foundry-rbac-audit
Probes Azure RBAC role assignments at a resource-group scope for privilege-escalation risks (Owner, User Access Administrator, RBAC Administrator). Returns a spec §4.3.1 sibling-skill dict with finding_id "IAM-101", observations, remediation hints, confidence, and never raises. USE FOR: threadlight IAM-101 sibling-skill flip, rbac audit on a Foundry-adjacent resource group, least privilege review before spoke onboarding, over-privileged detection after team offboarding, role assignment audit for spoke security probe, scheduled CI security check on a Foundry project RG. DO NOT USE FOR: granting or revoking roles — use az role assignment create/delete instead; DO NOT USE FOR: Foundry-internal agent identity or per-agent-instance MI RBAC — use foundry-agt; DO NOT USE FOR: hub-side Citadel security checks — use citadel-spoke-onboarding probe_hub_contract.
Informations de source
- Dépôt
- aiappsgbb/awesome-gbb
- Dernière activité de la source
- 25 septembre 2026 à 14:00
- Langue détectée de SKILL.md
- anglais
- Étoiles
- 6
- Forks
- 3
Options d'installation
Le prompt qui vérifie d'abord la source est sélectionné par défaut. Vous pouvez passer à une commande directe ou télécharger une copie locale.
Vérifiez les fichiers source
Lisez SKILL.md et les fichiers associés affichés par SkillsMP avant de décider de l'installer.
Affichage de SKILL.md
- name
- foundry-rbac-audit
- description
- Probes Azure RBAC role assignments at a resource-group scope for privilege-escalation risks (Owner, User Access Administrator, RBAC Administrator). Returns a spec §4.3.1 sibling-skill dict with finding_id "IAM-101", observations, remediation hints, confidence, and never raises. USE FOR: threadlight IAM-101 sibling-skill flip, rbac audit on a Foundry-adjacent resource group, least privilege review before spoke onboarding, over-privileged detection after team offboarding, role assignment audit for spoke security probe, scheduled CI security check on a Foundry project RG. DO NOT USE FOR: granting or revoking roles — use az role assignment create/delete instead; DO NOT USE FOR: Foundry-internal agent identity or per-agent-instance MI RBAC — use foundry-agt; DO NOT USE FOR: hub-side Citadel security checks — use citadel-spoke-onboarding probe_hub_contract.
- metadata
- {"version":"1.0.2"}