# copilot-studio-mcp

Build, test, ship and maintain Microsoft Copilot Studio agents from the editor

- **Type:** MCP server
- **Trust:** 60/100 (B), scored on the package rubric
- **Verification:** community-indexed — nobody has claimed this listing
- **Version:** 0.1.7
- **Author:** io.github.jgt87
- **License:** MIT
- **npm:** copilot-studio-mcp
- **Source:** https://github.com/jgt87/copilot-studio-mcp
- **Compatible clients:** claude-code, cursor, copilot, gemini (basis: transport)

## Trust

60/100 (B), scored on the package rubric
- Publisher verified: no
- Install scripts: nothing suspicious found
- Prompt-injection scan: not run
- Obfuscation scan: not run
- Evidence age: 24 days

## Security scan

- **Status:** clean
- **Scanned:** 2026-09-11T14:24:05.166Z
- **Version scanned:** 0.1.6
- **CVEs:** none found by OSV at scan time

## Tools

40 declared. Statically extracted from the shipped source — a floor on the surface, not a census.
- `cs_describe_workspace` — Inventory of an agent workspace: settings, instructions, topics (with trigger phrases), knowledge sources, tools, flows, triggers, variables, connection referen
- `cs_validate` — Structural validation of every component file against the Copilot Studio authoring schema (kinds, unknown/missing properties, duplicate ids, placeholders, Power
- `cs_lookup_schema` — Inspect the Copilot Studio authoring schema: summarize or resolve a definition (e.g. Question, SearchAndSummarizeContent, KnowledgeSourceConfiguration), search 
- `cs_add_topic` — Create topics/<name>.topic.mcs.yml from a declarative spec: trigger phrases (or a system trigger) plus message / question / condition / redirect / setVariable /
- `cs_add_knowledge_source` — Add knowledge as YAML: kind 'public-site' (Bing-scoped website, max 2 path levels), 'sharepoint' (direct folder URL), 'graph-connector' (Microsoft Graph connect
- `cs_add_tool`
- `cs_list_connectors` — The environment's connector registry (the same list the portal's Add a tool shows): Microsoft-published and custom connectors, with an mcpLikely flag for MCP se
- `cs_describe_connector` — Fetch (or read from cache) a connector's OpenAPI definition and list its operations with operationId, parameters (required, type, description) and response fiel
- `cs_list_prompts` — pac copilot model list: AI Builder models (including custom prompts) in the environment, with ids for cs_add_tool type 'prompt'.
- `cs_add_flow` — EXPERIMENTAL: write workflows/<Name>/metadata.yaml + workflow.json for a flow with the 'when an agent calls the flow' trigger and a response, optionally exposin
- `cs_add_trigger` — Create trigger/<name>.trigger.mcs.yml pointing at a cloud flow that starts the agent (WorkflowExternalTrigger).
- `cs_add_variable` — Create variables/<name>.variable.mcs.yml (GlobalVariableComponent, conversation scope).
- `cs_update_agent`
- `cs_update_settings` — Set values in settings.mcs.yml by dot path, e.g. {"configuration.settings.GenerativeActionsEnabled": true}. Do not change authoringModel/recognizer/template.
- `cs_chat` — Send one utterance to the published agent and return its replies (and raw activities). Use conversationId to continue. If the agent answers with a sign-in card,
- `cs_run_conversation_tests`
- `cs_snapshot_environment` — Capture one environment into a folder for comparison or history: solution version, every agent cloned with pac copilot clone (agents/<name>), and, when signed i
- `cs_compare_snapshots` — Offline diff of two snapshot folders: solution version, per-agent YAML differences (noise such as ids, audit info and connection ids removed), flows, connection
- `cs_compare_environments` — Snapshot every environment in an ordered chain (e.g. DEV, TEST, ACC, PROD) and compare each adjacent pair. Returns one report per pair plus the first stage wher
- `cs_edit_topic` — Change an existing topic in place, keeping its comment header: rename, description, trigger phrases (set / add / remove), priority, append or insert nodes (same
- `cs_edit_tool` — Change an existing tool file: name, description, modelDescription / modelDisplayName (what the orchestrator routes on), operationId, connection mode or referenc
- `cs_edit_knowledge` — Change a knowledge source file: name, description, site URL, includeSubPages, trigger condition (null removes it), additional search terms.
- `cs_remove_component` — Delete a topic, knowledge source, tool, trigger, variable or flow from the workspace files (the live agent changes on the next cs_push). For tools, the connecti
- `cs_delete_agent` — pac copilot delete: permanently delete an agent from the environment. Requires confirm: true.
- `cs_delete_solution` — pac solution delete: delete an unmanaged solution container (its components stay in the environment) or uninstall a managed one (its components are removed). Re
- `cs_review_agent` — Judge whether the agent is any good and say what to improve, as a score out of 10 with a fix for each finding: instructions present and sized, escalation and fa
- `cs_list_environments` — List Power Platform environments the signed-in user can access (BAP API), with Dataverse URLs.
- `cs_list_agents` — List Copilot Studio agents in an environment. via 'pac' uses 'pac copilot list' (needs a pac auth profile); via 'dataverse' queries the bots table with the MSAL
- `cs_create_test_set_csv` — Write the CSV the portal's Evaluation page imports (columns Question, Expected response; max 100 cases). Test sets cannot be created through the API, so this fi
- `cs_list_test_sets` — Power Platform API: test sets defined for the agent (standard harness).
- `cs_run_evaluation` — Start an evaluation run for a test set (draft agent by default, or the published one). Optionally wait for completion and return the summary. Counts against the
- `cs_get_evaluation_run`
- `cs_list_evaluation_runs`
- `cs_build_flow_definition`
- `cs_list_flows`
- `cs_get_flow`
- `cs_set_flow_state`
- `cs_update_flow`
- `cs_create_flow`
- `cs_delete_flow`

## Install

**Verdict: review** — Installable, but 1 thing to check first: No publisher has proved control of this listing; it is indexed, not vouched for.
**Cautions** (coverage gaps and advisories — never blocking)
- No publisher has proved control of this listing; it is indexed, not vouched for.
**Config** (claude-code):
```json
"{\n  \"mcpServers\": {\n    \"copilot-studio\": {\n      \"command\": \"npx\",\n      \"args\": [\n        \"-y\",\n        \"copilot-studio-mcp\"\n      ]\n    }\n  }\n}"
```

## Blast radius

Extensive to critical — no credential declaration found, from the publisher, the upstream registry, or the README. Known so far: deletes data; runs on your machine.
- Floor 42, ceiling 66 (tier: unknown)
- `unknown` means the floor and ceiling land in different bands — not measured enough to name one. It does not mean low.
- This is impact, not likelihood. A high radius is not a defect: a filesystem server is supposed to write files. It is never part of the trust score.

## Machine-readable views of this entry

- Signed JSON: https://forgeregistry.com/api/v1/packages/copilot-studio-mcp
- Install plan: https://forgeregistry.com/api/v1/packages/copilot-studio-mcp/install-plan
- Alternatives: https://forgeregistry.com/api/v1/alternatives/copilot-studio-mcp
- HTML page: https://forgeregistry.com/registry/copilot-studio-mcp
- MCP: POST https://forgeregistry.com/api/mcp → `forge_get_package` / `forge_install_plan`

## About this document

Generated by Forge (https://forgeregistry.com) — a compact rendering of the same record served, signed, at the JSON URL above. Trust and scan facts are the registry's own measurements; anything Forge did not measure is named as unmeasured rather than omitted.
