microsoft-foundry

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Azure CLI (az) and bundled scripts to manage cloud resources, discover model capacity, and perform deployments. These operations are within the stated purpose of the skill as an administrative tool for Azure AI Foundry.
  • [EXTERNAL_DOWNLOADS]: The skill downloads configuration templates and starter code from the trusted 'microsoft-foundry/foundry-samples' repository on GitHub. These actions are performed to initialize new agent projects at the user's request.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes a pipeline to harvest production traces from Application Insights for evaluation purposes. Although these traces contain raw user input, the skill enforces a mandatory human review step (curation) that requires users to approve all candidates before they are incorporated into agent instructions or datasets.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 06:42 PM
Security Audit — agent-trust-hub — microsoft-foundry