azure-devops

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The instructions in SKILL.md and README.md recommend updating the Git remote URL to include the authentication token (git remote set-url origin https://${AZURE_DEVOPS_TOKEN}@dev.azure.com/...). This practice causes the Personal Access Token (PAT) to be stored in plaintext within the .git/config file in the local workspace, which can lead to credential exposure if the directory is accessed by unauthorized users or included in backups.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external Azure DevOps repositories and APIs.
  • Ingestion points: Data enters the agent's context through curl API responses and git operations performed in SKILL.md and README.md.
  • Boundary markers: The skill does not implement boundary markers or specific instructions to ignore malicious content embedded in pull request descriptions or repository files.
  • Capability inventory: The skill possesses capabilities for filesystem operations, git repository management (branching, pushing), and network communication via curl and Invoke-RestMethod.
  • Sanitization: There is no evidence of sanitization, validation, or filtering of the content retrieved from the remote Azure DevOps resources before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:36 PM
Security Audit — agent-trust-hub — azure-devops