Back to skill

Security audit

Microsoft SharePoint

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed SharePoint integration that uses Maton and Microsoft Graph, with clear warnings around credentials and write operations.

Install this only if you intend to connect a SharePoint account through Maton. Prefer OAuth, choose the narrowest SharePoint scopes available, specify the target connection when more than one exists, and require explicit confirmation before uploads, edits, deletes, sharing links, or other write actions.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.