Opening SecureFlowCowork Exfil: Poisoned-Skill File Exfiltration via Microsoft 365 Copilot Cowork
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

PromptArmor aidefend-sf0003

Cowork Exfil: Poisoned-Skill File Exfiltration via Microsoft 365 Copilot Cowork

  • Copilot & SaaS
  • Autonomous Agents
  • AI Supply Chain
  • Tool Integrations & MCP
  • Data Exfiltration
  • Resource Hijacking & Cost

A validated research flow showing how five lines of indirect prompt injection in a Copilot Cowork skill make the autonomous agent read Microsoft 365 files, mint pre-authenticated download links, and auto-send a Teams message whose external image URLs exfiltrate them when opened, with no human approval.

Mapped threat techniques

Source