{"data":{"skill":{"slug":"microsoft-azure-cost","name":"azure-cost","icon":"📦","repo":"https://github.com/microsoft/azure-skills/tree/main/.github/plugins/azure-skills/skills/azure-cost/","status":"approved","author":"microsoft","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"385262a2-073a-4dfd-87ad-75fe43dfca6f","skill_id":"db48ab05-afd7-4c7b-b876-7ed596b4f8e9","version":3,"content_hash":"f283cb604270d402f40b8a55e705119e","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"No prompt-injection language, malicious data exfiltration, or business-logic abuse was found in the reviewed files. The static findings are false positives from Markdown links, code fences, official Azure endpoints, Azure CLI examples, and credential best-practice snippets.","remediation":[{"issue":"Azure CLI examples can access subscription cost and resource metadata when a user runs them.","severity":"low","suggestion":"State that commands require explicit user approval and should use least-privilege Cost Management Reader access."},{"issue":"Generated reports and saved query results may contain cost amounts, resource IDs, and subscription identifiers.","severity":"low","suggestion":"Add guidance to redact sensitive identifiers before sharing reports outside the user organization."}],"risk_factor_evidence":[{"factor":"filesystem","evidence":[{"file":"cost-forecast/examples.md","line_end":3,"line_start":3},{"file":"cost-forecast/workflow.md","line_end":5,"line_start":5},{"file":"cost-forecast/workflow.md","line_end":21,"line_start":21},{"file":"cost-forecast/workflow.md","line_end":44,"line_start":44},{"file":"cost-forecast/workflow.md","line_end":92,"line_start":92},{"file":"cost-optimization/sdk/azure-resource-manager-redis-dotnet.md","line_end":13,"line_start":13},{"file":"cost-optimization/sdk/azure-resource-manager-redis-dotnet.md","line_end":24,"line_start":24},{"file":"cost-optimization/workflow.md","line_end":5,"line_start":5},{"file":"cost-optimization/workflow.md","line_end":119,"line_start":119},{"file":"cost-optimization/workflow.md","line_end":152,"line_start":152},{"file":"cost-query/examples.md","line_end":3,"line_start":3},{"file":"cost-query/workflow.md","line_end":7,"line_start":7}]},{"factor":"external_commands","evidence":[{"file":"cost-forecast/workflow.md","line_end":83,"line_start":81},{"file":"cost-forecast/workflow.md","line_end":77,"line_start":77},{"file":"cost-optimization/auth-best-practices.md","line_end":16,"line_start":16},{"file":"cost-optimization/auth-best-practices.md","line_end":81,"line_start":81},{"file":"cost-optimization/auth-best-practices.md","line_end":87,"line_start":87},{"file":"cost-optimization/azure-quick-review.md","line_end":25,"line_start":25},{"file":"cost-optimization/report-template.md","line_end":49,"line_start":47},{"file":"cost-optimization/report-template.md","line_end":67,"line_start":67},{"file":"cost-optimization/workflow.md","line_end":177,"line_start":176},{"file":"cost-optimization/workflow.md","line_end":179,"line_start":178},{"file":"cost-optimization/workflow.md","line_end":182,"line_start":180},{"file":"cost-optimization/workflow.md","line_end":20,"line_start":20},{"file":"cost-optimization/workflow.md","line_end":112,"line_start":112},{"file":"cost-optimization/workflow.md","line_end":170,"line_start":170},{"file":"cost-query/workflow.md","line_end":81,"line_start":79},{"file":"cost-query/workflow.md","line_end":124,"line_start":110},{"file":"cost-query/workflow.md","line_end":73,"line_start":73},{"file":"cost-query/workflow.md","line_end":108,"line_start":108},{"file":"SKILL.md","line_end":30,"line_start":30},{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33},{"file":"SKILL.md","line_end":40,"line_start":40},{"file":"SKILL.md","line_end":41,"line_start":41},{"file":"SKILL.md","line_end":42,"line_start":42},{"file":"SKILL.md","line_end":43,"line_start":43},{"file":"SKILL.md","line_end":44,"line_start":44},{"file":"SKILL.md","line_end":46,"line_start":46},{"file":"SKILL.md","line_end":69,"line_start":69},{"file":"SKILL.md","line_end":70,"line_start":70},{"file":"SKILL.md","line_end":71,"line_start":71},{"file":"SKILL.md","line_end":72,"line_start":72},{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":115,"line_start":115},{"file":"SKILL.md","line_end":127,"line_start":127}]},{"factor":"env_access","evidence":[{"file":"cost-optimization/auth-best-practices.md","line_end":43,"line_start":43},{"file":"cost-optimization/auth-best-practices.md","line_end":101,"line_start":101},{"file":"cost-optimization/auth-best-practices.md","line_end