investigating-azure-incidents

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents standard Azure investigation procedures. All command examples (az CLI) and KQL queries are appropriate for the stated purpose of incident response and security auditing.\n- [SAFE]: No obfuscated code, hidden URLs, or malicious data exfiltration patterns were identified. The use of the metadata service URL (169.254.169.254) is correctly documented as a target for attacker exfiltration to be monitored.\n- [SAFE]: References to external security tools like MicroBurst and ROADtools are for educational context regarding attacker TTPs and do not involve unauthorized downloads or execution.\n- [SAFE]: The skill has an attack surface for indirect prompt injection as it processes untrusted log data (Azure Activity and Entra logs) and possesses resource management capabilities. However, these are handled as part of standard IR workflows.\n
  • Ingestion points: Azure Activity Log, Entra sign-in logs, and resource diagnostic logs processed via KQL and Azure CLI.\n
  • Boundary markers: None explicitly specified in the provided commands.\n
  • Capability inventory: Extensive Azure CLI capabilities for resource management and identity modification, including disk snapshots, role assignment deletion, and service principal credential rotation.\n
  • Sanitization: Instructions rely on responder review; no automated input sanitization is scripted within the skill markdown.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:46 PM
Security Audit — agent-trust-hub — investigating-azure-incidents