Scanned skills

microsoft/azure-skills microsoft-foundry

Checked the catalogued skill at microsoft-foundry.

SkillTrust corpus scan 22 September 2026 v0.10.0 via skillsh Verify on GitHub
F AI-triaged 227
D Security

D; retained sample includes a high finding · SD-007 · what this rule accepts as a false positive →

F Permissions

F; retained sample includes a high finding · SD-003 · what this rule accepts as a false positive →

B Transparency

B set by findings not listed in the stored summary

showing 10 of 227
securityhigh SD-007
finetuning/scripts/check_training.py
permission_hygienehigh SD-003
finetuning/scripts/deploy_model.py
permission_hygienehigh SD-003
finetuning/scripts/deploy_model.py
securityhigh SD-007
finetuning/scripts/deploy_model.py
securityhigh SD-007
finetuning/scripts/deploy_model.py
securityhigh SD-007
finetuning/scripts/deploy_model.py
securityhigh SD-007
finetuning/scripts/deploy_model.py
securityhigh SD-007
finetuning/scripts/deploy_model.py
securityhigh SD-007
finetuning/scripts/monitor_training.py
securityhigh SD-007
finetuning/scripts/monitor_training.py
11 suppressed by AI triage
securityhigh SD-007 benign_example
finetuning/scripts/calibrate_grader.py

The reference appears only in an example command, not in executable code that performs a network call.

securityhigh SD-007 benign_example
finetuning/scripts/common.py

The code only contains a static string reference to an Azure endpoint, not an executed network call.

securityhigh SD-007 benign_example
finetuning/scripts/common.py

The code only contains a static string reference to an Azure endpoint, not an executed network call.

securityhigh SD-007 benign_example
finetuning/scripts/common.py

The code only contains a static string reference to an Azure endpoint, not an executed network call.

securityhigh SD-007 benign_example
finetuning/scripts/common.py

The code only contains a static string reference to an Azure endpoint, not an executed network call.

permission_hygienehigh SD-003 benign_example
foundry-agent/agent-optimizer/agent-optimizer.md

Documentation text, no actual path traversal code present.

permission_hygienehigh SD-003 benign_example
foundry-agent/agent-optimizer/references/azd-setup.md

The reference is a relative link in documentation, not code execution.

permission_hygienehigh SD-003 benign_example
foundry-agent/create/references/local-run.md

The documentation contains no actual '../' or absolute system path usage; it is merely explanatory text.

permission_hygienehigh SD-003 benign_example
foundry-agent/create/references/tools/prompt-agent/tool-work-iq.md

The flagged line contains only a comment about boundary rules, with no actual path traversal patterns.

permission_hygienehigh SD-003 benign_example
foundry-agent/toolbox/references/tool-a2a.md

The reference to '../toolbox.md#supported-tool-types' is a harmless documentation link, not code that performs path traversal.

permission_hygienehigh SD-003 benign_example
foundry-agent/trace/references/search-traces.md

Comment only; no actual path traversal code present.