Microsoft Copilot security directory

AI for Work

Published by KoreaiAzureAgentMarketplace

High risk

Search within enterprise data and streamline work with intelligent AI agents

Security assessment

Plutonium assessed this plugin for permissions, capabilities, and security-relevant behavior.

  • Reads your private information: This connector can read data the connected service holds about you - documents, messages, contact lists, source code, customer records, or saved profile details - and pass it back to the AI.
  • Can change or update your information: This connector can edit, rename, overwrite, or otherwise modify records in the connected service. If a request gets manipulated, your data could be altered without you noticing.
  • Can permanently delete data: This connector can erase records, files, or accounts. Once deleted the data may be unrecoverable - even an accidental request can cause permanent loss.
  • Can send messages as you: This connector can post messages, emails, or chat replies on your behalf. Recipients will believe the message came from you, which makes phishing or social-engineering risks higher.
  • Stores long-lived access tokens: This connector requires API access tokens. If those tokens leak or are stolen, whoever holds them gets the same access you have to the connected service.

Available capabilities

This add-on exposes 19 tools or capabilities.

  • Channel.ReadBasic.All
  • ChannelMessage.Send
  • Chat.ReadWrite
  • ChatMessage.Send
  • Files.ReadWrite.All
  • Mail.Read
  • Mail.ReadWrite
  • Mail.Send
  • People.Read
  • Sites.ReadWrite.All
  • Sites.ReadWrite.All
  • Team.ReadBasic.All
  • User.Read
  • User.Read.All
  • User.Read.All
  • email
  • offline_access
  • openid
  • profile

The interactive security report will load automatically.