governance

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references official Microsoft resources for the Power Platform Center of Excellence (CoE) Starter Kit and Creator Kit using trusted domains such as aka.ms and microsoft.com (e.g., in coe-starter-kit.md). These references are used for legitimate setup and configuration tasks.
  • [COMMAND_EXECUTION]: Files like tenant-admin.md and compliance-audit.md contain PowerShell and Bash snippets for interacting with the Power Platform Admin API. These examples use dynamic token acquisition and environment variables, avoiding the use of hardcoded secrets or dangerous execution patterns.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or passwords were found. Authentication examples correctly demonstrate the use of the az CLI to retrieve access tokens or require existing session variables.
  • [PROMPT_INJECTION]: The instructions and evaluation scenarios (found in evals/governance-decisions.json) are purely focused on administrative tasks and do not contain attempts to override agent behavior or bypass safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 02:03 AM
Security Audit — agent-trust-hub — governance