pentest-gemini-az

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill is internally coherent and uses official Microsoft tooling and endpoints, so there is no clear malware or credential-harvesting pattern. However, its footprint is very broad: it grants an AI agent general administrative power across Azure, Microsoft 365, Graph, and Entra using the current CLI session, including scope changes and destructive actions. This makes it a high-impact operator skill with meaningful security risk despite legitimate infrastructure.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Mar 27, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/crtvrffnrt%2Fskills%2Fpentest-gemini-az%2F@dd4aa1473294988ed6b9eb1bee6e4d0b8141e67f