microsoft-docs
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- External CLI Fallback: The skill suggests using the
@microsoft/learn-clipackage vianpxornpmas a fallback. This involves downloading and executing code from the npm registry. Because this resource is provided by the vendor, it is consistent with the skill's functionality and official documentation purpose. - Content Ingestion from External Sources: Through the
microsoft_docs_fetchtool, the agent retrieves content from external documentation URLs. As with any tool that processes web content, there is a possibility that the ingested data could contain text that influences the agent's behavior. This is a common consideration for skills that interact with external web data and is typically managed by the agent's own safety protocols.
Audit Metadata