azure-diagnostics

Warn

Audited by ZeroLeaks on Apr 15, 2026

Risk Level: MEDIUM
Scan Summary

The SKILL.md is transparent and reviewable, with no hidden execution paths or obfuscated content. However, the skill does materially weaken instruction/data boundaries by treating untrusted external content in a way that blurs the line with policy-level instructions, which increases prompt-injection risk. Behavior analysis was not run, so downstream impact relative to a no-skill baseline remains unvalidated. Given the identified boundary-weakening issue and the missing behavioral comparison, this does not pass clean—the prompt-injection concern is real and warrants remediation before deployment.

Score
69/100
Verdict
AT_RISK
Confidence
medium
Findings
1
Section Analysis (3)
TransparencyPASS
96/100

The scanned SKILL.md is materially reviewable, with no hidden execution path or secret-like content detected in the markdown.

Prompt InjectionWARNING
57/100

The skill increases prompt injection risk by weakening trust boundaries around untrusted external content treated as policy.

Agent BehaviorSkipped

Behavior analysis was not run.

Findings (1)
CRITICAL

Untrusted external content treated as policy

Coverage DetailsClick to expand
Discovered Files
1
Omitted Files
0
Analyzed Bytes
4.4 KB
Sections Completed
2
Sections Skipped
1
Behavior Probes
0/0
Audit Metadata
Score
69/100
Verdict
AT_RISK
Confidence
medium
Sections
2/3 completed
Findings
1
Mode
risk
Files Scanned
1
Duration
136.7s
Analyzed
Apr 15, 2026, 10:03 PM
Security Audit — zeroleaks — azure-diagnostics