dotnet-ado-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides documentation and structural patterns for Azure DevOps YAML pipelines without including any malicious scripts, remote downloads, or hardcoded credentials.
  • [INDIRECT_PROMPT_INJECTION]: The provided YAML templates accept parameters such as buildConfiguration and projects which are interpolated into command-line arguments for the DotNetCoreCLI@2 task. This creates a potential surface for argument injection if the input values are sourced from untrusted external data without prior sanitization. * Ingestion points: Template parameters defined in YAML examples within SKILL.md (e.g., buildConfiguration, projects, dotnetVersion). * Boundary markers: None present in the example YAML snippets. * Capability inventory: DotNetCoreCLI@2 task execution (restore, build, test, publish) and script tasks used in SKILL.md examples. * Sanitization: Not demonstrated in the provided pipeline patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 07:31 AM
Security Audit — agent-trust-hub — dotnet-ado-patterns