":104,"line_start":104},{"file":"cost-optimization/auth-best-practices.md","line_end":105,"line_start":105},{"file":"cost-optimization/auth-best-practices.md","line_end":43,"line_start":43},{"file":"cost-optimization/auth-best-practices.md","line_end":101,"line_start":101},{"file":"cost-optimization/auth-best-practices.md","line_end":104,"line_start":104},{"file":"cost-optimization/auth-best-practices.md","line_end":105,"line_start":105},{"file":"cost-optimization/auth-best-practices.md","line_end":57,"line_start":57},{"file":"cost-optimization/auth-best-practices.md","line_end":57,"line_start":57},{"file":"cost-optimization/auth-best-practices.md","line_end":69,"line_start":69},{"file":"cost-optimization/auth-best-practices.md","line_end":104,"line_start":104},{"file":"cost-optimization/auth-best-practices.md","line_end":105,"line_start":105}]},{"factor":"network","evidence":[{"file":"cost-optimization/azure-aks-anomalies.md","line_end":13,"line_start":13},{"file":"cost-optimization/report-template.md","line_end":56,"line_start":56}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":21,"total_lines":2237,"audit_model":"codex","audited_at":"2026-07-05T21:04:47.882+00:00","created_at":"2026-07-05T22:05:16.666635+00:00","static_findings":[{"id":"blocker:cost-forecast/error-handling.md:7:system-reconnaissance","file":"cost-forecast/error-handling.md","pattern":"System reconnaissance","snippet":"| 400 | Bad Request | Invalid request body, missing `dataset`, past-only dates, invalid field depend","category":"blocker","line_end":7,"severity":"low","line_start":7},{"id":"blocker:cost-forecast/error-handling.md:10:system-reconnaissance","file":"cost-forecast/error-handling.md","pattern":"System reconnaissance","snippet":"| 404 | Not Found | Invalid scope URL — subscription, resource group, or billing account not found |","category":"blocker","line_end":10,"severity":"low","line_start":10},{"id":"blocker:cost-forecast/error-handling.md:20:system-reconnaissance","file":"cost-forecast/error-handling.md","pattern":"System reconnaissance","snippet":"| `InvalidForecastRequestBody` | Request body has invalid JSON structure | Check JSON syntax — verif","category":"blocker","line_end":20,"severity":"low","line_start":20},{"id":"blocker:cost-forecast/error-handling.md:22:system-reconnaissance","file":"cost-forecast/error-handling.md","pattern":"System reconnaissance","snippet":"| `DontContainsValidTimeRangeWhileContainsPeriod` | `timePeriod` is present but `from` or `to` is in","category":"blocker","line_end":22,"severity":"low","line_start":22},{"id":"blocker:cost-forecast/error-handling.md:23:system-reconnaissance","file":"cost-forecast/error-handling.md","pattern":"System reconnaissance","snippet":"| `DontContainsValidTimeRangeWhileMonthlyAndIncludeCost` | Monthly granularity with `includeActualCo","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"blocker:cost-forecast/error-handling.md:31:system-reconnaissance","file":"cost-forecast/error-handling.md","pattern":"System reconnaissance","snippet":"| \"Forecast is unavailable for the specified time period\" | Valid response with null/empty rows | No","category":"blocker","line_end":31,"severity":"low","line_start":31},{"id":"filesystem:cost-forecast/examples.md:3:path-traversal-sequence","file":"cost-forecast/examples.md","pattern":"Path traversal sequence","snippet":"Common forecast patterns with request bodies. Use the [SKILL.md workflow](../SKILL.md) to construct ","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"blocker:cost-forecast/guardrails.md:11:system-reconnaissance","file":"cost-forecast/guardrails.md","pattern":"System reconnaissance","snippet":"| Both dates must be valid | When `timePeriod` is present, both `from` and `to` must be valid parsea","category":"blocker","line_end":11,"severity":"low","line_start":11},{"id":"blocker:cost-forecast/guardrails.md:12:system-reconnaissance","file":"cost-forecast/guardrails.md","pattern":"System reconnaissance","snippet":"| Monthly + includeActualCost | Monthly granularity with `includeActualCost=true` requires an explic","category":"blocker","line_end":12,"severity":"low","line_start":12},{"id":"blocker:cost-forecast/guardrails.md:68:system-reconnaissance","file":"cost-forecast/guardrails.md","pattern":"System reconnaissance","snippet":"> ⚠️ **Warning:** This is **not an error** — it is a valid response indicating the forecast model ca","category":"blocker","line_end":68,"severity":"low","line_start":68},{"id":"blocker:cost-forecast/request-body-schema.md:111:system-reconnaissance","file":"cost-forecast/request-body-schema.md","pattern":"System