azure-ai
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a documentation and configuration hub for Azure AI services. All resources, including SDK references and external links, point to official Microsoft domains and well-known package registries.
- [EXTERNAL_DOWNLOADS]: The skill references multiple official Microsoft Azure SDKs (e.g., @azure/identity, azure-ai-contentsafety, Azure.Search.Documents). These are standard dependencies for the described functionality and are sourced from trusted registries (NPM, PyPI, NuGet, Maven). According to the security protocol, these references are documented neutrally and do not escalate the verdict.
- [INDIRECT_PROMPT_INJECTION]: The skill defines tools that process external data, such as search index results and audio transcriptions, which creates an attack surface for indirect prompt injection. However, the skill explicitly includes comprehensive documentation on using Azure AI Content Safety to moderate and filter these inputs, demonstrating a security-first design for handling untrusted data.
- [CREDENTIALS_UNSAFE]: The documentation includes a dedicated file on authentication best practices that strictly warns against hardcoding keys and connection strings, instead promoting the use of Environment-aware credentials and Managed Identities.
Audit Metadata