detect-entra-credential-addition
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements detection logic to identify 'Add service principal credentials' and 'Create federated identity credential' operations within Microsoft Entra audit logs.
- [SAFE]: No network operations, file system modifications (outside of specified output), or subprocess executions were found in the source code.
- [SAFE]: The skill correctly handles data normalization and deduplication of security events without any use of dynamic code execution or obfuscation techniques.
- [SAFE]: External references and metadata are consistent with the skill's stated purpose and point to reputable sources like MITRE and Microsoft documentation.
Audit Metadata