Back to skill

Security audit

Storage Exposure Auditor

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Azure storage audit guide, but it tells users to grant broad write-capable Azure permissions for a read-only workflow.

Review carefully before installing or following this skill. Do not grant Storage Account Contributor for this workflow; use the narrowest read-only roles and scopes available, and redact account names, resource groups, network rules, tenant details, tokens, keys, and other sensitive identifiers before sharing exported data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:43
Finding

Excessive Subscription-Wide Azure RBAC Recommendation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43-50
Vulnerability Type: Least-privilege violation through excessive Azure RBAC guidance
Risk Level: High

Complete Code Snippet:

markdown
**Minimum required Azure RBAC role to run the CLI commands above (read-only):**
```json
{
  "role": "Storage Account Contributor",
  "scope": "Subscription",
  "note": "Use 'Reader' role at minimum for account-level config; 'Storage Blob Data Reader' to list containers"
}
text

### Technical Analysis

The Skill identifies `Storage Account Contributor` at subscription scope as the minimum role required for read-only Azure Storage inspection. This is inaccurate and violates least-privilege principles.

`Storage Account Contributor` is a management-plane role that can modify storage accounts; it is not limited to reading their configuration. Assigning it at subscription scope grants unnecessary management privileges over storage accounts throughout the subscription. The recommendation conflicts with both the Skill's `permissions: read-only` declaration and its own note that `Reader` can inspect account-level configuration.

The listed `az storage account list` and `az storage account show` operations generally require management-plane read access, for which `Reader` at the narrowest applicable scope is appropriate. Container enumeration may separately require data-plane access such as `Storage Blob Data Reader`, scoped only to the relevant storage account or container. Authentication should explicitly use Microsoft Entra ID rather than account-key fallback.

### Attack Path

1. A user follows the Skill's claim that `Storage Account Contributor` at subscription scope is the minimum prerequisite.
2. The user assigns that role to a person, service principal, managed identity, or automation identity performing the audit.
3. That identity obtains write-capable storage-management privileges across the subscript
...[truncated 959 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the claim that Storage Account Contributor is the minimum required role.
  2. Recommend the Azure Reader role for management-plane configuration inspection.
  3. Scope Reader to the specific resource group or storage account whenever possible, rather than the entire subscription.
  4. Where container enumeration requires data-plane access, assign Storage Blob Data Reader only to the relevant storage account or container.
  5. Separate management-plane and data-plane prerequisites so users do not infer that one broad contributor role is required.
  6. Require Microsoft Entra ID authentication for data-plane commands, for example by documenting --auth-mode login, to avoid implicit account-key authentication.
  7. Advise users to use a temporary audit identity or time-bound privileged-access workflow and remove assignments after the audit.
  8. Document the exact Azure operations needed and, where built-in roles remain broader than necessary, provide a reviewed custom read-only role containing only those operations.
  9. Add a warning that contributor roles must not be assigned for this read-only workflow.

A safer prerequisite would distinguish the roles as follows:

markdown
- Account configuration inspection: Azure `Reader`, scoped to the smallest applicable storage account or resource group.
- Container enumeration: `Storage Blob Data Reader`, scoped only to the storage account or container being assessed.
- Use Microsoft Entra ID authentication (`--auth-mode login`); do not provide or request storage account keys.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to export and share Azure storage inventory and network configuration data without warning that the JSON may reveal sensitive infrastructure metadata such as account names, resource groups, network rules, and private endpoint posture. Even without secrets, this information can aid reconnaissance, expose security gaps, or violate internal data-handling requirements if pasted into external tooling unredacted.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims to be read-only and instruction-only, but its stated 'minimum required' role includes 'Storage Account Contributor' at subscription scope, which grants write-capable privileges far beyond what is needed to gather the described data. This can cause users to overprovision access when following the skill, increasing the blast radius if the account, session, or operator makes a mistake.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.