microsoft-foundry

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • Cloud Infrastructure Management: The skill leverages the Azure CLI (az) and Azure Developer CLI (azd) to provision and configure resources such as AI Services, Container Registries, and Virtual Networks. These operations require high-level permissions but are necessary for the skill's primary function of infrastructure management.
  • Remote Resource Acquisition: The skill downloads deployment templates and sample agent code from official Microsoft and Azure-Samples repositories on GitHub. These resources are fetched from well-known, trusted organizations to seed new projects with established patterns.
  • Observability and Telemetry Analysis: The skill performs structured queries against Application Insights using Kusto Query Language (KQL) to help developers analyze agent performance and failures. This involves processing agent-generated traces and logs, which is a standard practice for diagnosing production behavior.
  • Identity and Access Management Guidance: The skill includes detailed workflows for managing Role-Based Access Control (RBAC) and managed identities. These instructions help users implement security best practices, such as moving away from hardcoded keys toward identity-based authentication for Azure services.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 10:12 PM
Security Audit — agent-trust-hub — microsoft-foundry