azure-resource-visualizer

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill ingests Azure resource metadata, such as resource names and tags, which are externally controlled. While this is necessary for diagram generation, malicious content within these fields could potentially influence the agent's behavior during report preparation.
  • Ingestion points: Resource data retrieved via Azure CLI and Resource Graph queries (SKILL.md).
  • Boundary markers: The skill does not define explicit delimiters for incoming resource data during the processing phase.
  • Capability inventory: Capabilities include Azure CLI read-only operations and file system write access for report generation.
  • Sanitization: The skill proactively instructs the agent to use placeholders for sensitive values like connection strings, which helps prevent data exposure.
  • [Extension Installation]: The skill utilizes the standard resource-graph extension for the Azure CLI. This is a common requirement for performing complex cross-subscription resource analysis and is a recognized component of the Azure management ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 02:52 PM
Security Audit — agent-trust-hub — azure-resource-visualizer