azuresql-db-scaffold
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [Command Execution]: The skill instructs the agent to use
dockerandsqlcmdto manage database lifecycles and provision schemas. These operations are standard for development environment setup and are limited to containerized environments. - [External Resource Retrieval]: The skill pulls Docker images from the
azurecr.ioregistry and defines dependencies for packages like Prisma, SQLAlchemy, and TypeORM. These resources are standard industry tools and the registry belongs to the vendor's infrastructure. - [Input Sanitization]: A significant security positive is that the skill explicitly mandates the use of parameterized queries for all generated data access code. This is a critical defense-in-depth measure against SQL injection vulnerabilities.
- [Credential Management]: The skill uses placeholder strings for passwords during the local setup phase and correctly guides the agent to use environment variables for application configuration, which is a recommended practice for secret management.
Audit Metadata