audit_ai_agents
Audit AI agents and MCP servers for security issues: risky sharing, missing auth, HTTP misconfigs, email exfiltration, hard-coded credentials, dormant agents, high-risk sign-ins.
Instructions
Audit the organisation's AI attack surface using Maester's AIAgent checks (MT.1113–MT.1122): risky Copilot Studio agent sharing, missing agent authentication, risky HTTP config, AI-driven email exfiltration, MCP server tools that need review, hard-coded credentials in topics, dormant/orphaned agents, plus high agent-risk sign-ins. Requires the Dataverse service. Use this to let an AI agent police the org's other agents and MCP servers.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| services | No | Defaults to ['Graph','Dataverse']. Dataverse is required for Copilot Studio checks. |