Microsoft Copilot security directory
Starmind
Published by Starmind (inc)
Medium risk
An AI-powered knowledge network for employees to tap into the company expertise.
Security assessment
Plutonium assessed this plugin for permissions, capabilities, and security-relevant behavior.
- Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
- Can send messages as you: This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
- Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.
- Stores long-lived access tokens: This connector requires API access tokens. If those tokens leak or are stolen, whoever holds them gets the same access you have to the connected service.
Available capabilities
This add-on exposes 6 tools or capabilities.
- AppCatalog.Read.All
- AppCatalog.Read.All
- TeamsActivity.Send
- TeamsActivity.Send.User
- User.ReadBasic.All
- offline_access
The interactive security report will load automatically.