azure-ad-sso

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This is a legitimate, well-aligned Azure AD SSO integration guide for Kubernetes-hosted applications. I found no signs of malicious code, obfuscation, or exfiltration to attacker-controlled endpoints. The primary security issues are poor operational hygiene in examples: echoing client secrets to stdout (which can be captured in shell history/logs), suggesting pasting tokens into a third-party site (jwt.io), and sample diagnostic commands that could reveal secrets if run inappropriately. Additionally, the Environment Reference includes explicit UUIDs and Key Vault names which may be sensitive if real. Recommend removing/avoiding echoing secrets, warning against pasting tokens to external services, and redacting any real tenant/identity identifiers in public documentation.

Confidence: 80%Severity: 35%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:59 PM
Package URL
pkg:socket/skills-sh/julianobarbosa%2Fclaude-code-skills%2Fazure-ad-sso%2F@1bc6015bf5a1617613ce3088857ad4eece7a316d