Skip to main content

azure-redteam-external-vuln

Use this skill for AUTHORIZED active external testing of internet-facing web apps and endpoints discovered in an Azure subscription, during a red team engagement. Covers OWASP Top 10 validation from the outside — missing security headers, weak TLS, insecure cookies, permissive CORS, risky HTTP methods, sensitive-path exposure, reflected/DOM XSS, SQL/NoSQL injection, SSRF (incl. Azure IMDS), broken access control / IDOR — plus optional OFFLINE static analysis (Semgrep) of code pulled from Azure. Strictly scope-locked: only targets hosts derived from in-scope Azure resources (public IPs, App Service, Static Web Apps, Storage $web, Front Door/CDN, API Management, container apps). Hard-gated to mode external-active-testing with a signed external_testing authorization; off by default. Trigger only when active external testing is explicitly authorized.

インストールへ移動

ソース情報

リポジトリ
Contoso-State/red-team-agent-orchestration
ソースの最終更新活動
2026年6月17日 15:15
検出された SKILL.md の言語
英語
スター
6
フォーク
1

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。