← Back to Playbooks
Agent Operations

Agentic Consent Builder Hardening (CoPhish-Shaped Holes)

When the OAuth consent UX on an agent-builder platform is itself the phishing path

Operator recipe for agent-builder platforms whose OAuth consent UX can itself become the phishing path. CoPhish (Datadog Security Labs, Oct 2025) used a real Copilot Studio agent on copilotstudio.microsoft.com: configurable sign-in redirect plus a post-consent HTTP action that exfiltrated tokens server-side from Microsoft infrastructure. Pattern to check for: (1) host under a trusted platform domain, (2) configurable OAuth consent destination, (3) automated post-consent action. Hardening checks: redirect allowlist — not free-text; treat post-consent actions as a privileged, reviewed capability; issue audience-bound tokens (RFC 8707); separate who-can-build from who-can-grant high-risk scopes; correlate agent-creation events with consent-grant events; do not treat domain trust as a phishing signal. Industry direction cited on the primary: Entra Agent ID mandatory for new Copilot Studio agents (Jul 2026); WorkOS Agent Auth early access (Sep 2026) for first-class agent identity and short-lived scoped tokens. Primary: https://workos.com/blog/cophish-and-the-agentic-consent-problem-oauth-phishing-for-the-agent-builder-era.

Core Workflows (6)

Each workflow represents a critical business function. Click any workflow to see detailed automation architecture.

01

Check for the CoPhish-shaped pattern

Led by: Consent Operator

CoPhish (Datadog Security Labs, Oct 2025) used a real Copilot Studio agent on copilotstudio.microsoft.com: configurable sign-in redirect plus a post-consent HTTP action that exfiltrated tokens server-side from Microsoft infrastructure. Pattern to check for: (1) host under a trusted platform domain, (2) configurable OAuth consent destination, (3) automated post-consent action. Do not treat domain trust as a phishing signal.

Sub-Agents
Builder Platform
Skills Required
OAuth consentCoPhish pattern
Human TouchpointInventory whether host domain, consent destination, and post-consent action match the three-part pattern
02

Allowlist redirects — not free-text

Led by: Consent Operator

Hardening check: redirect allowlist — not free-text. A configurable OAuth consent destination is one of the three CoPhish-shaped holes.

Sub-Agents
Redirect Policy
Skills Required
OAuth redirect allowlist
Human TouchpointRefuse free-text consent destinations; require an allowlist
03

Treat post-consent actions as privileged

Led by: Consent Operator

Hardening check: treat post-consent actions as a privileged, reviewed capability. CoPhish used a post-consent HTTP action that exfiltrated tokens server-side from Microsoft infrastructure.

Sub-Agents
Reviewer
Skills Required
Post-consent HTTP actions
Human TouchpointReview post-consent actions as a privileged capability, not a default builder feature
04

Issue audience-bound tokens (RFC 8707)

Led by: Authorization Operator

Hardening check: issue audience-bound tokens (RFC 8707). Industry direction cited on the primary also points at short-lived scoped tokens (WorkOS Agent Auth early access, Sep 2026).

Sub-Agents
Consent Operator
Skills Required
RFC 8707Audience-bound tokens
Human TouchpointRequire audience-bound tokens on the consent path
05

Separate who-can-build from who-can-grant

Led by: Consent Operator

Hardening check: separate who-can-build from who-can-grant high-risk scopes. Correlate agent-creation events with consent-grant events.

Sub-Agents
Identity Operator
Skills Required
Agent-creation auditConsent-grant audit
Human TouchpointSplit build permission from high-risk scope grant; correlate creation events with consent grants
06

Watch Entra Agent ID and WorkOS Agent Auth

Led by: Identity Operator

Industry direction cited on the primary: Entra Agent ID mandatory for new Copilot Studio agents (Jul 2026); WorkOS Agent Auth early access (Sep 2026) for first-class agent identity and short-lived scoped tokens.

Sub-Agents
Consent Operator
Skills Required
Entra Agent IDWorkOS Agent Auth
Human TouchpointTrack Entra Agent ID (Jul 2026) and WorkOS Agent Auth early access (Sep 2026) as cited on the primary