reconnaissance","snippet":"| `to` date | Must be in the future | Can be any valid past/present date |","category":"blocker","line_end":111,"severity":"low","line_start":111},{"id":"external_commands:cost-forecast/workflow.md:81:ruby-shell-backtick-execution","file":"cost-forecast/workflow.md","pattern":"Ruby/shell backtick execution","snippet":"--url \"/subscriptions/<subscription-id>/providers/Microsoft.CostManagement/forecast?api-version=2023","category":"external_commands","line_end":83,"severity":"medium","line_start":81},{"id":"external_commands:cost-forecast/workflow.md:77:powershell-invocation","file":"cost-forecast/workflow.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":77,"severity":"high","line_start":77},{"id":"filesystem:cost-forecast/workflow.md:5:path-traversal-sequence","file":"cost-forecast/workflow.md","pattern":"Path traversal sequence","snippet":"> ⚠️ **Warning:** If the user wants **historical** cost data, use the [Cost Query Workflow](../cost-","category":"filesystem","line_end":5,"severity":"high","line_start":5},{"id":"filesystem:cost-forecast/workflow.md:21:path-traversal-sequence","file":"cost-forecast/workflow.md","pattern":"Path traversal sequence","snippet":"Use the same scope patterns from the Scope Reference table in the main [SKILL.md](../SKILL.md#scope-","category":"filesystem","line_end":21,"severity":"high","line_start":21},{"id":"filesystem:cost-forecast/workflow.md:44:path-traversal-sequence","file":"cost-forecast/workflow.md","pattern":"Path traversal sequence","snippet":"> ⚠️ **Warning:** Grouping is **NOT supported** for forecast. Suggest using the [Cost Query Workflow","category":"filesystem","line_end":44,"severity":"high","line_start":44},{"id":"filesystem:cost-forecast/workflow.md:92:path-traversal-sequence","file":"cost-forecast/workflow.md","pattern":"Path traversal sequence","snippet":"> 💡 **Tip:** \"Forecast is unavailable for the specified time period\" is not an error — it means the","category":"filesystem","line_end":92,"severity":"high","line_start":92},{"id":"blocker:cost-forecast/workflow.md:114:system-reconnaissance","file":"cost-forecast/workflow.md","pattern":"System reconnaissance","snippet":"| 400 | Invalid dependency | Set `includeActualCost: true` when using `includeFreshPartialCost`. |","category":"blocker","line_end":114,"severity":"low","line_start":114},{"id":"external_commands:cost-optimization/auth-best-practices.md:16:powershell-invocation","file":"cost-optimization/auth-best-practices.md","pattern":"PowerShell invocation","snippet":"| **Local development** | `DefaultAzureCredential` | Chains CLI, PowerShell, and VS Code credentials","category":"external_commands","line_end":16,"severity":"high","line_start":16},{"id":"external_commands:cost-optimization/auth-best-practices.md:81:powershell-invocation","file":"cost-optimization/auth-best-practices.md","pattern":"PowerShell invocation","snippet":"3. **Azure PowerShell** — `Connect-AzAccount`","category":"external_commands","line_end":81,"severity":"high","line_start":81},{"id":"external_commands:cost-optimization/auth-best-practices.md:87:powershell-invocation","file":"cost-optimization/auth-best-practices.md","pattern":"PowerShell invocation","snippet":"// Local development only — uses CLI/PowerShell/VS Code credentials","category":"external_commands","line_end":87,"severity":"high","line_start":87},{"id":"env_access:cost-optimization/auth-best-practices.md:43:environment-variable-access-dot-notation","file":"cost-optimization/auth-best-practices.md","pattern":"Environment variable access (dot notation)","snippet":"const credential = process.env.NODE_ENV === \"development\"","category":"env_access","line_end":43,"severity":"low","line_start":43},{"id":"env_access:cost-optimization/auth-best-practices.md:101:environment-variable-access-dot-notation","file":"cost-optimization/auth-best-practices.md","pattern":"Environment variable access (dot notation)","snippet":"if (process.env.NODE_ENV === \"development\") {","category":"env_access","line_end":101,"severity":"low","line_start":101},{"id":"env_access:cost-optimization/auth-best-practices.md:104:environment-variable-access-dot-notation","file":"cost-optimization/auth-best-practices.md","pattern":"Environment variable access (dot notation)","snippet":"return process.env.AZURE_CLIENT_ID","category":"env_access","line_end":104,"severity":"low","line_start":104},{"id":"env_access:cost-optimization/auth-best-practices.md:105:environment-variable-access-dot-notation","file":"cost-optimization/auth-best-practices.md","pattern":"Environment