microsoft-docs

Pass

Audited by Gen Agent Trust Hub on Jun 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the @microsoft/learn-cli package available on the npm registry. The instructions suggest using specific versions (0.1.0), which is a security best practice for supply chain stability. The package is part of the well-known @microsoft organization.
  • [SAFE]: The skill contains a 'Remote Content Safety' section that explicitly directs the agent to treat external search results and fetched pages as untrusted. It instructs the agent to ignore embedded instructions or tool requests found in the data, mitigating the risk of indirect prompt injection.
  • [SAFE]: The skill employs clear routing and composition rules, deferring specific technical implementations and code examples to more specialized skills, which limits the scope and potential misuse of documentation-fetching capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 28, 2026, 05:51 PM
Security Audit — agent-trust-hub — microsoft-docs