Microsoft Copilot security directory

Harvest

Published by Microsoft

High risk

Harvest is a simple tool to help track the time spent by your team on each project and task.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 13 tools or capabilities.

  • Add new client
  • Add new contact
  • Add new user
  • Add user to a project
  • Create time entry
  • Delete time entry
  • Get time entry by id
  • Get user info
  • List all clients
  • List all contacts
  • List projects
  • List tasks
  • Update time entry

The interactive security report will load automatically.