Audit History
azure-observability - 4 audits
Version comparison
Capability and finding changes across audited versions, newest first.
| Version | Date | Result | Review items | Change vs previous |
|---|---|---|---|---|
| v4 Latest | Jul 6, 2026, 05:53 PM | No confirmed findings | 0 | No capability change |
| v3 | Jul 6, 2026, 05:53 PM | No confirmed findings | 0 | No capability change |
| v2 | Jun 30, 2026, 07:25 AM | 1 confirmed | 0 | External commandsNetwork accessEnv variables |
| v1 | Feb 20, 2026, 08:51 AM | No confirmed findings | 0 | Baseline |
Jul 6, 2026, 05:53 PM
The static alerts are false positives caused by Markdown code formatting, read-oriented Azure documentation examples, and normal Azure Monitor SDK configuration. No prompt injection, covert exfiltration intent, destructive command guidance, or automatic network behavior was found in the reviewed files.
Risk Factors
🔑 Env variables (2)
⚙️ External commands (15)
🌐 Network access (2)
Jul 6, 2026, 05:53 PM
The static alerts are false positives caused by Markdown code formatting, read-oriented Azure documentation examples, and normal Azure Monitor SDK configuration. No prompt injection, covert exfiltration intent, destructive command guidance, or automatic network behavior was found in the reviewed files.
Risk Factors
🔑 Env variables (2)
⚙️ External commands (15)
🌐 Network access (2)
Jun 30, 2026, 07:25 AM
Static analysis flagged many command, network, environment, and weak-crypto patterns, but review found documentation examples rather than executable skill code. The only residual risks are that users may run Azure CLI or SDK examples against live resources and should protect connection strings. No evidence found of prompt injection, credential exfiltration, obfuscation, or confirmed malicious intent.
Confirmed security concerns (1)
Static false positives ignored (4)
These static matches were dismissed by semantic review or matched schema-only tokens, so they are shown for transparency but do not drive the quality score.
Risk Factors
⚙️ External commands (36)
🌐 Network access (3)
🔑 Env variables (1)
Feb 20, 2026, 08:51 AM
This is an official Microsoft documentation skill containing only markdown reference files. All 57 static findings are false positives: backtick commands are CLI examples in documentation, URLs point to Microsoft Learn documentation, and environment variable patterns are standard configuration. No malicious behavior detected.