microsoft-foundry
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- Dynamic Code Execution: The script
finetuning/scripts/calibrate_grader.pyutilizes theexec()andcompile()functions to load a Python function from a user-specified file. - Evidence: Found in
finetuning/scripts/calibrate_grader.pyat lines 53-56. - Context: This is used to allow users to provide custom grading logic for reinforcement fine-tuning. Since the script executes the provided Python code with the permissions of the current environment, users should ensure they only provide grader files they have reviewed or authored themselves.
- Command Execution: The skill frequently executes shell commands through the Azure CLI (
az) and Azure Developer CLI (azd) to manage cloud resources. - Evidence: For example,
finetuning/scripts/deploy_model.pyusessubprocess.runto executeaz account get-access-tokenfor authentication. - Context: This is standard functionality for an infrastructure management skill. It relies on the security and configuration of the local CLI environment and the user's active Azure session.
- External Dependencies and Downloads: The skill instructions and setup scripts download several Python packages and
azdextensions from official Microsoft sources. - Evidence: Found in
scripts/check-and-setup-dependencies.sh(installingmicrosoft.foundry) and thedependenciesblocks in several Python scripts (e.g.,azure-ai-projects). - Context: All identified external resources originate from trusted Microsoft organizations or official package registries, which is expected for the skill's stated purpose.
Audit Metadata