azure-quotas

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/check-quota.sh

The code is a legitimate Azure quota-reporting script with no clear malicious intent, but it contains a significant code-injection weakness in all-quotas mode. Azure JSON and the region argument are embedded directly into generated Python source. Use `python3` with JSON supplied via stdin or environment-safe mechanisms, and validate numeric quota values and region format before processing. The automatic quota-extension installation is expected behavior but should be reviewed under the deployment's trust policy.

Confidence: 96%Severity: 72%
Audit Metadata
Analyzed At
Sep 14, 2026, 04:38 PM
Package URL
pkg:socket/skills-sh/microsoft%2Fazure-skills%2Fazure-quotas%2F@42f212a0436e46112c419bf3f7e54b825c34a8b4d9b4ee561e344880900156f7
Security Audit — socket — azure-quotas