microsoft-code-reference

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for the agent to retrieve content from Microsoft's public documentation services, which creates a potential surface for indirect prompt injection. \n
  • Ingestion points: Documentation fetch and search tools (microsoft_docs_fetch, microsoft_docs_search, microsoft_code_sample_search) retrieve data from external Microsoft resources into the agent's context. \n
  • Boundary markers: Absent. The instructions do not define the use of delimiters or boundary markers to isolate the external content. \n
  • Capability inventory: None. The skill's functionality is limited to information retrieval and does not include capabilities for file modification or code execution. \n
  • Sanitization: Absent. No sanitization or validation of the retrieved documentation is specified. \n- [NO_CODE]: The skill consists entirely of instructional documentation and does not include any scripts, binaries, or executable code components.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 08:37 PM