Agent skill

Detecting Misconfigured Azure Storage

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Audit Azure Storage accounts for public blob containers, missing encryption, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft…

Apache-2.0Auto-check: notesSecurity

Install Detecting Misconfigured Azure Storage

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-misconfigured-azure-storage -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills detecting-misconfigured-azure-storage --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/detecting-misconfigured-azure-storage .claude/skills/detecting-misconfigured-azure-storage && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
detecting-misconfigured-azure-storage
GitHub stars
34k
Token cost
~3.1k tokens
SKILL.md length
657 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit Azure Storage accounts for public blob containers, missing encryption, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft…

  • Works in 6 steps: Enumerate All Storage Accounts and Basic… → Detect Publicly Accessible Blob Containers → Audit Network Access and Firewall Rules → …
  • Storage security audits across subscriptions
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls az and curl; reaches account.blob.core.windows.net

What it does

Detecting Misconfigured Azure Storage is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Audit Azure Storage accounts for public blob containers, missing encryption, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage. Use for storage security audits across subscriptions, responding to Defender for Storage anonymous-access alerts, verifying compliance controls, or setting security baselines when onboarding a subscription.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Security review and Cryptography. It works with Microsoft Azure, Microsoft Defender and PowerShell. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Storage security audits across subscriptions
  • Responding to Defender for Storage anonymous-access alerts
  • Verifying compliance controls
  • Setting security baselines when onboarding a subscription

Example prompts

  • “/detecting-misconfigured-azure-storage”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Enumerate All Storage Accounts and Basic Configuration
  2. Detect Publicly Accessible Blob Containers
  3. Audit Network Access and Firewall Rules
  4. Verify Encryption Settings and Key Management
  5. Audit Shared Access Signatures and Access Keys
  6. Check Diagnostic Logging and Monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • az
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • account.blob.core.windows.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Detecting Misconfigured Azure Storage loads about 3.1k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 116 tokens; SKILL.md has 657 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~116
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:260
    Contents: 1,247 files including .env and config.json

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 657 words, ~3,097 tokens.

Download SKILL.mdSave it as .claude/skills/detecting-misconfigured-azure-storage/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
detecting-misconfigured-azure-storage
description
Audit Azure Storage accounts for public blob containers, missing encryption, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage. Use for storage security audits across subscriptions, responding to Defender for Storage anonymous-access alerts, verifying compliance controls, or setting security baselines when onboarding a subscription.
domain
cybersecurity
subdomain
cloud-security
tags
cloud-security, azure, storage-security, blob-storage, sas-tokens, data-protection
version
1.0
author
mahipal
license
Apache-2.0
nist_ai_rmf
MEASURE-2.7, MAP-5.1, MANAGE-2.4
atlas_techniques
AML.T0070, AML.T0066, AML.T0082
nist_csf
PR.IR-01, ID.AM-08, GV.SC-06, DE.CM-01
mitre_attack
T1078.004, T1530, T1537, T1580, T1610

Detecting Misconfigured Azure Storage

When to Use

  • When performing a security audit of Azure Storage accounts across subscriptions
  • When responding to Microsoft Defender for Storage alerts about anonymous access or data exfiltration
  • When compliance requires verification of encryption, network restrictions, and access logging
  • When investigating potential data exposure through publicly accessible blob containers
  • When onboarding Azure subscriptions and establishing storage security baselines

Do not use for Azure SQL or Cosmos DB security auditing (use dedicated database security tools), for real-time threat detection on storage operations (use Defender for Storage), or for Azure Files or Data Lake Gen2 specific auditing without adapting the checks.

Prerequisites

  • Azure CLI installed and authenticated (az login) with Reader and Storage Account Contributor roles
  • Az PowerShell module installed for advanced queries (Install-Module Az.Storage)
  • Microsoft Defender for Storage enabled for threat detection
  • Access to Azure Resource Graph for cross-subscription queries
  • ScoutSuite or Prowler Azure provider for automated assessment

Workflow

Step 1: Enumerate All Storage Accounts and Basic Configuration

List all storage accounts across subscriptions and assess their baseline security settings.

bash
# List all storage accounts across all subscriptions
az storage account list \
  --query "[].{Name:name, ResourceGroup:resourceGroup, Location:location, Kind:kind, Sku:sku.name, HttpsOnly:enableHttpsTrafficOnly, MinTLS:minimumTlsVersion, PublicAccess:allowBlobPublicAccess}" \
  -o table

