The skill exhibits a potential supply chain risk by referencing external documentation that is missing from the package, which could lead to unauthorized content injection or runtime execution errors.
npx skills add https://github.com/microsoft/azure-skillsSKILL.md links to "references/azure-resource-graph.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[Azure Resource Graph Query Patterns](references/azure-resource-graph.md)
[](https://mondoo.com/ai-agent-security/skills/github/microsoft/azure-skills/azure-resource-lookup)<a href="https://mondoo.com/ai-agent-security/skills/github/microsoft/azure-skills/azure-resource-lookup"><img src="https://mondoo.com/ai-agent-security/api/badge/github/microsoft/azure-skills/azure-resource-lookup.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/microsoft/azure-skills/azure-resource-lookup.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.