azure-review
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows secure design principles for its intended purpose of security posture assessment.
- [PROMPT_INJECTION]: The skill includes a 'Prompt Injection Safety Notice' that explicitly instructs the AI agent to treat all data within scanned infrastructure files as untrusted content, preventing indirect prompt injection attacks.
- [EXTERNAL_DOWNLOADS]: The skill only references documentation from well-known and trusted sources like Microsoft, the Center for Internet Security (CIS), and HashiCorp. No remote scripts or executable code are fetched.
- [COMMAND_EXECUTION]: Capability usage is limited to built-in platform tools (
Read,Grep,Glob) for the purpose of analyzing local configuration files. There are no attempts to execute arbitrary shell commands or perform privileged operations.
Audit Metadata