azure-validate

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill ingests untrusted data by scanning various source and configuration files in the user's workspace, which could potentially contain malicious instructions designed to influence the agent's behavior during the validation process.\n
  • Ingestion points: The skill reads content from .cs files (via references/scripts/scan-aspire-functions-secrets.sh), .tf and .tfvars.json files (via references/scripts/validate-terraform.sh), and azure.yaml (referenced in references/recipes/azd/README.md).\n
  • Boundary markers: There are no explicit delimiters or warnings provided to the agent instructions to ignore content embedded within the files being scanned.\n
  • Capability inventory: The skill has the capability to execute shell commands using az, azd, terraform, docker, and npm across its helper scripts, and it can modify local state files such as .azure/deployment-plan.md.\n
  • Sanitization: The skill does not perform sanitization, escaping, or filtering of the content read from these external project files before processing them.\n- Tool and Command Execution: The skill defines a structured workflow for invoking several powerful command-line tools including the Azure CLI (az), Azure Developer CLI (azd), Terraform, and Docker. These tools are used appropriately for their intended purpose of infrastructure validation and deployment readiness, but they grant the agent broad capabilities within the user's environment.\n
  • Evidence: Multiple scripts in the references/scripts/ directory and instructional recipes in references/recipes/ automate the execution of these commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 12:28 AM
Security Audit — agent-trust-hub — azure-validate