variable access (dot notation)","snippet":"? new ManagedIdentityCredential(process.env.AZURE_CLIENT_ID)  // user-assigned","category":"env_access","line_end":105,"severity":"low","line_start":105},{"id":"env_access:cost-optimization/auth-best-practices.md:43:environment-variable-object","file":"cost-optimization/auth-best-practices.md","pattern":"Environment variable object","snippet":"const credential = process.env.NODE_ENV === \"development\"","category":"env_access","line_end":43,"severity":"low","line_start":43},{"id":"env_access:cost-optimization/auth-best-practices.md:101:environment-variable-object","file":"cost-optimization/auth-best-practices.md","pattern":"Environment variable object","snippet":"if (process.env.NODE_ENV === \"development\") {","category":"env_access","line_end":101,"severity":"low","line_start":101},{"id":"env_access:cost-optimization/auth-best-practices.md:104:environment-variable-object","file":"cost-optimization/auth-best-practices.md","pattern":"Environment variable object","snippet":"return process.env.AZURE_CLIENT_ID","category":"env_access","line_end":104,"severity":"low","line_start":104},{"id":"env_access:cost-optimization/auth-best-practices.md:105:environment-variable-object","file":"cost-optimization/auth-best-practices.md","pattern":"Environment variable object","snippet":"? new ManagedIdentityCredential(process.env.AZURE_CLIENT_ID)  // user-assigned","category":"env_access","line_end":105,"severity":"low","line_start":105},{"id":"env_access:cost-optimization/auth-best-practices.md:57:python-getenv-function","file":"cost-optimization/auth-best-practices.md","pattern":"Python getenv function","snippet":"if os.getenv(\"AZURE_FUNCTIONS_ENVIRONMENT\") == \"Development\"","category":"env_access","line_end":57,"severity":"low","line_start":57},{"id":"env_access:cost-optimization/auth-best-practices.md:57:getenv-function-call","file":"cost-optimization/auth-best-practices.md","pattern":"getenv function call","snippet":"if os.getenv(\"AZURE_FUNCTIONS_ENVIRONMENT\") == \"Development\"","category":"env_access","line_end":57,"severity":"low","line_start":57},{"id":"env_access:cost-optimization/auth-best-practices.md:69:getenv-function-call","file":"cost-optimization/auth-best-practices.md","pattern":"getenv function call","snippet":"var credential = \"Development\".equals(System.getenv(\"AZURE_FUNCTIONS_ENVIRONMENT\"))","category":"env_access","line_end":69,"severity":"low","line_start":69},{"id":"env_access:cost-optimization/auth-best-practices.md:104:azure-credential-environment-variables","file":"cost-optimization/auth-best-practices.md","pattern":"Azure credential environment variables","snippet":"return process.env.AZURE_CLIENT_ID","category":"env_access","line_end":104,"severity":"high","line_start":104},{"id":"env_access:cost-optimization/auth-best-practices.md:105:azure-credential-environment-variables","file":"cost-optimization/auth-best-practices.md","pattern":"Azure credential environment variables","snippet":"? new ManagedIdentityCredential(process.env.AZURE_CLIENT_ID)  // user-assigned","category":"env_access","line_end":105,"severity":"high","line_start":105},{"id":"sensitive:cost-optimization/auth-best-practices.md:43:environment-file-access","file":"cost-optimization/auth-best-practices.md","pattern":"Environment file access","snippet":"const credential = process.env.NODE_ENV === \"development\"","category":"sensitive","line_end":43,"severity":"high","line_start":43},{"id":"sensitive:cost-optimization/auth-best-practices.md:101:environment-file-access","file":"cost-optimization/auth-best-practices.md","pattern":"Environment file access","snippet":"if (process.env.NODE_ENV === \"development\") {","category":"sensitive","line_end":101,"severity":"high","line_start":101},{"id":"sensitive:cost-optimization/auth-best-practices.md:104:environment-file-access","file":"cost-optimization/auth-best-practices.md","pattern":"Environment file access","snippet":"return process.env.AZURE_CLIENT_ID","category":"sensitive","line_end":104,"severity":"high","line_start":104},{"id":"sensitive:cost-optimization/auth-best-practices.md:105:environment-file-access","file":"cost-optimization/auth-best-practices.md","pattern":"Environment file access","snippet":"? new ManagedIdentityCredential(process.env.AZURE_CLIENT_ID)  // user-assigned","category":"sensitive","line_end":105,"severity":"high","line_start":105},{"id":"network:cost-optimization/azure-aks-anomalies.md:13:hardcoded-url","file":"cost-optimization/azure-aks-anomalies.md","pattern":"Hardcoded