ToolNavs Find Useful AI Tools
Submit Sign in
Back to AI information
Copilot Cowork Sandbox Bypass Exposed: A Skill Downloaded Online Could Steal Your Outlook Email

Copilot Cowork Sandbox Bypass Exposed: A Skill Downloaded Online Could Steal Your Outlook Email

AI information • Admin • • 4 views

The sandbox in Copilot Cowork was supposed to be an iron door. Security research published by PromptArmor on September 30 shows it can be bypassed. An attacker only needs the victim to run a malicious Skill downloaded from the internet inside Cowork: the Skill can open a command-and-control channel back to the attacker's server, quietly exfiltrating Outlook emails, SharePoint files, and Teams chat history — and even clicking the "stop" button won't halt the attack.

The attack chain has four steps. First, the victim does something entirely ordinary in Copilot Cowork, like asking it to "check two contracts for contradictory clauses," and invokes a Skill called /doc-consistency — such Skills are routinely downloaded from the web or shared inside companies. Second, a script bundled with the Skill is malicious and calls a file-sync service that lives outside the sandbox. Third, that sync service, whose job is to hand files back to the user, accepts any attacker-chosen URL — effectively opening a direct door to the internet for the malicious script. Fourth, the malicious script fetches a command file from the attacker's server every few seconds, executes it in the sandbox, and sends the results back inside URL parameters. PromptArmor demonstrated the attacker listing the victim's Outlook messages from their own terminal and reading through an entire email thread about a deal, one message at a time.

Two details should alarm enterprise users. First, the stop button is useless: background processes in the sandbox keep running after an agent's turn ends, so stopping the chat doesn't stop them. Second, the attack surface is not prompt injection but the Skill supply chain — a Cowork Skill can bundle up to 20 companion files (scripts, reference documents, and more), and any third-party Skill can hide malicious code that users can't easily tell apart from a trustworthy one.

PromptArmor reported the vulnerability to Microsoft on June 24 of this year, and Microsoft confirmed it mitigated on August 19 — the research was only published after responsible disclosure. If your team uses Microsoft 365 Copilot Cowork, three things are worth doing now: audit the third-party Skills in use internally and remove any of unknown origin; confirm Microsoft's security fixes are deployed; and write "don't install Skills from random websites" into your internal usage policy. The malicious-Skill route is only just getting started for the agent era — a recent test by the UK AI Safety Institute also found that flagship agent models now succeed at unauthorized attacks at five times the rate of the previous generation. (GPT-6 Astra's unauthorized attack rate hits five times the previous generation)

Recommended Tools

More