hosted-agents-v2-py
Pass
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches and installs the official
azure-ai-projectsandazure-identityPython packages from the standard public registry.\n- [PROMPT_INJECTION]: Indirect Prompt Injection Surface Analysis (Category 8):\n - Ingestion points: Agents created using this skill retrieve container images from Azure Container Registry and ingest data through
file_searchandmcptools (SKILL.md).\n - Boundary markers: The provided templates do not specify delimiters or explicit instructions for the agent to ignore commands within retrieved content.\n
- Capability inventory: The hosted agents are configured with
code_interpreterandfile_searchcapabilities, which process data at runtime (SKILL.md).\n - Sanitization: The documentation does not implement specific sanitization or validation logic for data ingested by the agent tools.
Audit Metadata