azure-network-function-manager

Pass

Audited by Gen Agent Trust Hub on Mar 8, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation from learn.microsoft.com using the mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage tools. It also references a tool installation guide on github.com/MicrosoftDocs. These represent official vendor resources and trusted domains.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by integrating external data into the agent's context.
  • Ingestion points: Documentation is retrieved from learn.microsoft.com via specified tools as described in SKILL.md.
  • Boundary markers: The skill does not provide explicit delimiters or instructions to the agent to disregard instructions contained within the fetched documentation.
  • Capability inventory: The skill is configured for network read operations; no local shell execution or file system writing is defined in this skill file.
  • Sanitization: There is no evidence of sanitization or validation of the markdown content retrieved from the external URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 8, 2026, 08:31 AM