Microsoft Copilot security directory

SparkPost

Published by Microsoft

High risk

SparkPost API allows you to manage email recipient lists and send emails.

Security assessment

Plutonium assessed this connector for permissions, capabilities, and security-relevant behavior.

  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can send messages as you: This connector can post messages, emails, or notifications on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Sends your data to outside companies: Anything you share with this connector flows to a third-party service. That company sees, stores, and may use the data according to their own policies.

Available capabilities

This add-on exposes 5 tools or capabilities.

  • Add user to recipient list
  • Create recipient list
  • Delete user from recipient list
  • Send email to a recipient
  • Send email to a recipient list

The interactive security report will load automatically.