# Use Resource Graph for cross-subscription enumeration
az graph query -q "
  Resources
  | where type == 'microsoft.storage/storageaccounts'
  | project name, resourceGroup, subscriptionId, location,
    properties.allowBlobPublicAccess,
    properties.enableHttpsTrafficOnly,
    properties.minimumTlsVersion,
    properties.networkAcls.defaultAction
" -o table
Step 2: Detect Publicly Accessible Blob Containers

Identify storage accounts and containers allowing anonymous public access to blob data.

bash
# Check each storage account for public blob access setting
for account in $(az storage account list --query "[].name" -o tsv); do
  public=$(az storage account show --name "$account" --query "allowBlobPublicAccess" -o tsv)
  echo "$account: allowBlobPublicAccess=$public"
done

# List containers with public access level set
for account in $(az storage account list --query "[?allowBlobPublicAccess==true].name" -o tsv); do
  key=$(az storage account keys list --account-name "$account" --query "[0].value" -o tsv)
  echo "=== $account ==="
  az storage container list \
    --account-name "$account" \
    --account-key "$key" \
    --query "[?properties.publicAccess!='off' && properties.publicAccess!=null].{Container:name, PublicAccess:properties.publicAccess}" \
    -o table 2>/dev/null
done

# Test anonymous access to discovered public containers
curl -s "https://ACCOUNT.blob.core.windows.net/CONTAINER?restype=container&comp=list" | head -50
Step 3: Audit Network Access and Firewall Rules

Check for storage accounts accessible from all networks versus those restricted to specific VNets or IP ranges.

bash
# Find storage accounts with default network action set to Allow (open to all networks)
az storage account list \
  --query "[?networkRuleSet.defaultAction=='Allow'].{Name:name, DefaultAction:networkRuleSet.defaultAction, VNetRules:networkRuleSet.virtualNetworkRules}" \
  -o table

# Detailed network rule audit
for account in $(az storage account list --query "[].name" -o tsv); do
  echo "=== $account ==="
  az storage account show --name "$account" \
    --query "{DefaultAction:networkRuleSet.defaultAction, IPRules:networkRuleSet.ipRules[*].ipAddressOrRange, VNetRules:networkRuleSet.virtualNetworkRules[*].virtualNetworkResourceId, Bypass:networkRuleSet.bypass}" \
    -o json
done

# Find storage accounts with private endpoints
az network private-endpoint list \
  --query "[?privateLinkServiceConnections[0].groupIds[0]=='blob'].{Name:name, Storage:privateLinkServiceConnections[0].privateLinkServiceId}" \
  -o table
Step 4: Verify Encryption Settings and Key Management

Ensure all storage accounts use encryption at rest with appropriate key management (Microsoft-managed or customer-managed keys).

bash
# Check encryption configuration for all storage accounts
for account in $(az storage account list --query "[].name" -o tsv); do
  echo "=== $account ==="
  az storage account show --name "$account" \
    --query "{Encryption:encryption.services, KeySource:encryption.keySource, KeyVaultUri:encryption.keyVaultProperties.keyVaultUri, InfraEncryption:encryption.requireInfrastructureEncryption}" \
    -o json
done

# Find accounts without infrastructure encryption (double encryption)
az storage account list \
  --query "[?encryption.requireInfrastructureEncryption!=true].{Name:name, KeySource:encryption.keySource}" \
  -o table

# Check for accounts using TLS version below 1.2
az storage account list \
  --query "[?minimumTlsVersion!='TLS1_2'].{Name:name, TLS:minimumTlsVersion}" \
  -o table
Step 5: Audit Shared Access Signatures and Access Keys

Identify overly permissive SAS tokens and check for access key usage patterns.

bash
# Check when storage account keys were last rotated
for account in $(az storage account list --query "[].name" -o tsv); do
  echo "=== $account ==="
  az storage account keys list \
    --account-name "$account" \
    --query "[].{KeyName:keyName, CreationTime:creationTime}" \
    -o table
done

# Check if storage account allows shared key access (should be disabled for AAD-only)
az storage account list \
  --query "[].{Name:name, AllowSharedKeyAccess:allowSharedKeyAccess}" \
  -o table

# Review stored access policies on containers (SAS governance)
for account in $(az storage account list --query "[].name" -o tsv); do
  key=$(az storage account keys list --account-name "$account" --query "[0].value" -o tsv 2>/dev/null)
  for container in $(az storage container list --account-name "$account" --account-key "$key" --query "[].name" -o tsv 2>/dev/null); do
    policies=$(az storage container policy list --container-name "$container" --account-name "$account" --account-key "$key" 2>/dev/null)
    [ -n "$policies" ] && echo "$account/$container: $policies"
  done
done
Step 6: Check Diagnostic Logging and Monitoring

