azure-kusto-irql
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- Command Execution for Desktop Integration: The skill provides instructions for automating the opening of queries in Kusto Explorer on Windows. This involves writing a temporary file and using
Start-Processin PowerShell. This integration is a convenience feature for security analysts and requires explicit user confirmation via theask_usertool before any file system or process operations are performed. The implementation documentation specifically warns against using insecure PowerShell string handling to prevent potential command injection from malformed queries. The automation is specifically targeted at the legitimateKusto.Explorer.exebinary within the user's local application data folder.
Audit Metadata