Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail5 providerslatest audit May 12, 2026
Independent checks from skills.sh's audit partners.
This skill provides tools for debugging Power Automate flows via a third-party MCP server. A security risk exists due to potential indirect prompt injection: the agent is instructed to read and analyze action outputs from flow runs, which can contain untrusted data from external sources like emails or web forms. This content could potentially include malicious instructions that attempt to influence the agent's actions, particularly when using the skill's capabilities to modify flows.
Detected behaviors
1 alert: gptAnomaly
No issues
1/3 files flagged
Score: 93/100 · 2 sections analyzed