Verify that storage analytics logging and Azure Monitor diagnostic settings are enabled.

bash
# Check diagnostic settings for storage accounts
for account in $(az storage account list --query "[].name" -o tsv); do
  rg=$(az storage account show --name "$account" --query "resourceGroup" -o tsv)
  echo "=== $account ==="
  az monitor diagnostic-settings list \
    --resource "/subscriptions/$(az account show --query id -o tsv)/resourceGroups/$rg/providers/Microsoft.Storage/storageAccounts/$account" \
    --query "[].{Name:name, Logs:logs[*].category, Metrics:metrics[*].category}" \
    -o json 2>/dev/null || echo "  No diagnostic settings configured"
done

# Check blob service logging properties
for account in $(az storage account list --query "[].name" -o tsv); do
  key=$(az storage account keys list --account-name "$account" --query "[0].value" -o tsv 2>/dev/null)
  az storage logging show \
    --account-name "$account" \
    --account-key "$key" \
    --services b 2>/dev/null
done

Key Concepts

TermDefinition
Blob Public AccessStorage account setting that allows anonymous read access to blob containers and their contents without authentication
Shared Access SignatureTime-limited URI with embedded authentication tokens granting delegated access to Azure Storage resources with specific permissions
Network ACL Default ActionStorage firewall setting that determines whether traffic is allowed or denied by default, with exceptions for specified IPs and VNets
Customer-Managed KeyEncryption key stored in Azure Key Vault that the customer controls for storage encryption instead of Microsoft-managed keys
Stored Access PolicyNamed policy on a container that defines SAS permissions, start/expiry times, and can be revoked independently of individual SAS tokens
Defender for StorageMicrosoft Defender plan providing threat detection for anomalous storage access patterns, malware uploads, and data exfiltration
Show full SKILL.md (248 more words)Show less

Tools & Systems

  • Azure CLI: Primary tool for querying storage account configuration, containers, and access policies
  • Azure Resource Graph: Cross-subscription query engine for efficient enumeration of storage security settings at scale
  • Microsoft Defender for Storage: Threat detection service identifying anomalous access patterns and potential data exfiltration
  • Prowler Azure: Open-source tool with automated storage security checks aligned to CIS Azure Foundations
  • ScoutSuite: Multi-cloud auditing tool with Azure storage-specific checks for public access, encryption, and networking

Common Scenarios

Scenario: Detecting a Storage Account Exposed by a Developer Misconfiguration

Context: A developer creates a storage account for a web application and enables blob public access to serve static files. They accidentally store API keys and database connection strings in a publicly accessible container.

Approach:

  1. Run az storage account list filtering for allowBlobPublicAccess=true
  2. Enumerate containers with public access level set to blob or container
  3. List contents of public containers to identify sensitive files
  4. Check Defender for Storage alerts for anomalous access from unexpected IPs
  5. Immediately set allowBlobPublicAccess to false on the storage account
  6. Rotate any exposed credentials found in public containers
  7. Enable network ACLs restricting access to the application VNet
  8. Configure Azure CDN or Front Door for legitimate public content delivery

Pitfalls: Disabling blob public access immediately breaks applications serving content publicly. Coordinate with the development team and implement Azure CDN before disabling public access. SAS tokens generated before a key rotation remain valid until expiry unless the underlying storage key is regenerated.

Output Format

Azure Storage Security Audit Report
======================================
Subscription: Production (SUB-ID)
Assessment Date: 2026-02-23
Storage Accounts Audited: 24

CRITICAL FINDINGS:
[STOR-001] Public Blob Access Enabled
  Account: webapp-static-prod
  Container: uploads (PublicAccess: blob)
  Risk: Anonymous users can read all blobs in the container
  Contents: 1,247 files including .env and config.json
  Remediation: Disable allowBlobPublicAccess, use Azure CDN with SAS

[STOR-002] Storage Account Open to All Networks
  Account: data-lake-analytics
  Default Action: Allow (no network restrictions)
  Risk: Accessible from any network including the internet
  Remediation: Set default action to Deny, add VNet rules

SUMMARY:
  Public blob access enabled:           3 / 24
  Open to all networks:                 8 / 24
  Missing infrastructure encryption:   12 / 24
  TLS version below 1.2:                2 / 24
  No diagnostic logging:               10 / 24
  Shared key access enabled:           18 / 24
  Keys not rotated in 90+ days:        14 / 24

