Microsoft Copilot security directory

CobbleStone - Contract Insight

Published by Cobblestone Software

High risk

Enhance your contract management process by connecting to our Contract Insight API for seamless interaction between systems. Functionality once connected includes: - Creating new records. - Updating existing records. - Pulling a list of records for a given entity. - Pulling all metadata, restrictions and flags. - Pulling a list of editable, updateable, or viewable records.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can execute code or queries: This connector can run arbitrary queries or code against a database or execution engine. An AI-generated query could be manipulated to exfiltrate, corrupt, or destroy data.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 11 tools or capabilities.

  • Create a new a record for a specified entity
  • Execute a specific database view
  • Pull list of entities that API is allowed to work with
  • Pull list of record(s) for a given entity
  • Pull metadata about all columns in specific database view
  • Pull metadata about all columns in specific entity
  • Retrieve List of available Database Views
  • Retrieve List of available Entities for Insert Purpose
  • Retrieve List of available Entities for Select Purpose
  • Retrieve List of available Entities for Update Purpose
  • Update record(s) for a specified entity

The interactive security report will load automatically.