azure-devops-workflow

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes az boards (Azure CLI) and @skapxd/azure-devops-agent (via npx/pnpx) to interact with the Azure DevOps API. These commands are used for standard developer tasks such as querying, creating, and updating work items.
  • [EXTERNAL_DOWNLOADS]: The skill uses npx and pnpx to run the @skapxd/azure-devops-agent utility. This utility is authored by the same vendor as the skill ('skapxd') and provides specialized functionality for Azure DevOps integration that the standard CLI lacks, such as listing unlinked branches and creating items with parent associations.
  • [CREDENTIALS_SAFE]: The skill explicitly instructs the agent never to print, guess, or create the Personal Access Token (PAT). It correctly identifies that the token should be read from the environment variable AZURE_DEVOPS_EXT_PAT or standard shell profile files, following secure practices for developer tools.
  • [SAFE]: All functionality described is consistent with its stated purpose of improving Azure DevOps traceability. It includes checks to ensure the repository is actually hosted on Azure DevOps before attempting operations and emphasizes user confirmation before making visible changes.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 12:55 PM
Security Audit — agent-trust-hub — azure-devops-workflow