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/detecting-misconfigured-azure-storage of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Detecting Misconfigured Azure Storage next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Detecting Misconfigured Azure Storage compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Detecting Misconfigured Azure Storage this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: NotesApache-2.0
Azure API Management Security Reviewthomast1906/github-copilot-agent-skills202—~3.1kAutomated safety check: PassMIT
Sharp Edges Analysistrailofbits/skills7.5k3 repos~3kAutomated safety check: PassCC-BY-SA-4.0
Code Securitysemgrep/skills324—~1.2kAutomated safety check: PassCustom licence
Security Analysismicrosoft/haste107—~1kAutomated safety check: PassMIT
Crypto Protocol Diagramstrailofbits/skills7.5k—~4.6kAutomated safety check: PassCC-BY-SA-4.0

Similar skills

  • Azure API Management Security Review

    thomast1906/github-copilot-agent-skills

    Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

    202 GitHub stars~3.1k tokensUpdated 3 days ago
    SecurityAuto-check passed
  • Sharp Edges Analysis

    trailofbits/skills

    Official

    Reviews APIs, configuration schemas and library interfaces for footguns, the designs where the easy path leads to insecure use, using a four-phase analysis.

    7.5k GitHub starsUsed in 3 repos~3k tokens
    SecurityAuto-check passed
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    324 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Security Analysis

    microsoft/haste

    Official

    Dependabot and security analysis skill for HASTE. An agent skill from microsoft/haste.

    107 GitHub stars~1k tokensUpdated yesterday
    SecurityAuto-check passed
  • Crypto Protocol Diagrams

    trailofbits/skills

    Official

    Turns a cryptographic protocol's source code, RFC, paper or ProVerif or Tamarin model into a Mermaid sequence diagram annotated with each cryptographic operation.

    7.5k GitHub stars~4.6k tokensUpdated yesterday
    SecurityAuto-check passed
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Detecting Misconfigured Azure Storage

What does Detecting Misconfigured Azure Storage do?

Audit Azure Storage accounts for public blob containers, missing encryption, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft…. Detecting Misconfigured Azure Storage is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Audit Azure Storage accounts for public blob containers, missing encryption, overly permissive SAS tokens, disabled logging, and network access violations using Azure CLI, PowerShell, and Microsoft Defender for Storage.

When should I use Detecting Misconfigured Azure Storage?

Detecting Misconfigured Azure Storage fits situations like: storage security audits across subscriptions; responding to Defender for Storage anonymous-access alerts; verifying compliance controls; setting security baselines when onboarding a subscription.

How do I install Detecting Misconfigured Azure Storage in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-misconfigured-azure-storage -a claude-code`. Or copy the skill folder (skills/detecting-misconfigured-azure-storage in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/detecting-misconfigured-azure-storage in your project. Claude Code loads it when a task matches its description.

How do I install Detecting Misconfigured Azure Storage in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-misconfigured-azure-storage -a codex`. Or copy the skill folder (skills/detecting-misconfigured-azure-storage in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/detecting-misconfigured-azure-storage in your project. Codex loads it when a task matches its description.

Can I use Detecting Misconfigured Azure Storage in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill detecting-misconfigured-azure-storage -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/detecting-misconfigured-azure-storage, .gemini/skills/detecting-misconfigured-azure-storage, .github/skills/detecting-misconfigured-azure-storage and .opencode/skills/detecting-misconfigured-azure-storage in your project.

What does Detecting Misconfigured Azure Storage need to run?

Going by SKILL.md and its folder, Detecting Misconfigured Azure Storage needs Python for the scripts in its folder and the command-line tools its instructions call (az and curl). Our summary lists: Python 3.

Does Detecting Misconfigured Azure Storage access the network?

SKILL.md names 1 domain. In commands or code: account.blob.core.windows.net; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Detecting Misconfigured Azure Storage safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Detecting Misconfigured Azure Storage use?

Detecting Misconfigured Azure Storage is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Detecting Misconfigured Azure Storage use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 666 tokens, read only when the agent opens those files.

What are the alternatives to Detecting Misconfigured Azure Storage?

Skills that share tags, products or a category with Detecting Misconfigured Azure Storage: Azure API Management Security Review (thomast1906/github-copilot-agent-skills, 202 stars), Sharp Edges Analysis (trailofbits/skills, 7.5k stars), Code Security (semgrep/skills, 324 stars) and Security Analysis (microsoft/haste, 107 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Detecting Misconfigured Azure Storage?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.