microsoft-docs

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill recommends using the @microsoft/learn-cli package via npx or global installation. This is a vendor-provided tool from Microsoft, a trusted organization.- [COMMAND_EXECUTION]: The instructions direct the agent to perform search and fetch operations using shell commands via npx or the mslearn CLI tools.- [INDIRECT_PROMPT_INJECTION]: The skill processes external documentation data, which represents a vulnerability surface for embedded instructions in the fetched content.
  • Ingestion points: Web-based documentation content retrieved through microsoft_docs_fetch and the CLI fetch command.
  • Boundary markers: None. The skill does not specify delimiters or instructions to ignore commands within the fetched data.
  • Capability inventory: The skill has the ability to execute shell commands via npx and specialized CLI tools.
  • Sanitization: No sanitization, filtering, or validation of the retrieved documentation content is present.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:39 AM
Security Audit — agent-trust-hub — microsoft-docs