Microsoft Copilot security directory

Microsoft Copilot Studio

Published by Microsoft

High risk

Microsoft Copilot Studio used to discover and trigger agents

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can execute code or queries: This connector can run arbitrary queries or code against a database or execution engine. An AI-generated query could be manipulated to exfiltrate, corrupt, or destroy data.
  • Stores long-lived access tokens: This connector requires persistent credentials. If those tokens leak or are stolen, whoever holds them gets the same access you granted.

Available capabilities

This add-on exposes 7 tools or capabilities.

  • Evaluate Agent
  • Execute Agent
  • Execute Agent and wait
  • Get Agent Test Run Details
  • Get Agent Test Runs
  • Get Agent Test Set Details
  • Get Agent Test Sets

The interactive security report will load automatically.