azure-provision

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for Azure provisioning, but its actual purpose is to bypass Conditional Access by harvesting first-party portal tokens and converting them into durable unattended service-principal access with RBAC and secret creation. Data stays mostly within Microsoft and a local vault, so this is not confirmed credential theft malware, but it is a high-risk privilege-escalation/identity-bootstrap skill with significant real-world impact.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Aug 19, 2026, 03:24 PM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fazure-provision%2F@07cff95cfa9dccb9cbe346af1803f21157767b9347fe5e6dee9436715ff17c23
Security Audit — socket — azure-provision