azure-devops
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The instructions in
SKILL.mdandREADME.mdrecommend updating the Git remote URL to include the authentication token (git remote set-url origin https://${AZURE_DEVOPS_TOKEN}@dev.azure.com/...). This practice causes the Personal Access Token (PAT) to be stored in plaintext within the.git/configfile in the local workspace, which can lead to credential exposure if the directory is accessed by unauthorized users or included in backups. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external Azure DevOps repositories and APIs.
- Ingestion points: Data enters the agent's context through
curlAPI responses andgitoperations performed inSKILL.mdandREADME.md. - Boundary markers: The skill does not implement boundary markers or specific instructions to ignore malicious content embedded in pull request descriptions or repository files.
- Capability inventory: The skill possesses capabilities for filesystem operations,
gitrepository management (branching, pushing), and network communication viacurlandInvoke-RestMethod. - Sanitization: There is no evidence of sanitization, validation, or filtering of the content retrieved from the remote Azure DevOps resources before it is processed.
Audit Metadata