We all knew M365 AI agents would eventually get tricked into handing over data. I just didn’t expect the exfiltration path to be this quiet.

PromptArmor just published an attack chain against Microsoft Copilot Cowork that turns the agent into an insider threat. They hid five lines of prompt injection inside a “skills file.” When the agent reads it, it starts exfiltrating documents from across the M365 environment. The user never sees an approval prompt.[3]

The mechanism is indirect prompt injection. Copilot Cowork uses skills files to learn workflows. If an attacker slips a malicious instruction into a document the agent reads—maybe you ask Cowork to summarize a shared folder—the agent parses the payload and executes it.[3]

The Exfiltration Mechanism

The hijacked agent uses Microsoft Graph to generate pre-authenticated download links for files you have access to in SharePoint or OneDrive.[3] These are shareable URLs that bypass authentication entirely. Anyone with the link can download the file.[3][4]

Instead of emailing the attacker directly, the agent embeds those URLs inside invisible HTML image tags pointing to an attacker-controlled server.[3]

It then sends you, the victim, a Teams message containing the payload.[3] Since the message comes from your own agent, it skips human approval.[3] When you open the Teams chat, the client automatically tries to load the invisible image. That single HTTP GET request leaks the download links straight to the attacker’s server logs.[3]

No MFA prompts. No suspicious login alerts. Just a broken image link.

The Practitioner Take

This is the nightmare scenario for enterprise AI. We deploy agents as principals operating with our privileges, but they have zero intuition for when they are being used as a confused deputy.

Allowing Cowork to generate pre-authenticated links without human confirmation is a straight-up design flaw. And the fact that Teams automatically renders external images—enabling zero-click exfiltration via GET requests—is an ancient Web 1.0 problem we are suddenly rediscovering.[3]

Microsoft hasn’t issued a CVE or a patch for this yet.[3] The only real mitigation right now is administrative: SharePoint admins have to deploy policies blocking the generation of pre-authenticated download links for sensitive sites.[3] If you are rolling out Copilot Cowork, restrict it via security groups and turn on Restricted Content Discovery (RCD) so the agent doesn’t have access to the crown jewels by default.[3]

We are way past the theoretical phase of prompt injection. If you deploy AI agents that can read your data and render output in a chat client, you have to assume they will eventually be turned against you.

Sources

[3] https://byteiota.com/microsoft-copilot-cowork-file-exfiltration — Microsoft Copilot Cowork Exfiltrates Your Files [4] https://news.ycombinator.com/item?id=48272354 — Hacker News: Microsoft Copilot Cowork Exfiltrates Files