aca-sandboxes
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [Remote Script Installation]: The skill includes instructions to install the
acaCLI by executing scripts directly from Microsoft'saka.msdomain. This is a standard practice for Azure tools, though it involves executing code from a remote source on the local machine. - [Command Execution in Isolated Environments]: A core capability of this skill is running shell commands and interactive sessions within microVMs. This is the primary intended use case, facilitating the execution of code in a hardware-isolated environment.
- [Network and File System Operations]: The skill provides tools for exposing network ports and managing files within sandboxes. It includes built-in security features such as Entra ID authentication and egress control policies to help manage external connectivity and data access.
- [Authentication and Configuration]: The skill leverages the Azure CLI for identity management and stores local configuration in the user's home directory. Users are informed about the sensitivity of debug logs, highlighting standard operational security practices for CLI tools.
Audit Metadata