az-cost-optimize

Warn

Audited by Socket on Feb 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This skill/workflow is consistent with its stated purpose (discover Azure resources and IaC, analyze usage and costs, produce evidence-based recommendations, and create GitHub issues). I found no obfuscated code, credential-harvesting redirects, download-execute chains, or explicit malicious logic. Primary risks are operational: it requires broad Azure and GitHub credentials and produces executable Azure CLI commands that can modify resources. Another trust boundary is the unspecified MCP servers (azmcp-*), which could route data through third-party control planes — this should be verified and limited. Recommend: grant least privilege credentials, require explicit user/operator approval before any modifying az commands are executed, and validate MCP server trust and operators before use.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:27 AM
Package URL
pkg:socket/skills-sh/github%2Fawesome-copilot%2Faz-cost-optimize%2F@75941e175066d21b970698c2f3e00de19f5c1c91