Skip to main content

azure-redteam-external-vuln

Use this skill for AUTHORIZED active external testing of internet-facing web apps and endpoints discovered in an Azure subscription, during a red team engagement. Covers OWASP Top 10 validation from the outside — missing security headers, weak TLS, insecure cookies, permissive CORS, risky HTTP methods, sensitive-path exposure, reflected/DOM XSS, SQL/NoSQL injection, SSRF (incl. Azure IMDS), broken access control / IDOR — plus optional OFFLINE static analysis (Semgrep) of code pulled from Azure. Strictly scope-locked: only targets hosts derived from in-scope Azure resources (public IPs, App Service, Static Web Apps, Storage $web, Front Door/CDN, API Management, container apps). Hard-gated to mode external-active-testing with a signed external_testing authorization; off by default. Trigger only when active external testing is explicitly authorized.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
Contoso-State/red-team-agent-orchestration
آخر نشاط في المصدر
١٧ يونيو ٢٠٢٦ في ١٥:١٥
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٦
التفرعات
١

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.