microsoft-build

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • Official CLI Integration: The skill uses npx to execute @microsoft/events-cli and @microsoft/learn-cli. These tools are maintained by the vendor to facilitate session catalog searching and documentation access. Using npx ensures the agent uses the latest versions of these utilities.
  • Project Stack Discovery: To provide tailored recommendations, the skill analyzes local project files such as package.json, requirements.txt, and .csproj. This data is used to identify relevant event sessions and documentation updates specifically for your current development environment.
  • Local Workspace Operations: The skill includes features to scaffold project starters and maintain a session journal in a local directory. These operations are part of the skill's utility for helping developers organize their event takeaways and implement new technologies.
  • Verified Data Sources: All session metadata and event announcements are retrieved from official vendor domains, including aka.ms, microsoft.com, and news.microsoft.com.
  • Indirect Content Consideration: The skill processes information from external catalogs and documentation pages. While this involves processing structured data from the web, the use of official vendor endpoints provides a reliable source of information.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 12:16 PM
Security Audit — agent-trust-hub — microsoft-build