azure-review
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs a legitimate security function by auditing Azure infrastructure configurations (Terraform, Bicep, ARM templates) against the CIS Microsoft Azure Foundations Benchmark v2.1.0.
- [SAFE]: Tool access is restricted to basic file system operations (
Read,Grep,Glob), preventing the skill from performing unauthorized network operations or executing external code. - [SAFE]: The skill includes a dedicated 'Prompt Injection Safety Notice' that instructs the agent to treat audited file content as data rather than instructions, effectively addressing potential indirect prompt injection vulnerabilities.
- [SAFE]: Analysis of all skill files found no evidence of obfuscation, hidden commands, hardcoded credentials, or persistence mechanisms.
Audit Metadata