azure-devops-create-work-item
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill contains a verification script
scripts/probe_create_work_item_packet.pythat usessubprocess.runto test internal logic. The command is constructed safely as a list of strings and does not use a shell, preventing command injection vulnerabilities. - [DATA_EXFILTRATION]: The skill reads project context and writes drafts to the local filesystem in the current working directory. It does not access sensitive directories (e.g., .ssh, .aws), hardcode credentials, or perform unauthorized network requests. All external links target official Microsoft and Google documentation.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external text from user notes and codebases to fill templates. While these are untrusted inputs, they are processed into local Markdown files intended for human-in-the-loop review before use, and the skill does not grant elevated capabilities to the ingested data.
Audit Metadata