azure-provision

Warn

Audited by Socket on Aug 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent for Azure provisioning, but its actual purpose is to bypass Conditional Access by harvesting first-party portal tokens and converting them into durable unattended service-principal access with RBAC and secret creation. Data stays mostly within Microsoft and a local vault, so this is not confirmed credential theft malware, but it is a high-risk privilege-escalation/identity-bootstrap skill with significant real-world impact.

Confidence: 87%Severity: 84%
Audit Metadata
Analyzed At
Aug 11, 2026, 05:07 PM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fazure-provision%2F@1cf5a821818f241deb6e844c171507a9cfaeed933c55fb0b135a5ae9078b1de1
Security Audit — socket — azure-provision