Back to skill

Security audit

Agent Framework Azure Ai Py

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Azure agent development skill, but it promotes some high-impact remote tool and install patterns without enough safety boundaries.

Install and use this only in an isolated, nonprivileged Python environment, pin reviewed package versions, and treat Azure project credentials, MCP tokens, uploaded files, prompts, and thread IDs as sensitive. Before using MCP examples, require approvals or allowlist specific read-only tools, especially for private, authenticated, GitHub, or company API endpoints. Avoid sending secrets, regulated data, or confidential documents to hosted tools unless your Azure and third-party data-handling requirements are satisfied.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Prerelease Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24-28
Vulnerability Type: Unpinned prerelease package installation
Risk Level: Medium

Vulnerable Code:

bash
# Full framework (recommended)
pip install agent-framework --pre

# Or Azure-specific package only
pip install agent-framework-azure-ai --pre

Technical Analysis

The installation instructions retrieve mutable prerelease packages without pinning an exact version or validating package hashes. Consequently, the installed code and its transitive dependency graph can change after this Skill has been reviewed.

The --pre option also permits prerelease versions, which generally receive less stability and compatibility assurance than production releases. If the package publisher, package registry, release process, or a transitive dependency were compromised, following these commands could install attacker-controlled code. Python packages may execute code during installation or later when imported.

This is a supply-chain weakness rather than evidence that the named packages are currently malicious.

Attack Path

  1. An attacker compromises a relevant package publisher, release pipeline, registry entry, or unpinned transitive dependency.
  2. The attacker publishes a malicious or backdoored prerelease version that satisfies pip's unconstrained resolution.
  3. A user follows the documented pip install ... --pre command.
  4. Pip resolves and downloads the compromised release because no reviewed version or hash is required.
  5. Malicious package code executes during installation or when the package is imported and used.

Impact Assessment

Exploitation could execute arbitrary Python or native package code with the privileges of the account running pip. Depending on those privileges and the environment, this may expose local files, environment variables, Azure credentials, source code, or application secrets. It may also modify the a ...[truncated 295 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin each direct dependency to an exact, reviewed version, for example:
    bash
    pip install agent-framework==<reviewed-version>
    pip install agent-framework-azure-ai==<reviewed-version>
    
  2. Remove --pre unless a specific prerelease is operationally required. If required, pin that exact prerelease.
  3. Generate and commit a lock file that includes transitive dependencies.
  4. Require package hashes during installation, such as through a hash-locked requirements file and pip install --require-hashes.
  5. Explicitly configure the trusted package index and prevent unintended fallback to untrusted or internal indexes.
  6. Scan locked packages for known vulnerabilities and review dependency changes before updating.
  7. Install dependencies in an isolated, nonprivileged virtual environment rather than as an administrator.

T09 · Insecure Skill Coding Practices

Warning
Location
references/mcp.md:24
Finding

Hosted MCP Tools Are Automatically Approved Without a Restrictive Tool Allowlist

Content
View full analysis

Vulnerability Details

File Location: references/mcp.md, lines 24-31
Vulnerability Type: Unrestricted automatic execution of remotely advertised MCP tools
Risk Level: Medium

Vulnerable Code:

python
agent = await provider.create_agent(
    name="DocsAgent",
    instructions="Answer questions using Microsoft documentation.",
    tools=HostedMCPTool(
        name="Microsoft Learn MCP",
        url="https://learn.microsoft.com/api/mcp",
        approval_mode="never_require",  # Don't ask for approval
    ),
)

Technical Analysis

The basic MCP example configures approval_mode="never_require" but does not specify allowed_tools. The agent may therefore invoke any capability advertised by the remote MCP endpoint without obtaining user approval.

MCP tool definitions and metadata are supplied remotely and may change independently of the reviewed Skill. If the endpoint, its deployment pipeline, DNS or network path, or its configuration is compromised, new or altered tools could become available to the agent. Prompt injection in user input or remote content could then influence the model to select one of those capabilities.

Later sections demonstrate allowlists and more restrictive approval modes, but the primary example establishes an insecure default that readers may copy directly.

