azure-architecture-autopilot

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill extensively uses PowerShell to execute Azure CLI (az) and Bicep commands to scan existing infrastructure, verify service availability, and manage deployments. These commands are essential for its core functionality and follow standard Azure administration practices.
  • [DYNAMIC_EXECUTION]: The diagram engine in scripts/cli.py dynamically generates a Node.js script to perform HTML-to-PNG conversion via Puppeteer. This execution is local, targeted at a specific visualization task, and uses path resolution to prevent injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from Azure resource metadata and Microsoft documentation, which creates a potential surface for indirect prompt injection. This is addressed by the evidence chain: Ingestion points are localized in phase0-scanner.md and phase1-advisor.md; boundary markers are established through the multi-phase validation process; capabilities include shell execution and file writing; and sanitization is implemented using JMESPath filtering in CLI commands.
  • [EXTERNAL_DOWNLOADS]: The skill fetches service specifications and architectural guidelines from trusted Microsoft domains including learn.microsoft.com and azure.microsoft.com. These downloads are performed to ensure generated templates use correct API versions and adhere to official best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:34 AM
Security Audit — agent-trust-hub — azure-architecture-autopilot