URL","snippet":"--url \"https://management.azure.com/subscriptions/<subscription-id>/resourceGroups/<resource-group>/","category":"network","line_end":13,"severity":"low","line_start":13},{"id":"blocker:cost-optimization/azure-aks-anomalies.md:7:system-reconnaissance","file":"cost-optimization/azure-aks-anomalies.md","pattern":"System reconnaissance","snippet":"Ask the user: \"When did you notice the spike? (e.g., 'last Tuesday', 'between 2 AM and 4 AM yesterda","category":"blocker","line_end":7,"severity":"low","line_start":7},{"id":"external_commands:cost-optimization/azure-quick-review.md:25:powershell-invocation","file":"cost-optimization/azure-quick-review.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":25,"severity":"high","line_start":25},{"id":"external_commands:cost-optimization/report-template.md:47:ruby-shell-backtick-execution","file":"cost-optimization/report-template.md","pattern":"Ruby/shell backtick execution","snippet":"- Cost Query Results: `output/cost-query-result<timestamp>.json`","category":"external_commands","line_end":49,"severity":"medium","line_start":47},{"id":"external_commands:cost-optimization/report-template.md:67:powershell-invocation","file":"cost-optimization/report-template.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":67,"severity":"high","line_start":67},{"id":"network:cost-optimization/report-template.md:56:hardcoded-url","file":"cost-optimization/report-template.md","pattern":"Hardcoded URL","snippet":"https://portal.azure.com/#@<TENANT_ID>/resource/subscriptions/<SUBSCRIPTION_ID>/resourceGroups/<RESO","category":"network","line_end":56,"severity":"low","line_start":56},{"id":"filesystem:cost-optimization/sdk/azure-resource-manager-redis-dotnet.md:13:path-traversal-sequence","file":"cost-optimization/sdk/azure-resource-manager-redis-dotnet.md","pattern":"Path traversal sequence","snippet":"> **Auth:** `DefaultAzureCredential` is for local development. See [auth-best-practices.md](../auth-","category":"filesystem","line_end":13,"severity":"high","line_start":13},{"id":"filesystem:cost-optimization/sdk/azure-resource-manager-redis-dotnet.md:24:path-traversal-sequence","file":"cost-optimization/sdk/azure-resource-manager-redis-dotnet.md","pattern":"Path traversal sequence","snippet":"- Use DefaultAzureCredential for **local development only**. In production, use ManagedIdentityCrede","category":"filesystem","line_end":24,"severity":"high","line_start":24},{"id":"external_commands:cost-optimization/workflow.md:176:ruby-shell-backtick-execution","file":"cost-optimization/workflow.md","pattern":"Ruby/shell backtick execution","snippet":"--resource \"<RESOURCE_ID>\" `","category":"external_commands","line_end":177,"severity":"medium","line_start":176},{"id":"external_commands:cost-optimization/workflow.md:178:ruby-shell-backtick-execution","file":"cost-optimization/workflow.md","pattern":"Ruby/shell backtick execution","snippet":"--interval PT1H `","category":"external_commands","line_end":179,"severity":"medium","line_start":178},{"id":"external_commands:cost-optimization/workflow.md:180:ruby-shell-backtick-execution","file":"cost-optimization/workflow.md","pattern":"Ruby/shell backtick execution","snippet":"--start-time $startTime `","category":"external_commands","line_end":182,"severity":"medium","line_start":180},{"id":"external_commands:cost-optimization/workflow.md:20:powershell-invocation","file":"cost-optimization/workflow.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":20,"severity":"high","line_start":20},{"id":"external_commands:cost-optimization/workflow.md:112:powershell-invocation","file":"cost-optimization/workflow.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":112,"severity":"high","line_start":112},{"id":"external_commands:cost-optimization/workflow.md:170:powershell-invocation","file":"cost-optimization/workflow.