copilot-studio-mcp

MCPcommunauté
v0.1.7io.github.jgt87MITMis à jour il y a 19 jnpmGitHub

Build, test, ship and maintain Microsoft Copilot Studio agents from the editor

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Indexé automatiquement depuis des sources publiques. Pas encore vérifié par son développeur sur Forge.Revendiquer cette annonce →
290Téléch./sem.
il y a 19 jDernière mise à jour
Paquet
Auteurio.github.jgt87
LicenceMIT
Version0.1.7
Sourcenpm+mcp-registry
Statut de confiance
B
60/100Bon
✓Listé dans l’index Forge+10/10
—Identité de l’éditeur vérifiée+0/20
→ Éditeur : exécutez `forge publish` depuis le dépôt du paquet pour revendiquer la propriété
—Signature de publication Ed25519+0/5
→ Incluse automatiquement quand l’éditeur exécute `forge publish`
—Vérification de domaine+0/5
→ Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
—npm Trusted Publishing (Sigstore)+0/5
→ Publiez depuis GitHub Actions avec --provenance pour que l’attestation lie ce paquet à ce dépôt
—Correspondance de mainteneur npm+0/5
→ Acquis dès que votre identité est vérifiée ci-dessus et que ce login est mainteneur npm de ce paquet
✓Analyse CVE · propre+30/30
✓Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIndexé par la communauté
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance—
Dépendances✓ 60 résolues+ · aucune vulnérable
Surface d’outils40 outils · 7 privilégiés
Analyse de sécurité✓ Proprev0.1.6 · il y a 22 jQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé11 sept. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

40 outils · 7 privilégiés
Extrait statiquement du paquet publiév0.1.6 · 22d ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

cs_describe_workspaceInventory of an agent workspace: settings, instructions, topics (with trigger phrases), knowledge sources, tools, flows, triggers, variables, connection references, sync metadata.

Inventory of an agent workspace: settings, instructions, topics (with trigger phrases), knowledge sources, tools, flows, triggers, variables, connection references, sync metadata.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_validateStructural validation of every component file against the Copilot Studio authoring schema (kinds, unknown/missing properties, duplicate ids, placeholders, Power Fx prefixes, variable scopes) plus cross-file checks (connection references, topic redirects). Answers 'is anything broken in these files?…

Structural validation of every component file against the Copilot Studio authoring schema (kinds, unknown/missing properties, duplicate ids, placeholders, Power Fx prefixes, variable scopes) plus cross-file checks (connection references, topic redirects). Answers 'is anything broken in these files?…

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_lookup_schemaInspect the Copilot Studio authoring schema: summarize or resolve a definition (e.g. Question, SearchAndSummarizeContent, KnowledgeSourceConfiguration), search by keyword, or list all kinds.

Inspect the Copilot Studio authoring schema: summarize or resolve a definition (e.g. Question, SearchAndSummarizeContent, KnowledgeSourceConfiguration), search by keyword, or list all kinds.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_add_topicCreate topics/<name>.topic.mcs.yml from a declarative spec: trigger phrases (or a system trigger) plus message / question / condition / redirect / setVariable / searchKnowledge / http / invokeFlow / end / raw nodes. Validates the result. Push to apply.

Create topics/<name>.topic.mcs.yml from a declarative spec: trigger phrases (or a system trigger) plus message / question / condition / redirect / setVariable / searchKnowledge / http / invokeFlow / end / raw nodes. Validates the result. Push to apply.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_add_knowledge_sourceAdd knowledge as YAML: kind 'public-site' (Bing-scoped website, max 2 path levels), 'sharepoint' (direct folder URL), 'graph-connector' (Microsoft Graph connector via environment variable), or 'files' (copy documents into knowledge/files for upload on push). Dataverse, AI Search and SQL knowledge a…

Add knowledge as YAML: kind 'public-site' (Bing-scoped website, max 2 path levels), 'sharepoint' (direct folder URL), 'graph-connector' (Microsoft Graph connector via environment variable), or 'files' (copy documents into knowledge/files for upload on push). Dataverse, AI Search and SQL knowledge a…

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_add_toolAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_list_connectorsThe environment's connector registry (the same list the portal's Add a tool shows): Microsoft-published and custom connectors, with an mcpLikely flag for MCP servers. Cached under .cs-catalog/<environment>/connectors.json for offline use; with search and no sign-in, falls back to the offline seed o…

The environment's connector registry (the same list the portal's Add a tool shows): Microsoft-published and custom connectors, with an mcpLikely flag for MCP servers. Cached under .cs-catalog/<environment>/connectors.json for offline use; with search and no sign-in, falls back to the offline seed o…

