skills/openhands/skills/azure-devops/Gen Agent Trust Hub

azure-devops

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: Employs git and curl to perform repository management and API tasks as specified in the skill instructions.
  • [DATA_EXFILTRATION]: Accesses the AZURE_DEVOPS_TOKEN environment variable for authentication. It directs all network traffic to official dev.azure.com endpoints and providing instructions for local credential configuration through standard git commands.
  • [PROMPT_INJECTION]: Identifies an indirect prompt injection surface where the agent processes external data from Azure DevOps (ingestion points) and has write capabilities (capability inventory), though this is characteristic of the skill's integration purpose rather than a malicious pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 01:32 PM