Skip to main content

azure-redteam-supplychain

Use this skill to assess Azure DevOps, CI/CD, and software-supply-chain security during a red team engagement. Finds workload identity federation (OIDC / federated credentials trusting GitHub Actions or Azure DevOps) with broad trust and Azure privilege, over-privileged pipeline service principals, deployment identities using static secrets instead of OIDC, container-registry admin users and risky ACR build tasks, Automation Accounts with privileged identities, and Logic App deployment automation. Trigger when assessing CI/CD security, GitHub Actions or Azure DevOps OIDC, workload identity federation, federated credentials, pipeline service principals, ACR tasks, automation runbooks, or deployment supply chain.

Jump to install

Source facts

Repository
Contoso-State/red-team-agent-orchestration
Last source activity
June 17, 2026 at 15:15
Detected SKILL.md language
English
Stars
6
Forks
1

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.