The skill bypasses user confirmation, probes cloud metadata, and executes unconstrained operations while relying on external, non-packaged documentation, creating significant security and transparency risks.
npx skills add https://github.com/microsoft/azure-skillsUser confirmation bypass detected — attempts to skip human oversight (seen 2 times in this file at lines 63, 202)
auto-approve
Cloud identity probing — discovers cloud account identity or queries instance metadata
az account show
SKILL.md links to "references/advanced-commands.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[az quota request status](./references/advanced-commands.md#az-quota-request-status-list)
SKILL.md links to "references/commands.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[commands.md](./references/commands.md)
[](https://mondoo.com/ai-agent-security/skills/github/microsoft/azure-skills/azure-quotas)<a href="https://mondoo.com/ai-agent-security/skills/github/microsoft/azure-skills/azure-quotas"><img src="https://mondoo.com/ai-agent-security/api/badge/github/microsoft/azure-skills/azure-quotas.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/microsoft/azure-skills/azure-quotas.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.