditing of API permissions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 06:54 PM
Security Audit — agent-trust-hub — security-copilot-agents