azure-compliance
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or significant security risks were identified. The skill facilitates legitimate Azure resource management and compliance auditing.- [PROMPT_INJECTION]: The skill provides instructions for the agent to analyze outputs from external tools like azqr and Azure Resource Graph. While this defines an ingestion surface for potentially untrusted data (Indirect Prompt Injection), the risk is minimal as it operates on the user's own cloud environment data within an administrative context.- [DATA_EXFILTRATION]: The skill uses tools to retrieve metadata from Azure Key Vault (e.g., expiration dates of secrets and certificates). This is essential for compliance auditing and is performed using standard Azure MCP tools without any evidence of exfiltration to unauthorized external domains.
Audit Metadata