Microsoft Copilot security directory

Starmind

Published by Starmind (inc)

Medium risk

An AI-powered knowledge network for employees to tap into the company expertise.

Security assessment

Plutonium assessed this plugin for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can send messages as you: This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Sends your data to outside companies: Anything you share with this connector flows through one or more third-party services. Those companies see, store, and may use the data according to their own policies.
  • Stores long-lived access tokens: This connector requires API access tokens. If those tokens leak or are stolen, whoever holds them gets the same access you have to the connected service.

Available capabilities

This add-on exposes 6 tools or capabilities.

  • AppCatalog.Read.All
  • AppCatalog.Read.All
  • TeamsActivity.Send
  • TeamsActivity.Send.User
  • User.ReadBasic.All
  • offline_access

The interactive security report will load automatically.