azure-hosted-copilot-sdk

Pass

Audited by Gen Agent Trust Hub on Apr 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Use of Trusted Templates: The skill instructs the agent to use azd init with a template from azure-samples, which is a recognized and trusted source for Azure development. This approach ensures that the initial project structure follows recommended patterns.\n- Authentication Best Practices: The skill includes detailed documentation on using passwordless authentication. By recommending ManagedIdentityCredential for production, it helps developers avoid the risks associated with hardcoded credentials and secret management.\n- Secure Deployment Hooks: It describes a process for handling GitHub tokens using azd hooks and Azure Key Vault. This pattern ensures that sensitive tokens are handled securely and are not exposed in logs or environment variables.\n- Documentation and Resource Integration: The skill leverages MCP tools to fetch the most up-to-date documentation for the Copilot SDK, ensuring that the implementation remains consistent with the latest security and API guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 8, 2026, 09:58 PM