foundry-rbac-audit
Probes Azure RBAC role assignments at a resource-group scope for privilege-escalation risks (Owner, User Access Administrator, RBAC Administrator). Returns a spec §4.3.1 sibling-skill dict with finding_id "IAM-101", observations, remediation hints, confidence, and never raises. USE FOR: threadlight IAM-101 sibling-skill flip, rbac audit on a Foundry-adjacent resource group, least privilege review before spoke onboarding, over-privileged detection after team offboarding, role assignment audit for spoke security probe, scheduled CI security check on a Foundry project RG. DO NOT USE FOR: granting or revoking roles — use az role assignment create/delete instead; DO NOT USE FOR: Foundry-internal agent identity or per-agent-instance MI RBAC — use foundry-agt; DO NOT USE FOR: hub-side Citadel security checks — use citadel-spoke-onboarding probe_hub_contract.
Datos de origen
- Repositorio
- aiappsgbb/awesome-gbb
- Última actividad en el origen
- 25 de septiembre de 2026 a las 14:00
- Idioma detectado de SKILL.md
- inglés
- Estrellas
- 6
- Forks
- 3
Opciones de instalación
De forma predeterminada está seleccionado el prompt que primero revisa el origen. Puedes cambiar a un comando directo o descargar una copia local.
Revisa los archivos de origen
Lee SKILL.md y los archivos complementarios que muestra SkillsMP antes de decidir si quieres instalarlo.
Mostrando SKILL.md
- name
- foundry-rbac-audit
- description
- Probes Azure RBAC role assignments at a resource-group scope for privilege-escalation risks (Owner, User Access Administrator, RBAC Administrator). Returns a spec §4.3.1 sibling-skill dict with finding_id "IAM-101", observations, remediation hints, confidence, and never raises. USE FOR: threadlight IAM-101 sibling-skill flip, rbac audit on a Foundry-adjacent resource group, least privilege review before spoke onboarding, over-privileged detection after team offboarding, role assignment audit for spoke security probe, scheduled CI security check on a Foundry project RG. DO NOT USE FOR: granting or revoking roles — use az role assignment create/delete instead; DO NOT USE FOR: Foundry-internal agent identity or per-agent-instance MI RBAC — use foundry-agt; DO NOT USE FOR: hub-side Citadel security checks — use citadel-spoke-onboarding probe_hub_contract.
- metadata
- {"version":"1.0.2"}