azure-attestation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation from official Microsoft domains (
learn.microsoft.com) and references a tool repository on GitHub (github.com/MicrosoftDocs/mcp). These are legitimate references for a documentation-focused skill produced by the vendor. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from external URLs to provide responses. This creates a surface where external content could influence agent behavior. However, the ingestion is limited to trusted documentation sites, and the skill does not possess capabilities (like file writing or command execution) that would make such an injection high-risk.
- [COMMAND_EXECUTION]: The skill instructions advise the agent to suggest the user install a tool (
mcp_microsoftdocs) if it is missing, rather than attempting to execute installation commands automatically.
Audit Metadata