Skip to main content

azure-redteam-supplychain

Use this skill to assess Azure DevOps, CI/CD, and software-supply-chain security during a red team engagement. Finds workload identity federation (OIDC / federated credentials trusting GitHub Actions or Azure DevOps) with broad trust and Azure privilege, over-privileged pipeline service principals, deployment identities using static secrets instead of OIDC, container-registry admin users and risky ACR build tasks, Automation Accounts with privileged identities, and Logic App deployment automation. Trigger when assessing CI/CD security, GitHub Actions or Azure DevOps OIDC, workload identity federation, federated credentials, pipeline service principals, ACR tasks, automation runbooks, or deployment supply chain.

跳到安装

来源信息

仓库
Contoso-State/red-team-agent-orchestration
最近来源活动
2026年6月17日 15:15
检测到的 SKILL.md 语言
英语
星标
6
分支
1

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。