Third-party audit

Gen Agent Trust Hub

flowstudio-power-automate-debug · github/awesome-copilot

Passed
Provider summary

This skill provides tools for debugging Power Automate flows via a third-party MCP server. A security risk exists due to potential indirect prompt injection: the agent is instructed to read and analyze action outputs from flow runs, which can contain untrusted data from external sources like emails or web forms. This content could potentially include malicious instructions that attempt to influence the agent's actions, particularly when using the skill's capabilities to modify flows.

The provider classified the analyzed snapshot as NONE risk. This result applies to the content available at audit time.

Provider
Gen Agent Trust Hub
Normalized result
pass
Risk level
NONE
Audited
May 12, 2026
Interpretation

How to use this signal

01

Confirm the source

Compare the repository, publisher, and installation command before continuing.

02

Read the content

Review SKILL.md, scripts, and allowed tools. Artificial Atlas never executes them during indexing.

03

Limit permissions

Use the narrowest possible scope and avoid broad credentials for third-party skills.