agent-framework-azure-ai-py
Pass
Audited by Gen Agent Trust Hub on May 27, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The documentation provides standard shell commands for package installation using
pip install. - [EXTERNAL_DOWNLOADS]: The skill instructs users to install
agent-frameworkandagent-framework-azure-aifrom public package registries. These are documented as the core dependencies for the agent framework described. - [SAFE]: The skill correctly implements authentication using
DefaultAzureCredentialandAzureCliCredentialfrom the officialazure-identitylibrary. It also references well-known services including Azure AI Foundry, Bing Search, and Microsoft Learn. - [PROMPT_INJECTION]: The skill's architecture is susceptible to indirect prompt injection (Category 8) due to the integration of external data sources with high-privilege tools.
- Ingestion points: Untrusted data enters the agent context through
HostedWebSearchToolandHostedFileSearchToolas described in the Multi-Tool Agent and Research Assistant examples inSKILL.md. - Boundary markers: The provided code examples do not include delimiters or specific instructions to the agent to disregard instructions found within external search results.
- Capability inventory: The agent has access to
HostedCodeInterpreterTool, which allows for code execution in a hosted environment, andMCPStreamableHTTPToolfor interacting with external APIs. - Sanitization: There is no evidence of input validation or content sanitization for the data retrieved from hosted tools before it is processed by the agent.
Audit Metadata