azure-cost
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill's metadata identifies the author as 'Microsoft', whereas the provided context states it was authored by 'midudev'. This discrepancy could be misleading regarding the skill's origin and official status.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from several external sources, which represents an attack surface for indirect prompt injection.
- Ingestion points: Data enters the context from the Azure Cost Management API (documented in cost-query/workflow.md and cost-forecast/workflow.md), Azure Monitor metrics (cost-optimization/workflow.md), and external Azure pricing web pages fetched via fetch_webpage (cost-optimization/workflow.md).
- Boundary markers: The workflows do not explicitly include delimiters or instructions to ignore embedded commands in the retrieved data.
- Capability inventory: The skill can execute various CLI commands including 'az rest', 'az monitor', 'az resource', 'az graph', 'az aks', and 'kubectl' across multiple files, and includes file-writing capabilities via 'create_file' (report-template.md).
- Sanitization: No explicit sanitization or validation of the retrieved data is mentioned before it is processed by the agent.
Audit Metadata