Back to skill

Security audit

azure

Security checks across malware telemetry and agentic risk

Overview

This Azure management skill is not malicious, but it asks for broad cloud-operation authority without clear safeguards before changing or deleting resources.

Review this before installing if you manage real Azure subscriptions. Use least-privilege Azure credentials, limit the subscription/resource group available to the agent, and require the agent to show an exact plan and get explicit approval before any create, modify, or delete operation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill's invocation and usage guidance is overly broad and lacks clear activation boundaries, allowing the agent to apply the skill to loosely related requests. Because the skill has read/exec/write capabilities and is framed for general Azure management, ambiguous triggering can lead to unintended execution of impactful cloud or local operations from ordinary user prompts.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill describes create, modify, query, and delete management operations but does not require an explicit warning or confirmation before destructive actions. In an Azure operations context, this can result in accidental deletion or alteration of cloud resources, service outages, data loss, or unexpected billing impacts if the agent acts on ambiguous or mistaken prompts.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.