azure-deploy

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and executes an official installation script for the Azure Developer CLI.
  • Evidence: In references/sdk/azd-deployment.md, the skill provides the command curl -fsSL https://aka.ms/install-azd.sh | bash to install the azd tool. This URL belongs to a trusted organization (Microsoft).
  • Evidence: Migration scripts and SDK references pull dependencies from official registries, including NPM for @azure/identity and PyPI for azure-identity.
  • [COMMAND_EXECUTION]: The skill is primarily focused on executing system-level commands to manage Azure infrastructure.
  • Evidence: The SKILL.md and various recipe files (e.g., references/recipes/azd/README.md) execute powerful CLI tools including azd up, terraform apply, and az deployment sub create.
  • Evidence: The skill incorporates strict rules for destructive commands, requiring ask_user confirmation before running operations like az group delete or azd down as defined in references/global-rules.md.
  • [DYNAMIC_EXECUTION]: The skill generates and executes scripts at runtime to handle post-deployment tasks like database migrations.
  • Evidence: In references/recipes/azd/ef-migrations.md, the agent is instructed to write shell and PowerShell scripts (apply-migrations.sh, apply-migrations.ps1) verbatim to the user's project directory and then execute them using bash or pwsh.
  • Evidence: These scripts dynamically load environment variables using azd env get-values and construct SQL queries and connection strings for dotnet ef database update and az sql db query operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, user-supplied configuration files and deployment plans which could potentially harbor malicious instructions.
  • Ingestion points: The skill reads .azure/deployment-plan.md, azure.yaml, and infrastructure templates in the infra/ directory.
  • Boundary markers: The SKILL.md requires a Validation Proof section in the deployment plan, created by a separate validation skill, to ensure the data has been verified before processing.
  • Capability inventory: The skill can execute arbitrary shell commands through deployment tools and scripts, and perform network operations via the Azure CLI and curl.
  • Sanitization: Migration scripts implement a safe parsing loop for environment variables instead of using dangerous functions like eval on raw output.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — azure-deploy