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_describe_connectorFetch (or read from cache) a connector's OpenAPI definition and list its operations with operationId, parameters (required, type, description) and response fields; marks MCP-capable connectors (x-ms-agentic-protocol). Exactly what cs_add_tool needs. Cached under .cs-catalog/<environment>/connectors…

Fetch (or read from cache) a connector's OpenAPI definition and list its operations with operationId, parameters (required, type, description) and response fields; marks MCP-capable connectors (x-ms-agentic-protocol). Exactly what cs_add_tool needs. Cached under .cs-catalog/<environment>/connectors…

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_list_promptspac copilot model list: AI Builder models (including custom prompts) in the environment, with ids for cs_add_tool type 'prompt'.

pac copilot model list: AI Builder models (including custom prompts) in the environment, with ids for cs_add_tool type 'prompt'.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_add_flowEXPERIMENTAL: write workflows/<Name>/metadata.yaml + workflow.json for a flow with the 'when an agent calls the flow' trigger and a response, optionally exposing it as a tool. Format follows the schema's CloudFlowDefinition and the Power Automate solution JSON; verify with cs_pack and in the portal…

EXPERIMENTAL: write workflows/<Name>/metadata.yaml + workflow.json for a flow with the 'when an agent calls the flow' trigger and a response, optionally exposing it as a tool. Format follows the schema's CloudFlowDefinition and the Power Automate solution JSON; verify with cs_pack and in the portal…

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_add_triggerCreate trigger/<name>.trigger.mcs.yml pointing at a cloud flow that starts the agent (WorkflowExternalTrigger).

Create trigger/<name>.trigger.mcs.yml pointing at a cloud flow that starts the agent (WorkflowExternalTrigger).

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_add_variableCreate variables/<name>.variable.mcs.yml (GlobalVariableComponent, conversation scope).

Create variables/<name>.variable.mcs.yml (GlobalVariableComponent, conversation scope).

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_update_agentAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_update_settingsSet values in settings.mcs.yml by dot path, e.g. {"configuration.settings.GenerativeActionsEnabled": true}. Do not change authoringModel/recognizer/template.

Set values in settings.mcs.yml by dot path, e.g. {"configuration.settings.GenerativeActionsEnabled": true}. Do not change authoringModel/recognizer/template.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_chatSend one utterance to the published agent and return its replies (and raw activities). Use conversationId to continue. If the agent answers with a sign-in card, signInUrl is returned.

Send one utterance to the published agent and return its replies (and raw activities). Use conversationId to continue. If the agent answers with a sign-in card, signInUrl is returned.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_run_conversation_testsAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_snapshot_environmentCapture one environment into a folder for comparison or history: solution version, every agent cloned with pac copilot clone (agents/<name>), and, when signed in, flows, connection references, environment variables and publish state. Read-only for the environment.

Capture one environment into a folder for comparison or history: solution version, every agent cloned with pac copilot clone (agents/<name>), and, when signed in, flows, connection references, environment variables and publish state. Read-only for the environment.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_compare_snapshotsOffline diff of two snapshot folders: solution version, per-agent YAML differences (noise such as ids, audit info and connection ids removed), flows, connection references, environment variables, unpublished changes. Writes <reportDir>/<a>-vs-<b>.md and .json. failOnDrift returns an error result wh…

Offline diff of two snapshot folders: solution version, per-agent YAML differences (noise such as ids, audit info and connection ids removed), flows, connection references, environment variables, unpublished changes. Writes <reportDir>/<a>-vs-<b>.md and .json. failOnDrift returns an error result wh…

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_compare_environmentsSnapshot every environment in an ordered chain (e.g. DEV, TEST, ACC, PROD) and compare each adjacent pair. Returns one report per pair plus the first stage where drift appears. Snapshots go to <dir>/<label>, reports to <dir>/reports.

Snapshot every environment in an ordered chain (e.g. DEV, TEST, ACC, PROD) and compare each adjacent pair. Returns one report per pair plus the first stage where drift appears. Snapshots go to <dir>/<label>, reports to <dir>/reports.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_edit_topicprivilégiéChange an existing topic in place, keeping its comment header: rename, description, trigger phrases (set / add / remove), priority, append or insert nodes (same node spec as cs_add_topic), remove top-level nodes by id. Validates the file afterwards.

