Versioned security assessment

Report ID: SA-1200D2F8

7/8/2026, 5:18:03 AM

deploy-model security assessment v4

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
deploy-model
Version
v4
Maintainer
microsoft
Coverage
17 Files scanned · 2,763 Lines analyzed
Policy version
Unavailable

Highest confirmed finding severity

Critical

1 confirmed security finding requires attention.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

The static findings are largely false positives from Markdown code fences, relative documentation links, official Azure endpoints, and expected Azure CLI helper scripts. No prompt-injection attempt was found; the jailbreak keyword hit is an Azure Prompt Shield policy reference. A critical semantic issue remains in capacity/scripts/discover_and_rank.sh because it constructs inline Python from unescaped shell variables.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

17 Files scanned · 2,763 Lines analyzed

1 item shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Observed in 26 evidence locations

Filesystem access

May read or write local files.

Observed in 38 evidence locations

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Observed in 176 evidence locations

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (1)

RISK-001 Critical
Unsanitized Inline Python Construction
capacity/scripts/discover_and_rank.sh builds a python3 -c program with shell variables and JSON interpolated directly into Python source. A crafted model, version, or minimum capacity argument could break out of string literals and run local Python code when the helper script is executed.
Lines 54-60 embed CAPACITY_JSON, PROJECTS_JSON, QUOTA_JSON, and MIN_CAPACITY into Python source without escaping. Line 104 also embeds model and version values into an f-string expression, so user-controlled arguments can alter code structure.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    Critical
    Unsanitized inline Python in capacity discovery helper
    Replace python3 -c interpolation with a script or heredoc that reads JSON from stdin and arguments from sys.argv. Validate MIN_CAPACITY as an integer before use.
  2. FIX-002
    High
    Insufficient helper script input validation
    Validate model names, versions, regions, SKUs, and capacity values with strict allowlists before passing them to Azure CLI, jq, or Python.
  3. FIX-003
    Medium
    Predictable temporary file path in workflow examples
    Use mktemp or a scoped temporary directory for capacity JSON examples, then delete the file after processing.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable