entra-app-registration
Pass
Audited by Gen Agent Trust Hub on Feb 20, 2026
Risk Level: SAFE
Full Analysis
- SAFE (SAFE): No malicious patterns or security vulnerabilities were detected in the analyzed files. The content is educational and instructional.\n- Category 1 (Prompt Injection): No instructions attempting to bypass safety filters or override system behavior were found.\n- Category 2 (Data Exposure): No hardcoded secrets or sensitive file paths were detected. The skill correctly uses placeholders for sensitive values (e.g., GUIDs) and explicitly instructs users to store secrets in secure locations like Azure Key Vault.\n- Category 4 (Dependencies): The skill references trusted official Microsoft Authentication Libraries (MSAL) and standard Azure CLI commands. No suspicious third-party packages or remote script execution (curl | bash) were found.\n- Category 5 (Privilege Escalation): While high-privilege commands like
admin-consentare documented, they are appropriate for the skill's primary purpose of administrative app registration and are not presented in an automated or deceptive manner.\n- Category 8 (Indirect Prompt Injection): The skill provides documentation and does not include mechanisms for ingesting or processing untrusted external data at runtime.
Audit Metadata