Agent skill

Cloud App Security Posture

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps.

MITAuto-check passedSecurity

Install Cloud App Security Posture

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill cloud-app-security-posture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills cloud-app-security-posture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud-app-security-posture .claude/skills/cloud-app-security-posture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-app-security-posture
GitHub stars
175
Token cost
~2.1k tokens
SKILL.md length
973 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps.

  • Works in 7 steps: Enable foundation CSPM everywhere - Turn… → Turn on Defender CSPM (paid) for… → Enable SSPM in Defender for Cloud Apps -… → …
  • IaaS/PaaS workload threat protection plans (use defender-for-cloud-hardening)
  • SKILL.md covers When to use, Pick the right posture lens, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cloud App Security Posture is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps. Covers Secure Score, MCSB, attack-path analysis, SSPM recommendations, and governance. WHEN: cloud security posture, SaaS security posture management, SSPM, CSPM, secure cloud apps, posture recommendations, harden SaaS configuration, app security posture, multicloud and SaaS hardening, harden Microsoft 365 SaaS…

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Cloud security, Cloud office suites and CRM management. It works with Microsoft Defender, Microsoft 365, Salesforce and ServiceNow. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • IaaS/PaaS workload threat protection plans (use defender-for-cloud-hardening)
  • For SaaS threat detection only (use defender-for-cloud-apps)

Example prompts

  • “/cloud-app-security-posture”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Enable foundation CSPM everywhere - Turn on Defender for Cloud across all Azure
  2. Turn on Defender CSPM (paid) for high-value scopes - Enable the paid plan on
  3. Enable SSPM in Defender for Cloud Apps - Connect each SaaS app (Microsoft 365,
  4. Prioritise by exposure and impact - Rank remediations by: internet exposure, sensitive
  5. Assign owners and SLAs - Recommendations without an owner do not get fixed. Route by
  6. Enforce and automate where safe - Use Azure Policy to prevent regression of fixed
  7. Monitor drift continuously - Re-baseline as the estate changes (new subscriptions, new

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud App Security Posture loads about 2.1k tokens when it runs. Until then it costs about 197 tokens; SKILL.md has 973 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~197
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 973 words, ~2,122 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-app-security-posture/SKILL.md (or your agent's skills folder).
name
cloud-app-security-posture
description
Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps. Covers Secure Score, MCSB, attack-path analysis, SSPM recommendations, and governance. WHEN: cloud security posture, SaaS security posture management, SSPM, CSPM, secure cloud apps, posture recommendations, harden SaaS configuration, app security posture, multicloud and SaaS hardening, harden Microsoft 365 SaaS settings, find misconfigured Salesforce or ServiceNow settings, SaaS app misconfiguration. DO NOT USE for IaaS/PaaS workload threat protection plans (use defender-for-cloud-hardening) or for SaaS threat detection only (use defender-for-cloud-apps).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Cloud & App Security Posture

Security posture management spans two complementary layers: CSPM for cloud infrastructure (IaaS/PaaS) via Microsoft Defender for Cloud, and SSPM for SaaS applications via Microsoft Defender for Cloud Apps. Together they continuously reduce misconfiguration risk across the cloud and SaaS estate.

When to use

Assessing and continuously hardening configuration posture across both cloud infrastructure and SaaS applications - especially when remediation has stalled or when you cannot answer "what should we fix next?".

Do not use this skill for:

  • IaaS/PaaS workload threat protection plans (use defender-for-cloud-hardening)
  • SaaS threat detection or shadow-IT discovery only (use defender-for-cloud-apps)
  • DSPM for AI (use purview-dspm-ai)

Pick the right posture lens

You need to harden...Use thisSurface
Azure subscriptions, AWS accounts, GCP projectsDefender for Cloud CSPMDefender for Cloud → Recommendations
Internet-exposed VMs / data with toxic combinationsDefender CSPM (paid) + attack-pathDefender for Cloud → Attack path analysis
Microsoft 365, Salesforce, ServiceNow, GitHub configDefender for Cloud Apps SSPMDefender XDR → Cloud apps → Posture
Container / Kubernetes postureDefender CSPM container planDefender for Cloud → Cloud security graph
Code / IaC misconfigurationDevOps security in Defender for CloudDefender for Cloud → DevOps
Identity hygiene gaps in the cloudIdentity recommendations (CIEM)Defender for Cloud + Entra Permissions Mgmt

Rule of thumb: Foundation CSPM is free with the Defender for Cloud plan and gives you Secure Score + MCSB recommendations. The paid Defender CSPM plan adds attack-path analysis, the cloud security graph, agentless scanning, and DevOps - enable it for any environment where you need to prioritise by exploitability, not by count.

