Agentic Consent Builder Hardening (CoPhish-Shaped Holes)
When the OAuth consent UX on an agent-builder platform is itself the phishing path
Operator recipe for agent-builder platforms whose OAuth consent UX can itself become the phishing path. CoPhish (Datadog Security Labs, Oct 2025) used a real Copilot Studio agent on copilotstudio.microsoft.com: configurable sign-in redirect plus a post-consent HTTP action that exfiltrated tokens server-side from Microsoft infrastructure. Pattern to check for: (1) host under a trusted platform domain, (2) configurable OAuth consent destination, (3) automated post-consent action. Hardening checks: redirect allowlist — not free-text; treat post-consent actions as a privileged, reviewed capability; issue audience-bound tokens (RFC 8707); separate who-can-build from who-can-grant high-risk scopes; correlate agent-creation events with consent-grant events; do not treat domain trust as a phishing signal. Industry direction cited on the primary: Entra Agent ID mandatory for new Copilot Studio agents (Jul 2026); WorkOS Agent Auth early access (Sep 2026) for first-class agent identity and short-lived scoped tokens. Primary: https://workos.com/blog/cophish-and-the-agentic-consent-problem-oauth-phishing-for-the-agent-builder-era.
Core Workflows (6)
Each workflow represents a critical business function. Click any workflow to see detailed automation architecture.
Check for the CoPhish-shaped pattern
Led by: Consent OperatorCoPhish (Datadog Security Labs, Oct 2025) used a real Copilot Studio agent on copilotstudio.microsoft.com: configurable sign-in redirect plus a post-consent HTTP action that exfiltrated tokens server-side from Microsoft infrastructure. Pattern to check for: (1) host under a trusted platform domain, (2) configurable OAuth consent destination, (3) automated post-consent action. Do not treat domain trust as a phishing signal.
Allowlist redirects — not free-text
Led by: Consent OperatorHardening check: redirect allowlist — not free-text. A configurable OAuth consent destination is one of the three CoPhish-shaped holes.
Treat post-consent actions as privileged
Led by: Consent OperatorHardening check: treat post-consent actions as a privileged, reviewed capability. CoPhish used a post-consent HTTP action that exfiltrated tokens server-side from Microsoft infrastructure.
Issue audience-bound tokens (RFC 8707)
Led by: Authorization OperatorHardening check: issue audience-bound tokens (RFC 8707). Industry direction cited on the primary also points at short-lived scoped tokens (WorkOS Agent Auth early access, Sep 2026).
Separate who-can-build from who-can-grant
Led by: Consent OperatorHardening check: separate who-can-build from who-can-grant high-risk scopes. Correlate agent-creation events with consent-grant events.
Watch Entra Agent ID and WorkOS Agent Auth
Led by: Identity OperatorIndustry direction cited on the primary: Entra Agent ID mandatory for new Copilot Studio agents (Jul 2026); WorkOS Agent Auth early access (Sep 2026) for first-class agent identity and short-lived scoped tokens.