azure-review

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs a legitimate security function by auditing Azure infrastructure configurations (Terraform, Bicep, ARM templates) against the CIS Microsoft Azure Foundations Benchmark v2.1.0.
  • [SAFE]: Tool access is restricted to basic file system operations (Read, Grep, Glob), preventing the skill from performing unauthorized network operations or executing external code.
  • [SAFE]: The skill includes a dedicated 'Prompt Injection Safety Notice' that instructs the agent to treat audited file content as data rather than instructions, effectively addressing potential indirect prompt injection vulnerabilities.
  • [SAFE]: Analysis of all skill files found no evidence of obfuscation, hidden commands, hardcoded credentials, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 01:36 PM
Security Audit — agent-trust-hub — azure-review