remediate-entra-credential-revoke

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes Microsoft Graph API calls to manage service principals, specifically to set 'accountEnabled' to false. This is the core functionality for incident response and is gated behind multiple environment variables.
  • [EXTERNAL_DOWNLOADS]: The skill depends on well-known, official SDKs including 'msgraph-sdk', 'azure-identity', and 'boto3' for AWS interaction. These are standard libraries from trusted vendors.
  • [DATA_EXFILTRATION]: Network egress is limited to 'graph.microsoft.com' for Entra management and 's3.amazonaws.com'/'dynamodb.amazonaws.com' for audit logging. These operations are transparently documented and match the stated purpose of the skill.
  • [SAFE]: The implementation follows security best practices for automated remediation: it defaults to dry-run mode, requires an incident ID and approver name to apply changes, and maintains an audit trail encrypted with KMS. It also includes a hardcoded deny-list to prevent accidental disabling of critical 'break-glass' or 'tenant-bootstrap' accounts.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:17 AM
Security Audit — agent-trust-hub — remediate-entra-credential-revoke