Change an existing topic in place, keeping its comment header: rename, description, trigger phrases (set / add / remove), priority, append or insert nodes (same node spec as cs_add_topic), remove top-level nodes by id. Validates the file afterwards.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_edit_toolprivilégiéChange an existing tool file: name, description, modelDescription / modelDisplayName (what the orchestrator routes on), operationId, connection mode or reference, output mode, and inputs (set / add / remove). Validates afterwards.

Change an existing tool file: name, description, modelDescription / modelDisplayName (what the orchestrator routes on), operationId, connection mode or reference, output mode, and inputs (set / add / remove). Validates afterwards.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_edit_knowledgeprivilégiéChange a knowledge source file: name, description, site URL, includeSubPages, trigger condition (null removes it), additional search terms.

Change a knowledge source file: name, description, site URL, includeSubPages, trigger condition (null removes it), additional search terms.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_remove_componentprivilégiéDelete a topic, knowledge source, tool, trigger, variable or flow from the workspace files (the live agent changes on the next cs_push). For tools, the connection reference is dropped too unless another tool uses it. Reports topics that still redirect to a removed topic. Deletes files: requires con…

Delete a topic, knowledge source, tool, trigger, variable or flow from the workspace files (the live agent changes on the next cs_push). For tools, the connection reference is dropped too unless another tool uses it. Reports topics that still redirect to a removed topic. Deletes files: requires con…

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_delete_agentprivilégiépac copilot delete: permanently delete an agent from the environment. Requires confirm: true.

pac copilot delete: permanently delete an agent from the environment. Requires confirm: true.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_delete_solutionprivilégiépac solution delete: delete an unmanaged solution container (its components stay in the environment) or uninstall a managed one (its components are removed). Requires confirm: true.

pac solution delete: delete an unmanaged solution container (its components stay in the environment) or uninstall a managed one (its components are removed). Requires confirm: true.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_review_agentJudge whether the agent is any good and say what to improve, as a score out of 10 with a fix for each finding: instructions present and sized, escalation and fallback topics, trigger phrase count and overlap, tool descriptions and name collisions, unbound connections, authentication versus private…

Judge whether the agent is any good and say what to improve, as a score out of 10 with a fix for each finding: instructions present and sized, escalation and fallback topics, trigger phrase count and overlap, tool descriptions and name collisions, unbound connections, authentication versus private…

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_list_environmentsList Power Platform environments the signed-in user can access (BAP API), with Dataverse URLs.

List Power Platform environments the signed-in user can access (BAP API), with Dataverse URLs.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_list_agentsList Copilot Studio agents in an environment. via 'pac' uses 'pac copilot list' (needs a pac auth profile); via 'dataverse' queries the bots table with the MSAL token. Default auto: pac when available, else dataverse.

List Copilot Studio agents in an environment. via 'pac' uses 'pac copilot list' (needs a pac auth profile); via 'dataverse' queries the bots table with the MSAL token. Default auto: pac when available, else dataverse.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_create_test_set_csvWrite the CSV the portal's Evaluation page imports (columns Question, Expected response; max 100 cases). Test sets cannot be created through the API, so this file is imported once in the portal; runs and results are then automated via cs_run_evaluation. suggestFromWorkspace derives cases from topic…

Write the CSV the portal's Evaluation page imports (columns Question, Expected response; max 100 cases). Test sets cannot be created through the API, so this file is imported once in the portal; runs and results are then automated via cs_run_evaluation. suggestFromWorkspace derives cases from topic…

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_list_test_setsPower Platform API: test sets defined for the agent (standard harness).

Power Platform API: test sets defined for the agent (standard harness).

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_run_evaluationStart an evaluation run for a test set (draft agent by default, or the published one). Optionally wait for completion and return the summary. Counts against the 20 runs per agent per 24h limit: requires confirm: true.

Start an evaluation run for a test set (draft agent by default, or the published one). Optionally wait for completion and return the summary. Counts against the 20 runs per agent per 24h limit: requires confirm: true.

Aucun schéma d’entrée n’a été publié pour cet outil.

cs_get_evaluation_runAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_list_evaluation_runsAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_build_flow_definitionAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_list_flowsAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_get_flowAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_set_flow_stateAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_update_flowAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_create_flowAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

cs_delete_flowprivilégiéAucune description publiée

Cet outil n’a publié aucune description. Forge n’en invente pas.

28 outils sur 40 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

Build, test, ship and maintain Microsoft Copilot Studio agents from the editor

Mots-clés
mcp
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-09-11 — résolution observée, et non une déclaration de l'éditeur.

60 paquets résolus · 8 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.

36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)

Déclarées mais non résolues

59 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.

+47 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.