NYC

azure-expert

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/resource_status.py

No explicit backdoor, exfiltration code, or obfuscated malicious payload found in this file. The dominant security issue is command injection risk due to subprocess.run(..., shell=True) with unsanitized, user-controlled string interpolation of az CLI arguments. Additionally, the script may leak sensitive Azure metadata to stdout/logs. Treat this as a moderate security risk: safe if used only by trusted operators in a controlled environment, dangerous if used with untrusted input or in automated systems. Remediate by using subprocess argument lists, input validation/whitelisting, and redacting sensitive output.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:33 PM
Package URL
pkg:socket/skills-sh/questfortech-investments%2Fclaude-code-skills%2Fazure-expert%2F@83dd86334f531ebb0eb406bc5c2951eee9f05c2f