Attack Path

  1. An attacker compromises or gains influence over the configured MCP endpoint, its deployment process, or a trusted data source that can inject instructions into the agent context.
  2. The endpoint advertises a harmful or deceptively described tool, or changes the behavior of an existing tool.
  3. The agent receives a user prompt or untrusted remote content that causes it to select that tool.
  4. Because no allowed_tools restriction is configured, the tool remains available to the model.
  5. Because approval_mode is never_require, execution proceeds without a user confirmation boundary ...[truncated 841 chars]
Remediation
View remediation

Remediation Suggestions

  1. Use approval_mode="always_require" as the default for remotely managed capabilities.
  2. Define a minimal allowed_tools list containing only reviewed operations:
    python
    tools=HostedMCPTool(
        name="Microsoft Learn MCP",
        url="https://learn.microsoft.com/api/mcp",
        approval_mode="always_require",
        allowed_tools=[
            "microsoft_docs_search",
            "microsoft_docs_read",
        ],
    )
    
  3. If automatic approval is operationally necessary, permit it only for explicitly enumerated, read-only tools. Require approval for all state-changing operations.
  4. Validate endpoint ownership, enforce HTTPS certificate verification, and monitor unexpected changes to advertised MCP tools.
  5. Apply least-privilege credentials to the MCP server and its downstream services.
  6. Treat MCP responses as untrusted input and add defenses against prompt injection from remote content.
  7. Update repeated examples, including the acceptance-criteria example, so secure approval and allowlist behavior is presented as the default.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill teaches use of persistent Azure-hosted agents and conversation threads but does not warn that prompts, thread contents, files, and tool inputs may be transmitted to and stored by Azure services. This can lead users to send sensitive or regulated data under the false assumption the workflow is purely local or ephemeral, increasing privacy, compliance, and data-governance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The hosted tool and MCP examples encourage web search and remote MCP usage without warning that user prompts, retrieved content, credentials, or contextual data may be sent to third-party or external services. This omission can cause unintentional disclosure of confidential data through Bing/web search, remote MCP endpoints, or other hosted integrations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example demonstrates placing a bearer token directly in source code headers, which normalizes insecure secret handling and can lead users to hard-code real credentials into repositories, logs, or shared examples. In a developer reference for building Azure AI agents, this is especially risky because readers may copy the snippet into production integrations with minimal changes.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/advanced.md (reported line 182)May include surrounding context.

md
openapi_tool = OpenAPITool(
    name="SecureAPI",
    spec="https://api.example.com/openapi.json",
    base_url="https://api.example.com",
    headers={
        "Authorization": "Bearer your-api-key",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The debug snippet prints raw tool-call arguments, which may contain secrets, personal data, prompts, file identifiers, or API parameters, causing accidental disclosure in console output and log pipelines. Because this skill covers hosted tools, MCP, file handling, and agent interactions, tool arguments are more likely than usual to carry sensitive operational data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly demonstrates approval_mode="never_require" for an MCP tool, which can normalize automatic execution of external tool actions without user confirmation. In an agent framework skill focused on persistent agents and tool integration, this is risky because readers may copy the example into production and enable unintended external reads, writes, or side effects through MCP tools.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/mcp.md (reported line 153)May include surrounding context.

md
async with (
    MCPStreamableHTTPTool(
        name="GitHub MCP",
        url="https://api.github.com/mcp",
        http_client=http_client,
    ) as github_mcp,
    AzureAIAgentsProvider(credential=credential) as provider,

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/mcp.md (reported line 176)May include surrounding context.

md
async with (
    MCPStreamableHTTPTool(
        name="GitHub MCP",
        url="https://api.github.com/mcp",
        http_client=http_client,
    ) as github_mcp,
    AzureAIAgentsProvider(credential=credential) as provider,

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The example shows an inline Authorization bearer token in headers without any accompanying guidance on secret handling. Although the token is a placeholder, this pattern encourages embedding credentials directly in code or documentation-driven copy/paste, which can lead to secret leakage in source control, logs, or shared snippets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation demonstrates persisting conversation identifiers to a local JSON file without warning that these identifiers may be sensitive and can enable unauthorized conversation resumption if exposed. In an agent framework focused on persistent threads and resumable conversations, readers may copy this pattern directly into production, increasing the chance of insecure storage or leakage through logs, shared disks, or source control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The web search examples show how to send user prompts to Bing-backed hosted search without disclosing that user queries may be transmitted to an external search provider. In an agent framework context, developers often copy examples directly, so omission of a privacy notice or consent guidance can lead to unintentional disclosure of sensitive prompts, internal data, or user information to third-party services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.