Skip to main content

azure-redteam-external-vuln

Use this skill for AUTHORIZED active external testing of internet-facing web apps and endpoints discovered in an Azure subscription, during a red team engagement. Covers OWASP Top 10 validation from the outside — missing security headers, weak TLS, insecure cookies, permissive CORS, risky HTTP methods, sensitive-path exposure, reflected/DOM XSS, SQL/NoSQL injection, SSRF (incl. Azure IMDS), broken access control / IDOR — plus optional OFFLINE static analysis (Semgrep) of code pulled from Azure. Strictly scope-locked: only targets hosts derived from in-scope Azure resources (public IPs, App Service, Static Web Apps, Storage $web, Front Door/CDN, API Management, container apps). Hard-gated to mode external-active-testing with a signed external_testing authorization; off by default. Trigger only when active external testing is explicitly authorized.

跳到安装

来源信息

仓库
Contoso-State/red-team-agent-orchestration
最近来源活动
2026年6月17日 15:15
检测到的 SKILL.md 语言
英语
星标
6
分支
1

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。