No security issues detected in microsoft/github-copilot-for-azure/azure-rbac.
Claims to do
Prerequisites for Granting Roles: To assign RBAC roles to identities, you need a role that includes the `Microsoft.Authorization/roleAssignments/write` permission. The most common roles with this permission are:
Actually does
The skill uses `azure__documentation` to find minimal role definitions, `azure__extension_cli_generate` to create custom roles or generate CLI commands for role assignment, and `azure__bicepschema` and `azure__get_azure_bestpractices` to provide Bicep code snippets. It also provides hardcoded text detailing the `Microsoft.Authorization/roleAssignments/write` permission required to grant roles.
npx skills add https://github.com/microsoft/github-copilot-for-azure[](https://mondoo.com/ai-agent-security/skills/github/microsoft/github-copilot-for-azure/azure-rbac)<a href="https://mondoo.com/ai-agent-security/skills/github/microsoft/github-copilot-for-azure/azure-rbac"><img src="https://mondoo.com/ai-agent-security/api/badge/github/microsoft/github-copilot-for-azure/azure-rbac.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/microsoft/github-copilot-for-azure/azure-rbac.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.