azure-diagnostics

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes legitimate Azure CLI (az) commands for diagnostic purposes, such as az monitor activity-log list, az containerapp show, and az network nsg rule list. These commands are context-appropriate for diagnostic workflows and are configured as read-only fallbacks.
  • [PROMPT_INJECTION]: The skill ingests untrusted telemetry and logs from Azure services, creating a surface for indirect prompt injection.
  • Ingestion points: CLI outputs from log commands and results from KQL queries (e.g., AppExceptions in references/logs-metrics-kql.md).
  • Boundary markers: None; the skill does not instruct the agent to use specific delimiters for external telemetry data.
  • Capability inventory: Execution of az CLI commands via the shell.
  • Sanitization: The instructions explicitly mention avoiding the printing of secret values and performing verification before taking action based on recommendations.
  • [SAFE]: The skill exhibits no signs of obfuscation, persistence mechanisms, or unauthorized network activity. It follows established security protocols by prioritizing read-only diagnostics and using standard, well-documented cloud management tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 09:41 PM
Security Audit — agent-trust-hub — azure-diagnostics