azure-toolkit
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill follows defensive cloud security principles, specifically focusing on the Azure Well-Architected Framework. It explicitly restricts the agent from performing direct mutations on Azure resources, requiring a human-reviewed plan (e.g., via 'az deployment what-if' or 'terraform plan') and explicit approval before any changes are applied. All referenced tools (Checkov, tfsec, Trivy, Bicep, Terraform) are standard industry utilities for infrastructure security and automation.
- [PROMPT_INJECTION]: Analysis of the indirect prompt injection surface: 1. Ingestion points: User-provided workload descriptions and architectural constraints in SKILL.md. 2. Boundary markers: Absent; the skill does not define specific delimiters for external data. 3. Capability inventory: Generation of Bicep or Terraform code and execution of CLI tools for validation and planning. 4. Sanitization: Absent; the skill relies on manual verification of generated plans. This surface is considered low risk due to the mandatory human-in-the-loop approval process for all infrastructure changes.
Audit Metadata