azure-compliance
Pass
Audited by Gen Agent Trust Hub on May 14, 2026
Risk Level: SAFE
Full Analysis
- Command Execution: The skill documentation includes numerous Azure CLI and Bicep snippets used for auditing and remediating compliance issues. These patterns are standard for cloud administration and are provided as reference material for the agent to generate valid management commands or as instructions for the user to follow.
- Indirect Prompt Injection Surface: The skill processes metadata from Azure resources, such as resource names and scan result artifacts from the
azqrtool. While processing external data is a common surface for indirect prompt injection, the skill is designed for administrative reporting, and the risks are typical for auditing tools interacting with external environment data. - Trusted External References: The reference files contain links to official Microsoft documentation and GitHub repositories. These are used to provide the agent and the user with authoritative guidance on Azure best practices and SDK usage, supporting the skill's intended function safely.
Audit Metadata