azdo-tool
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill interacts with Azure DevOps by executing the
azdo-toolCLI viabun. - [PROMPT_INJECTION]: The skill ingests untrusted data from Azure DevOps build logs, creating a surface for indirect prompt injection. 1. Ingestion points: Build logs retrieved through the
build log-contentcommand. 2. Boundary markers: None defined for the processing of log content in the instructions. 3. Capability inventory: Execution of Azure DevOps CLI commands for pipelines and builds. 4. Sanitization: No sanitization or filtering of external log data is mentioned. - [SAFE]: The skill utilizes dependencies and repositories belonging to the vendor 'blogic-cz'.
- [SAFE]: The skill explicitly defines and enforces restrictions to block write-access verbs and prevent the retrieval of sensitive credentials and secrets.
Audit Metadata