azure-deploy
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and executes an official installation script for the Azure Developer CLI.
- Evidence: In
references/sdk/azd-deployment.md, the skill provides the commandcurl -fsSL https://aka.ms/install-azd.sh | bashto install theazdtool. This URL belongs to a trusted organization (Microsoft). - Evidence: Migration scripts and SDK references pull dependencies from official registries, including NPM for
@azure/identityand PyPI forazure-identity. - [COMMAND_EXECUTION]: The skill is primarily focused on executing system-level commands to manage Azure infrastructure.
- Evidence: The
SKILL.mdand various recipe files (e.g.,references/recipes/azd/README.md) execute powerful CLI tools includingazd up,terraform apply, andaz deployment sub create. - Evidence: The skill incorporates strict rules for destructive commands, requiring
ask_userconfirmation before running operations likeaz group deleteorazd downas defined inreferences/global-rules.md. - [DYNAMIC_EXECUTION]: The skill generates and executes scripts at runtime to handle post-deployment tasks like database migrations.
- Evidence: In
references/recipes/azd/ef-migrations.md, the agent is instructed to write shell and PowerShell scripts (apply-migrations.sh,apply-migrations.ps1) verbatim to the user's project directory and then execute them usingbashorpwsh. - Evidence: These scripts dynamically load environment variables using
azd env get-valuesand construct SQL queries and connection strings fordotnet ef database updateandaz sql db queryoperations. - [INDIRECT_PROMPT_INJECTION]: The skill processes external, user-supplied configuration files and deployment plans which could potentially harbor malicious instructions.
- Ingestion points: The skill reads
.azure/deployment-plan.md,azure.yaml, and infrastructure templates in theinfra/directory. - Boundary markers: The
SKILL.mdrequires aValidation Proofsection in the deployment plan, created by a separate validation skill, to ensure the data has been verified before processing. - Capability inventory: The skill can execute arbitrary shell commands through deployment tools and scripts, and perform network operations via the Azure CLI and
curl. - Sanitization: Migration scripts implement a safe parsing loop for environment variables instead of using dangerous functions like
evalon raw output.
Audit Metadata