azure-storage

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the retrieval of data from external sources (Azure Blob Storage) through the storage_blob_get tool and various SDK examples. This creates an ingestion point for untrusted data that could potentially contain malicious instructions. Mandatory Evidence Chain: 1. Ingestion points: SKILL.md (MCP tool) and references/sdk/ files (download methods). 2. Boundary markers: Absent. 3. Capability inventory: Azure Storage management and data retrieval. 4. Sanitization: No sanitization of downloaded content is performed.
  • [METADATA_POISONING]: The skill metadata designates 'Microsoft' as the author, whereas the repository is maintained by 'kinnekate-hub'. This common attribution for documentation wrappers is informative rather than deceptive in this instance.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 06:42 PM
Security Audit — agent-trust-hub — azure-storage