azure-cost-management

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute various Azure CLI commands (az costmanagement, az consumption, az advisor) to analyze costs, budgets, and recommendations. This is the primary and intended functionality of the skill.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from external sources (Azure API responses).
  • Ingestion points: Data enters the agent's context through the output of commands such as az costmanagement query, az consumption budget list, and az advisor recommendation list in SKILL.md.
  • Boundary markers: The instructions do not define explicit delimiters or warnings to ignore potential instructions embedded within the retrieved cloud metadata (e.g., budget names or resource tags).
  • Capability inventory: The skill has the capability to execute shell commands and query various cloud management APIs across several scripts and command blocks in SKILL.md.
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the external content before it is processed or presented in the structured report format.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 11:46 AM
Security Audit — agent-trust-hub — azure-cost-management