azuresql-db-scaffold

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Command Execution]: The skill instructs the agent to use docker and sqlcmd to manage database lifecycles and provision schemas. These operations are standard for development environment setup and are limited to containerized environments.
  • [External Resource Retrieval]: The skill pulls Docker images from the azurecr.io registry and defines dependencies for packages like Prisma, SQLAlchemy, and TypeORM. These resources are standard industry tools and the registry belongs to the vendor's infrastructure.
  • [Input Sanitization]: A significant security positive is that the skill explicitly mandates the use of parameterized queries for all generated data access code. This is a critical defense-in-depth measure against SQL injection vulnerabilities.
  • [Credential Management]: The skill uses placeholder strings for passwords during the local setup phase and correctly guides the agent to use environment variables for application configuration, which is a recommended practice for secret management.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:32 AM