Microsoft Copilot security directory

Decisions

Published by Decisions

High risk

✨ AI-powered meetings: Agendas, summaries, decisions + tasks, all in one place

Security assessment

Plutonium assessed this plugin for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can send messages as you: This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Stores long-lived access tokens: This connector requires API access tokens. If those tokens leak or are stolen, whoever holds them gets the same access you have to the connected service.

Available capabilities

This add-on exposes 31 tools or capabilities.

  • Calendars.ReadWrite
  • Calendars.ReadWrite.Shared
  • Channel.ReadBasic.All
  • ChannelMember.Read.All
  • ChannelMessage.Read.All
  • ChannelMessage.Send
  • Chat.ReadWrite
  • Directory.Read.All
  • Files.Read.All
  • Files.ReadWrite
  • Group.ReadWrite.All
  • Mail.Send
  • MailboxSettings.Read
  • Notes.ReadWrite.All
  • OnlineMeetingTranscript.Read.Chat
  • OnlineMeetings.ReadWrite
  • People.Read
  • Sites.Manage.All
  • Sites.Manage.All
  • Sites.ReadWrite.All
  • Tasks.ReadWrite
  • Team.ReadBasic.All
  • TeamsActivity.Send
  • TeamsAppInstallation.ReadWriteForUser.All

The interactive security report will load automatically.