microsoft-code-reference

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references @microsoft/learn-cli, which is an official package from a well-known vendor. The instructions specifically guide the user to use a pinned version (@0.1.0) for stability.
  • [COMMAND_EXECUTION]: The skill provides examples of using npx and npm install for the official CLI tool. These are documented as alternative workflows if the primary MCP server is unavailable and represent standard developer operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a 'Remote Content Safety' section that explicitly instructs the agent to treat external search results as untrusted data and ignore any embedded instructions or unrelated links. This follows security best practices for handling external documentation content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 05:51 PM
Security Audit — agent-trust-hub — microsoft-code-reference