microsoft-docs

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • External CLI Fallback: The skill suggests using the @microsoft/learn-cli package via npx or npm as a fallback. This involves downloading and executing code from the npm registry. Because this resource is provided by the vendor, it is consistent with the skill's functionality and official documentation purpose.
  • Content Ingestion from External Sources: Through the microsoft_docs_fetch tool, the agent retrieves content from external documentation URLs. As with any tool that processes web content, there is a possibility that the ingested data could contain text that influences the agent's behavior. This is a common consideration for skills that interact with external web data and is typically managed by the agent's own safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:14 PM
Security Audit — agent-trust-hub — microsoft-docs