microsoft-docs
Pass
Audited by Gen Agent Trust Hub on Jun 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the
@microsoft/learn-clipackage available on the npm registry. The instructions suggest using specific versions (0.1.0), which is a security best practice for supply chain stability. The package is part of the well-known@microsoftorganization. - [SAFE]: The skill contains a 'Remote Content Safety' section that explicitly directs the agent to treat external search results and fetched pages as untrusted. It instructs the agent to ignore embedded instructions or tool requests found in the data, mitigating the risk of indirect prompt injection.
- [SAFE]: The skill employs clear routing and composition rules, deferring specific technical implementations and code examples to more specialized skills, which limits the scope and potential misuse of documentation-fetching capabilities.
Audit Metadata