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":170,"severity":"high","line_start":170},{"id":"filesystem:cost-optimization/workflow.md:5:path-traversal-sequence","file":"cost-optimization/workflow.md","pattern":"Path traversal sequence","snippet":"> **Important:** Always present the total bill and cost breakdown (from the [Cost Query Workflow](..","category":"filesystem","line_end":5,"severity":"high","line_start":5},{"id":"filesystem:cost-optimization/workflow.md:119:path-traversal-sequence","file":"cost-optimization/workflow.md","pattern":"Path traversal sequence","snippet":"Get actual cost data from Azure Cost Management API (last 30 days). Use the [Cost Query Workflow](..","category":"filesystem","line_end":119,"severity":"high","line_start":119},{"id":"filesystem:cost-optimization/workflow.md:152:path-traversal-sequence","file":"cost-optimization/workflow.md","pattern":"Path traversal sequence","snippet":"> 💡 **Tip:** Also run a cost-by-service query (grouping by `ServiceName`) to present the total bill","category":"filesystem","line_end":152,"severity":"high","line_start":152},{"id":"blocker:cost-query/dimensions-by-scope.md:64:system-reconnaissance","file":"cost-query/dimensions-by-scope.md","pattern":"System reconnaissance","snippet":"Available dimensions vary by agreement type. Only dimensions listed for your agreement type are vali","category":"blocker","line_end":64,"severity":"low","line_start":64},{"id":"blocker:cost-query/dimensions-by-scope.md:180:system-reconnaissance","file":"cost-query/dimensions-by-scope.md","pattern":"System reconnaissance","snippet":"| `AgreementType` | The agreement type (`EA`, `MCA`, `MOSP`). | Determines valid dimension set. |","category":"blocker","line_end":180,"severity":"low","line_start":180},{"id":"blocker:cost-query/error-handling.md:9:system-reconnaissance","file":"cost-query/error-handling.md","pattern":"System reconnaissance","snippet":"| 400 | `BadRequest` | Invalid request body, unsupported dimension, date range exceeds limits, malfo","category":"blocker","line_end":9,"severity":"low","line_start":9},{"id":"blocker:cost-query/error-handling.md:21:system-reconnaissance","file":"cost-query/error-handling.md","pattern":"System reconnaissance","snippet":"| \"Dimension Z is not valid for scope\" | The requested dimension is not available for the current sc","category":"blocker","line_end":21,"severity":"low","line_start":21},{"id":"blocker:cost-query/error-handling.md:23:system-reconnaissance","file":"cost-query/error-handling.md","pattern":"System reconnaissance","snippet":"| Date range exceeds granularity limit | `Daily` range > 31 days or `Monthly`/`None` range > 12 mont","category":"blocker","line_end":23,"severity":"low","line_start":23},{"id":"blocker:cost-query/error-handling.md:26:system-reconnaissance","file":"cost-query/error-handling.md","pattern":"System reconnaissance","snippet":"| Invalid filter structure | `And`/`Or` has fewer than 2 child expressions, or `Not` has more than 1","category":"blocker","line_end":26,"severity":"low","line_start":26},{"id":"blocker:cost-query/error-handling.md:28:system-reconnaissance","file":"cost-query/error-handling.md","pattern":"System reconnaissance","snippet":"| `BillingSubscriptionNotFound` | The subscription ID in the scope URL is invalid or not associated ","category":"blocker","line_end":28,"severity":"low","line_start":28},{"id":"filesystem:cost-query/examples.md:3:path-traversal-sequence","file":"cost-query/examples.md","pattern":"Path traversal sequence","snippet":"Common query patterns with request bodies. Use the [SKILL.md workflow](../SKILL.md) to construct and","category":"filesystem","line_end":3,"severity":"high","line_start":3},{"id":"blocker:cost-query/guardrails.md:3:system-reconnaissance","file":"cost-query/guardrails.md","pattern":"System reconnaissance","snippet":"Detailed validation rules and guardrails for the Cost Management Query API. The system applies these","category":"blocker","line_end":3,"severity":"low","line_start":3},{"id":"blocker:cost-query/guardrails.md:95:system-reconnaissance","file":"cost-query/guardrails.md","pattern":"System reconnaissance","snippet":"Dimensions must be valid for the intersection of the agreement type **and** scope type.","category":"blocker","line_end":95,"severity":"low","line_start":95},{"id":"blocker:cost-query/guardrails.md:105:system-reconnaissance","file":"cost-query/guardrails.md","pattern":"System reconnaissance","snippet":"| Dimension not valid for agreement type | `BillingSubscriptionNotFound` or dimension validation err","category":"blocker","line_end":105,"severity":"low","line_start":105},{"id":"blocker:cost-query/guardrails.md:106:system-reconnaissance","file":"cost-query/guardrails.md","pattern":"System reconnaissance","snippet":"| Dimension not valid for scope type | `BadRequest` with invalid dimension message. |","category":"blocker","line_end":106,"severity":"low","line_start":106},{"id":"external_commands:cost-query/workflow.md:79:ruby-shell-backtick-execution","file":"cost-query/workflow.md","pattern":"Ruby/shell backtick execution","snippet":"--url \"<scope>/providers/Microsoft.CostManagement/query?api-version=2023-11-01\" `","category":"external_commands","line_end":81,"severity":"medium","line_start":79},{"id":"external_commands:cost-query/workflow.md:110:ruby-shell-backtick-execution","file":"cost-query/workflow.md","pattern":"Ruby/shell backtick execution","snippet":"--url \"/subscriptions/<subscription-id>/providers/Microsoft.CostManagement/query?api-version=2023-11","category":"external_commands","line_end":124,"severity":"medium","line_start":110},{"id":"external_commands:cost-query/workflow.md:73:powershell-invocation","file":"cost-query/workflow.