azure-dev-box

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches documentation from learn.microsoft.com. This domain is the official host for Microsoft's technical documentation and is recognized as a well-known service.- [PROMPT_INJECTION]: Identified a surface for Indirect Prompt Injection (Category 8).
  • Ingestion points: External documentation is fetched from learn.microsoft.com into the agent context via documentation tools.
  • Boundary markers: The skill does not specify delimiters for wrapping retrieved content.
  • Capability inventory: No dangerous tools such as shell execution, file system modification, or arbitrary network exfiltration are utilized.
  • Sanitization: The skill does not implement explicit sanitization of the fetched markdown data.- [SAFE]: No executable code, binary components, or sensitive data access patterns were detected in the skill contents.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 01:59 AM