Back to skill

Security audit

Copilot Studio Agent Creator

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only guide for Microsoft Copilot Studio that clearly discusses powerful agent features, but the access and automation it describes are aligned with that purpose and not hidden.

Before installing or using this skill, treat it as a guide to powerful Microsoft automation. Review any Copilot Studio agent for least-privilege connections, sensitive knowledge sources, author-versus-user credential behavior, trigger frequency, billing impact, and monitoring before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explains how to enable autonomous event triggers that run using the agent maker's credentials, but the warning about authorization and data exposure appears later and not at the point where the risky configuration is introduced. This can mislead users into deploying triggers that access or act on data with broader privileges than intended, causing unauthorized data exposure or actions under the maker's identity.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The Power Automate tool section introduces connection modes where flows may run with maker credentials, but it does not present a prominent safety warning when that behavior is first described. Users may unknowingly create tools that let agents retrieve or modify data using elevated author permissions, leading to privilege misuse or unintended data disclosure.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.