Back to skill

Security audit

azure-agent-framework-tool-free

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-style Azure Agent Framework skill with purpose-aligned setup and Azure guidance, though users should approve any environment or cloud changes explicitly.

Install only if you want Azure AI Foundry / Microsoft Agent Framework development guidance. Before letting an agent follow the examples, approve package installs, Azure CLI login, environment-variable changes, and any creation of cloud agents or hosted tools that may use Azure resources or credentials.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger condition is written so broadly ('需要AI模型调用、智能对话、Agent编排、LLM应用时使用') that an agent could invoke this skill for a very wide range of requests, including cases where its exec/write-enabled guidance is unnecessary or risky. In the context of a skill that advertises command execution and file writing, ambiguous invocation criteria increase the chance of unintended use and unsafe action selection.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill declares read/exec/write capabilities and includes installation, authentication, and command-line workflow guidance, but it does not prominently warn users that using the skill may execute commands, modify files, or affect the local environment and cloud resources. This is dangerous because an agent may operationalize the documentation and perform system-impacting actions without explicit informed consent or safety gating.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.