azure-pipelines

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the fragment is coherent with its stated purpose of local Azure DevOps pipeline validation tooling. The primary security concern is the curl|bash installation pattern to install Azure CLI, which is a known risky pattern if the source cannot be trusted or if the installer can be tampered with. Otherwise, the flow aligns with legitimate developer workflows (auth, extension installation, and API-based pipeline operations). The content does not show hardcoded secrets, unintended data exfiltration, or autonomous actions. Recommend caution with the installer source integrity (verify the Microsoft-hosted URL, consider pinning or validating checksums) and ensure the azure-pipelines script is used in trusted environments with proper access controls.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 11:08 AM
Package URL
pkg:socket/skills-sh/microsoft%2Fvscode%2Fazure-pipelines%2F@4936955ccce5c6e728e7b01c612e940c986a789a