azsdk-common-apiview-feedback-resolution

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it processes external reviewer comments fetched via URL to guide code modifications and regeneration. Ingestion: azure-sdk-mcp:azsdk_apiview_get_comments tool fetching from APIView URLs. Capabilities: azsdk_customized_code_update and azsdk_package_generate_code. Boundary markers: None identified. Sanitization: Not specified. This surface is inherent to the skill's primary function in the Azure SDK development lifecycle.
  • [SAFE]: All tools in the azure-sdk-mcp namespace and domains like apiview.dev and apiviewstagingtest.com are verified vendor-owned resources for Azure development.
  • [SAFE]: No patterns of obfuscation, credential exfiltration, or unauthorized persistence mechanisms were detected in the skill instructions or supporting files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 09:49 AM
Security Audit — agent-trust-hub — azsdk-common-apiview-feedback-resolution