teams-app-developer

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFE
Full Analysis
  • Standard Developer Workflows: The skill utilizes official CLI tools such as atk, az (Azure CLI), and aws (AWS CLI) to facilitate project scaffolding, cloud resource provisioning, and application deployment. These operations are consistent with the skill's stated purpose as a development toolkit.- Secure Secrets Management: Dedicated experts (e.g., experts/security/secrets-ts.md) provide guidance on using environment variables, Azure Key Vault, and Managed Identity to avoid hardcoding credentials, aligning with industry security standards.- Input Validation Patterns: The skill includes detailed instructions on validating user inputs from messages and Adaptive Cards using schema validation libraries like zod to prevent injection and data corruption.- AI Implementation Guidance: Provides canonical patterns for integrating various AI model providers (OpenAI, Anthropic, Bedrock) using official SDKs and secure authentication methods.- Educational Code Samples: Contains various code snippets for building bot handlers and tools. A specific example using eval() for a calculation tool includes an explicit warning to use a safe parser in production environments, demonstrating a focus on developer education and safety.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 06:48 PM
Security Audit — agent-trust-hub — teams-app-developer