Approach

  1. Enable foundation CSPM everywhere - Turn on Defender for Cloud across all Azure subscriptions, connect AWS accounts and GCP projects, and confirm Microsoft Cloud Security Benchmark (MCSB) recommendations and Secure Score are populating. Verify: Defender for Cloud → Inventory shows all subscriptions/accounts; Secure Score is non-zero per scope.
  2. Turn on Defender CSPM (paid) for high-value scopes - Enable the paid plan on subscriptions/accounts holding internet-exposed workloads or sensitive data to unlock attack-path analysis and the cloud security graph. Foundation CSPM alone tells you what is misconfigured; Defender CSPM tells you which misconfigurations form an exploitable chain. Verify: Attack path analysis page lists at least one path; you can trace a path from internet to sensitive data.
  3. Enable SSPM in Defender for Cloud Apps - Connect each SaaS app (Microsoft 365, Salesforce, ServiceNow, GitHub, Okta, etc.) via API connector. SSPM recommendations cover admin controls, MFA settings, sharing exposure, and inactive privileged users per app. Verify: Defender XDR → Cloud apps → Posture shows recommendations per connected app, not just discovery.
  4. Prioritise by exposure and impact - Rank remediations by: internet exposure, sensitive data, privileged identity, and attack-path criticality. Use the cloud security graph to group recommendations that break the same path. Verify: top 10 remediation list is not the top 10 by recommendation count but the top 10 by risk-weighted impact.
  5. Assign owners and SLAs - Recommendations without an owner do not get fixed. Route by workload (subscription tag, resource group, SaaS app owner) into your ticketing system with a remediation SLA based on severity. Verify: ticket count per workload owner is visible; aging report shows median time to close per severity.
  6. Enforce and automate where safe - Use Azure Policy to prevent regression of fixed configurations (deny new resources without encryption, block public IP creation in tagged scopes). Use Defender for Cloud workflow automation to route recommendations to Logic Apps for auto-remediation where reversible. Verify: at least one Azure Policy denies a previously-common misconfiguration; auto- remediation logs show successful fixes for one recommendation class.
  7. Monitor drift continuously - Re-baseline as the estate changes (new subscriptions, new SaaS apps, new accounts). Posture is not a one-time project; it is an operating model. Verify: Secure Score trend over 90 days is flat or improving, not erratic.
Show full SKILL.md (349 more words)Show less

Guardrails

  • Posture management is preventive; pair with threat detection (Defender for Cloud workload plans, Defender for Cloud Apps threat policies). Posture without detection misses live attacks; detection without posture lets the same hole be exploited repeatedly.
  • Don't chase score for its own sake - fix exploitable, high-impact issues first. A 95% Secure Score with an open attack path to crown-jewel data is worse than a 70% score with no paths.
  • Coordinate remediation with app/workload owners to avoid breakage. Disabling public access on a storage account that a partner depends on is an outage, not a fix.
  • Free CSPM is the floor, not the ceiling. Foundation CSPM lacks attack-path and graph features - in high-risk scopes, the paid Defender CSPM plan is the right baseline.
  • Each connected SaaS app costs governance attention - connect the ones you actually manage, not every connector that exists.
  • Treat posture findings as code - fix the root template (Bicep, Terraform, IaC), not just the deployed resource, so the fix survives the next deployment.

Common anti-patterns

  • "Enable everything and let analysts triage the noise." Without scope, ownership, and prioritisation, posture becomes a 10,000-item backlog and nothing moves.
  • Chasing Secure Score number while ignoring attack paths. A clean score plus an exploitable path is worse than a messy score with no exploitable path.
  • SSPM as a checkbox - connecting SaaS apps but never reviewing the recommendations. The value is the recurring review cadence.
  • No Azure Policy backstop. Fixed recommendations regress because nothing prevents the next deployment from re-introducing the same misconfiguration.
  • Treating SSPM and CSPM as separate worlds. Many exploit chains cross the boundary (compromised SaaS admin → cloud workload). Review both lenses together for high-risk users.

