dotnet-ado-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides documentation and structural patterns for Azure DevOps YAML pipelines without including any malicious scripts, remote downloads, or hardcoded credentials.
- [INDIRECT_PROMPT_INJECTION]: The provided YAML templates accept parameters such as buildConfiguration and projects which are interpolated into command-line arguments for the DotNetCoreCLI@2 task. This creates a potential surface for argument injection if the input values are sourced from untrusted external data without prior sanitization. * Ingestion points: Template parameters defined in YAML examples within SKILL.md (e.g., buildConfiguration, projects, dotnetVersion). * Boundary markers: None present in the example YAML snippets. * Capability inventory: DotNetCoreCLI@2 task execution (restore, build, test, publish) and script tasks used in SKILL.md examples. * Sanitization: Not demonstrated in the provided pipeline patterns.
Audit Metadata