microsoft-foundry

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Dynamic Code Execution: The script finetuning/scripts/calibrate_grader.py utilizes the exec() and compile() functions to load a Python function from a user-specified file.
  • Evidence: Found in finetuning/scripts/calibrate_grader.py at lines 53-56.
  • Context: This is used to allow users to provide custom grading logic for reinforcement fine-tuning. Since the script executes the provided Python code with the permissions of the current environment, users should ensure they only provide grader files they have reviewed or authored themselves.
  • Command Execution: The skill frequently executes shell commands through the Azure CLI (az) and Azure Developer CLI (azd) to manage cloud resources.
  • Evidence: For example, finetuning/scripts/deploy_model.py uses subprocess.run to execute az account get-access-token for authentication.
  • Context: This is standard functionality for an infrastructure management skill. It relies on the security and configuration of the local CLI environment and the user's active Azure session.
  • External Dependencies and Downloads: The skill instructions and setup scripts download several Python packages and azd extensions from official Microsoft sources.
  • Evidence: Found in scripts/check-and-setup-dependencies.sh (installing microsoft.foundry) and the dependencies blocks in several Python scripts (e.g., azure-ai-projects).
  • Context: All identified external resources originate from trusted Microsoft organizations or official package registries, which is expected for the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 12:28 AM
Security Audit — agent-trust-hub — microsoft-foundry