Example prompts

  • Harden our Microsoft 365 SaaS settings and review posture recommendations.
  • Find misconfigured Salesforce or ServiceNow settings with SSPM.
  • How do I improve SaaS security posture across multiple cloud apps?
  • Use attack-path analysis to prioritise CSPM remediations.
  • Review and remediate the top 10 cross-cloud posture issues.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cloud-app-security-posture of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Cloud App Security Posture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud App Security Posture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud App Security Posture this skillvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Implementing Zero Trust For SaaS Applicationsmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Detecting Spearphishing With Email Gatewaymukul975/Anthropic-Cybersecurity-Skills34k—~1.4kAutomated safety check: PassApache-2.0
API GatewayCraftOS-dev/CraftBot3923 repos~7.1kAutomated safety check: PassMIT
Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills34k—~3kAutomated safety check: PassApache-2.0
Investigating Phishing Email Incidentmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Zero Trust For SaaS Applications

    mukul975/Anthropic-Cybersecurity-Skills

    Secures SaaS apps (Microsoft 365, Google Workspace, Salesforce, Slack) via CASB/SSPM deployment, conditional access policies, OAuth app governance, and session-level DLP controls enforcing identity…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Detecting Spearphishing With Email Gateway

    mukul975/Anthropic-Cybersecurity-Skills

    Detect and block spearphishing emails that use personalized, researched content to evade generic spam filters, by configuring email security gateway (SEG) impersonation protection, URL rewriting…

    34k GitHub stars~1.4k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • API Gateway

    CraftOS-dev/CraftBot

    Connect to 100+ APIs (Google Workspace, Microsoft 365, Notion, Slack, Airtable, HubSpot, etc.) with managed OAuth.

    392 GitHub starsUsed in 3 repos~7.1k tokens
    Backend & APIsAuto-check passed
  • Implementing Cloud Security Posture Management

    mukul975/Anthropic-Cybersecurity-Skills

    Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Investigating Phishing Email Incident

    mukul975/Anthropic-Cybersecurity-Skills

    Investigates phishing email incidents from initial user report through header analysis, URL/attachment detonation, impacted user identification, and containment actions using SOC tools like Splunk…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Analyzing Office365 Audit Logs For Compromise

    mukul975/Anthropic-Cybersecurity-Skills

    Parse Office 365 Unified Audit Logs via Microsoft Graph API to detect email forwarding rule creation, inbox delegation, suspicious OAuth app grants, and other indicators of account compromise.

    34k GitHub stars~584 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Cloud App Security Posture

What does Cloud App Security Posture do?

Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps. Cloud App Security Posture is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for cloud and SaaS security posture management - combining Defender for Cloud CSPM (IaaS/PaaS) and Defender for Cloud Apps SSPM (SaaS) to assess and harden posture across cloud and SaaS apps.

When should I use Cloud App Security Posture?

Cloud App Security Posture fits situations like: iaaS/PaaS workload threat protection plans (use defender-for-cloud-hardening); for SaaS threat detection only (use defender-for-cloud-apps).

How do I install Cloud App Security Posture in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill cloud-app-security-posture -a claude-code`. Or copy the skill folder (skills/cloud-app-security-posture in vinayaklatthe/microsoft-security-skills) into .claude/skills/cloud-app-security-posture in your project. Claude Code loads it when a task matches its description.

How do I install Cloud App Security Posture in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill cloud-app-security-posture -a codex`. Or copy the skill folder (skills/cloud-app-security-posture in vinayaklatthe/microsoft-security-skills) into .agents/skills/cloud-app-security-posture in your project. Codex loads it when a task matches its description.

Can I use Cloud App Security Posture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill cloud-app-security-posture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-app-security-posture, .gemini/skills/cloud-app-security-posture, .github/skills/cloud-app-security-posture and .opencode/skills/cloud-app-security-posture in your project.

What does Cloud App Security Posture need to run?

SKILL.md names no scripts, command-line tools or credentials: Cloud App Security Posture is instructions for the agent only.

Does Cloud App Security Posture access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Cloud App Security Posture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloud App Security Posture use?

Cloud App Security Posture is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud App Security Posture use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloud App Security Posture?

Skills that share tags, products or a category with Cloud App Security Posture: Implementing Zero Trust For SaaS Applications (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting Spearphishing With Email Gateway (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), API Gateway (CraftOS-dev/CraftBot, 392 stars) and Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud App Security Posture?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.