azure-dev-box
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches documentation from learn.microsoft.com. This domain is the official host for Microsoft's technical documentation and is recognized as a well-known service.- [PROMPT_INJECTION]: Identified a surface for Indirect Prompt Injection (Category 8).
- Ingestion points: External documentation is fetched from learn.microsoft.com into the agent context via documentation tools.
- Boundary markers: The skill does not specify delimiters for wrapping retrieved content.
- Capability inventory: No dangerous tools such as shell execution, file system modification, or arbitrary network exfiltration are utilized.
- Sanitization: The skill does not implement explicit sanitization of the fetched markdown data.- [SAFE]: No executable code, binary components, or sensitive data access patterns were detected in the skill contents.
Audit Metadata