agent-framework-azure-ai-py

Pass

Audited by Gen Agent Trust Hub on May 27, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The documentation provides standard shell commands for package installation using pip install.
  • [EXTERNAL_DOWNLOADS]: The skill instructs users to install agent-framework and agent-framework-azure-ai from public package registries. These are documented as the core dependencies for the agent framework described.
  • [SAFE]: The skill correctly implements authentication using DefaultAzureCredential and AzureCliCredential from the official azure-identity library. It also references well-known services including Azure AI Foundry, Bing Search, and Microsoft Learn.
  • [PROMPT_INJECTION]: The skill's architecture is susceptible to indirect prompt injection (Category 8) due to the integration of external data sources with high-privilege tools.
  • Ingestion points: Untrusted data enters the agent context through HostedWebSearchTool and HostedFileSearchTool as described in the Multi-Tool Agent and Research Assistant examples in SKILL.md.
  • Boundary markers: The provided code examples do not include delimiters or specific instructions to the agent to disregard instructions found within external search results.
  • Capability inventory: The agent has access to HostedCodeInterpreterTool, which allows for code execution in a hosted environment, and MCPStreamableHTTPTool for interacting with external APIs.
  • Sanitization: There is no evidence of input validation or content sanitization for the data retrieved from hosted tools before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 27, 2026, 10:15 PM
Security Audit — agent-trust-hub — agent-framework-azure-ai-py