azure-pipeline-architect

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and retrieves latest YAML syntax architecture and security guidelines from Microsoft's official documentation (learn.microsoft.com). This is a standard practice for maintaining compliance with Azure DevOps standards.
  • [COMMAND_EXECUTION]: The utility templates utilize PowerShell scripts to manage environment configurations, such as IIS website creation, application pool management, and file system operations (backup, deploy, cleanup). These commands are localized to the build agent environment and are essential for the skill's stated purpose of pipeline architecture.
  • [PROMPT_INJECTION]: The skill processes project source code structures and documentation to generate Pipeline configurations. While this presents a surface for indirect prompt injection, the templates use structured parameters and standard Azure DevOps tasks, which limits the risk of arbitrary instruction execution. The primary output is human-readable YAML for developer review.
  • [DATA_EXFILTRATION]: No evidence of unauthorized sensitive file access or credential harvesting. The skill manages standard CI/CD variables and artifacts within the defined Azure DevOps workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 04:46 AM
Security Audit — agent-trust-hub — azure-pipeline-architect