microsoft-security-skills-plugin

Warn

Audited by Gen Agent Trust Hub on Jun 12, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill directs the user to download and install security modules from an external GitHub repository (https://github.com/vinayaklatthe/microsoft-security-skills) which is not explicitly identified as a trusted vendor resource in the context of the current author.
  • [COMMAND_EXECUTION]: Several installation commands are provided that automate the fetching and setup of external content, including apm install, npx skills add, and gemini extensions install. These commands include flags such as -y which can suppress user confirmation during execution.
  • [EXTERNAL_DOWNLOADS]: The skill references a third-party repository (vinayaklatthe/microsoft-security-skills) for its core functionality, which introduces a dependency on external, unverifiable code for the security expertise it provides.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 12, 2026, 08:51 PM
Security Audit — agent-trust-hub — microsoft-security-skills-plugin