azure-provision
Warn
Audited by Socket on Aug 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill is internally coherent for Azure provisioning, but its actual purpose is to bypass Conditional Access by harvesting first-party portal tokens and converting them into durable unattended service-principal access with RBAC and secret creation. Data stays mostly within Microsoft and a local vault, so this is not confirmed credential theft malware, but it is a high-risk privilege-escalation/identity-bootstrap skill with significant real-world impact.
Confidence: 87%Severity: 84%
Audit Metadata