azure-devops-wiki-markdown

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes a Python script (scripts/find_code_language.py) to fetch the current list of supported language aliases from the official Highlight.js repository on GitHub. This functionality is intended to provide accurate, up-to-date information for users regarding code-fence syntax.
  • [COMMAND_EXECUTION]: The skill instructions guide the user to execute local Python scripts for language alias verification and internal skill validation. These scripts perform routine operations such as data fetching, parsing, and file integrity checks within the skill's directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an ingestion surface as it processes external data from a public GitHub repository and user-provided queries. However, the risk is considered safe due to the use of well-known, reputable sources and the structured way the data is parsed and presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — azure-devops-wiki-markdown