Skip to main content

ai-agent-activity

Use this skill when asked to report on, summarize, or investigate the RUNTIME ACTIVITY of AI agents (Agent 365 / Copilot Studio / Microsoft 365 Copilot / Work IQ) — who used which agents, what tools/connectors ran, which channels, token usage, prompt/reply content, and what the safety layer (Prompt Shield jailbreak / XPIA) caught. Triggers on keywords like "agent activity", "AI agent usage", "who is using agents", "agent runtime", "agent telemetry", "agent tool usage", "agent session", "jailbreak activity", "prompt injection activity", "Agent 365 activity", "UnifiedAgentObservability", "CloudAppEvents agents", "CopilotActivity". Auto-detects whichever data planes the tenant has — UnifiedAgentObservability (Sentinel Data Lake), CloudAppEvents (Defender), CopilotActivity (governance + fail-close posture) — and proceeds with what is available. Supports tenant-wide, single-agent, and single-user scopes. Runtime/behavioral companion to the config-focused ai-agent-posture skill.

Aller à l'installation

Informations de source

Dépôt
SCStelz/security-investigator
Dernière activité de la source
13 août 2026 à 02:09
Langue détectée de SKILL.md
anglais
Étoiles
233
Forks
64

Options d'installation

Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.

Vérifiez les fichiers source

Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.