Back to skill

Security audit

azure-infra-free

Security checks for vulnerabilities and agentic risk

Overview

This appears to be an Azure resource lookup helper, but it includes broader and conflicting capability claims that should be reviewed before installation.

Review this skill before installing. It is suitable only if you want an agent to run read-only Azure CLI queries against your logged-in Azure account. Avoid using it for generic Operations tasks, security audits, file processing, API integrations, or any write/change request unless the publisher narrows and clarifies the documentation and tool scope.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The skill repeatedly states the free edition excludes security auditing, but later claims it provides automated security audit capabilities. This contradiction can mislead users and agents into invoking the skill for security-sensitive assessments it is not designed to perform, creating false assurance and possible unsafe handling of privileged cloud data.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill is described as a read-only Azure CLI query tool, yet later sections advertise file read/write support, external API integration, and generic command execution. These contradictory claims materially expand the apparent attack surface and may cause an agent to grant or use capabilities beyond the intended least-privilege model.

Intent-Code Divergence

Medium
Confidence
85% confidence
Finding
The invocation criteria broaden from Azure-specific read-only queries to generic Operations-related activation. That inconsistency can trigger the skill outside its safe intended context, increasing the chance that an agent uses Azure CLI or related tools for unrelated tasks without proper user intent validation.

Vague Triggers

High
Confidence
95% confidence
Finding
A trigger that activates on broad 'Operations' tasks is overly permissive for a skill that has exec, read, and write tools in metadata. Over-broad activation can cause unintended invocation in unrelated workflows, exposing cloud context, local CLI state, or command execution paths where they are unnecessary.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Ambiguous invocation criteria make it unclear when the skill should run, which is risky in an agentic environment because the model may opportunistically select it for loosely related tasks. In this skill, that ambiguity is more dangerous because the documented behavior involves local command execution against authenticated Azure contexts.

Static analysis

No suspicious patterns detected.