azure-developer-cli
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill analyzes local repository files including
azure.yaml, infrastructure-as-code files (Bicep/Terraform), and deployment scripts. This represents a standard surface for indirect prompt injection common in development tools, where malicious content in a processed file could attempt to influence agent behavior. - Ingestion points: Processes
azure.yaml,infradirectory content, source code projects, and pipeline definitions. - Boundary markers: None explicitly defined for interpolated data.
- Capability inventory: Executes standard development CLI tools including
azd,az bicep, andterraform. - Sanitization: Not explicitly implemented; the skill relies on the user's local environment security and standard CLI tool validation.
- [EXTERNAL_DOWNLOADS]: The skill references official configuration schemas and technical documentation from trusted sources including Microsoft Learn and official Azure/GitHub repositories. These references are essential for maintaining up-to-date development standards and do not involve untrusted remote code execution.
Audit Metadata