azure-validate
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- Indirect Prompt Injection Surface: The skill ingests untrusted data by scanning various source and configuration files in the user's workspace, which could potentially contain malicious instructions designed to influence the agent's behavior during the validation process.\n
- Ingestion points: The skill reads content from
.csfiles (viareferences/scripts/scan-aspire-functions-secrets.sh),.tfand.tfvars.jsonfiles (viareferences/scripts/validate-terraform.sh), andazure.yaml(referenced inreferences/recipes/azd/README.md).\n - Boundary markers: There are no explicit delimiters or warnings provided to the agent instructions to ignore content embedded within the files being scanned.\n
- Capability inventory: The skill has the capability to execute shell commands using
az,azd,terraform,docker, andnpmacross its helper scripts, and it can modify local state files such as.azure/deployment-plan.md.\n - Sanitization: The skill does not perform sanitization, escaping, or filtering of the content read from these external project files before processing them.\n- Tool and Command Execution: The skill defines a structured workflow for invoking several powerful command-line tools including the Azure CLI (
az), Azure Developer CLI (azd), Terraform, and Docker. These tools are used appropriately for their intended purpose of infrastructure validation and deployment readiness, but they grant the agent broad capabilities within the user's environment.\n - Evidence: Multiple scripts in the
references/scripts/directory and instructional recipes inreferences/recipes/automate the execution of these commands.
Audit Metadata