Microsoft Copilot Studio: Discover & Add Skills from the skill catalog

🚨 The Signal: Copilot Studio now allows sharing and reusing 'skills' across agents via a catalog. This centralises AI agent capabilities, improving consistency but increasing the blast radius of a compromised skill.

The Impact

Security teams and AI governance teams are affected by the increased risk of unapproved or malicious AI skills spreading across the organisation.

  • Security Teams: Increased attack surface from shared AI agent skills.
  • AI Governance Teams: New challenge in vetting and approving shared AI capabilities.
  • Admins: Need to manage and monitor the skill catalog for compliance.
  • End Users: Potential exposure to less secure or unapproved AI agent behaviours.

The Action

  1. Review and define a clear policy for skill creation, approval, and sharing within Copilot Studio.
  2. Implement a robust vetting process for all skills added to the organisational skill catalog.
  3. Monitor Copilot Studio audit logs for skill creation, modification, and sharing activities.
  4. Educate makers on secure skill development practices and the risks associated with sharing unapproved skills.
  5. Regularly audit shared skills in the catalog to ensure ongoing compliance and security posture.

Domain: Agentic-AI · Impact: high · Workload: Other