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":73,"severity":"high","line_start":73},{"id":"external_commands:cost-query/workflow.md:108:powershell-invocation","file":"cost-query/workflow.md","pattern":"PowerShell invocation","snippet":"```powershell","category":"external_commands","line_end":108,"severity":"high","line_start":108},{"id":"filesystem:cost-query/workflow.md:7:path-traversal-sequence","file":"cost-query/workflow.md","pattern":"Path traversal sequence","snippet":"Identify the Azure scope for the cost query from the Scope Reference table in the main [SKILL.md](..","category":"filesystem","line_end":7,"severity":"high","line_start":7},{"id":"blocker:cost-query/workflow.md:132:system-reconnaissance","file":"cost-query/workflow.md","pattern":"System reconnaissance","snippet":"| 400 | Invalid request body | Check schema, date ranges, and dimension compatibility. |","category":"blocker","line_end":132,"severity":"low","line_start":132},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Query API Endpoint** | `POST {scope}/providers/Microsoft.CostManagement/query?api-version=2023-1","category":"external_commands","line_end":30,"severity":"medium","line_start":30},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **Forecast API Endpoint** | `POST {scope}/providers/Microsoft.CostManagement/forecast?api-version=","category":"external_commands","line_end":31,"severity":"medium","line_start":31},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **MCP Tools** | `azure__documentation`, `azure__extension_cli_generate`, `azure__get_azure_bestpra","category":"external_commands","line_end":32,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| **CLI** | `az rest`, `az monitor metrics list`, `az resource list` |","category":"external_commands","line_end":33,"severity":"medium","line_start":33},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `azure__documentation` | Search Azure documentation | `query` (Required): search terms | Research ","category":"external_commands","line_end":40,"severity":"medium","line_start":40},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `azure__extension_cli_generate` | Generate Azure CLI commands | `intent` (Required): task descript","category":"external_commands","line_end":41,"severity":"medium","line_start":41},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `azure__get_azure_bestpractices` | Get Azure best practices | `intent` (Required): optimization co","category":"external_commands","line_end":42,"severity":"medium","line_start":42},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `azure__extension_azqr` | Run Azure Quick Review compliance scan | `subscription` (Required): subs","category":"external_commands","line_end":43,"severity":"medium","line_start":43},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `azure__aks` | Azure Kubernetes Service operations | varies by sub-command | AKS cost analysis: li","category":"external_commands","line_end":44,"severity":"medium","line_start":44},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"> 💡 **Tip:** Prefer MCP tools over direct CLI commands. Use `az rest` only when MCP tools don't cov","category":"external_commands","line_end":46,"severity":"medium","line_start":46},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Subscription | `/subscriptions/<subscription-id>` |","category":"external_commands","line_end":69,"severity":"medium","line_start":69},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Resource Group | `/subscriptions/<subscription-id>/resourceGroups/<resource-group-name>` |","category":"external_commands","line_end":70,"severity":"medium","line_start":70},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Management Group | `/providers/Microsoft.Management/managementGroups/<management-group-id>` |","category":"external_commands","line_end":71,"severity":"medium","line_start":71},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Billing Account | `/providers/Microsoft.Billing/billingAccounts/<billing-account-id>` |","category":"external_commands","line_end":72,"severity":"medium","line_start":72},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| Billing Profile | `/providers/Microsoft.Billing/billingAccounts/<billing-account-id>/billingProfil","category":"external_commands","line_end":73,"severity":"medium","line_start":73},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- Use REST API for cost queries (more reliable than `az costmanagement query`)","category":"external_commands","line_end":115,"severity":"medium","line_start":115},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"- **Cost query failures**: Use `az rest` with JSON body, not `az costmanagement query`","category":"external_commands","line_end":127,"severity":"medium","line_start":127}],"finding_verdicts":[{"id":"blocker:cost-forecast/error-handling.md:7:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-forecast/error-handling.md:10:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-forecast/error-handling.md:20:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-forecast/error-handling.md:22:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-forecast/error-handling.md:23:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-forecast/error-handling.md:31:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:cost-forecast/examples.md:3:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"blocker:cost-forecast/guardrails.md:11:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-forecast/guardrails.md:12:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-forecast/guardrails.md:68:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-forecast/request-body-schema.md:111:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:cost-forecast/workflow.md:81:ruby-shell-backtick-execution","reason":"The match is PowerShell line-continuation syntax or a backticked file path inside documentation, not Ruby shell execution. The surrounding examples are explicit Azure cost-analysis commands with fixed methods and placeholders.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:cost-forecast/workflow.md:77:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"filesystem:cost-forecast/workflow.md:5:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:cost-forecast/workflow.md:21:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:cost-forecast/workflow.md:44:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:cost-forecast/workflow.md:92:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"blocker:cost-forecast/workflow.md:114:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:cost-optimization/auth-best-practices.md:16:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:cost-optimization/auth-best-practices.md:81:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:cost-optimization/auth-best-practices.md:87:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"env_access:cost-optimization/auth-best-practices.md:43:environment-variable-access-dot-notation","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:101:environment-variable-access-dot-notation","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:104:environment-variable-access-dot-notation","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:105:environment-variable-access-dot-notation","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:43:environment-variable-object","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:101:environment-variable-object","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:104:environment-variable-object","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:105:environment-variable-object","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:57:python-getenv-function","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:57:getenv-function-call","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:69:getenv-function-call","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:104:azure-credential-environment-variables","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"env_access:cost-optimization/auth-best-practices.md:105:azure-credential-environment-variables","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"sensitive:cost-optimization/auth-best-practices.md:43:environment-file-access","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"sensitive:cost-optimization/auth-best-practices.md:101:environment-file-access","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"sensitive:cost-optimization/auth-best-practices.md:104:environment-file-access","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"sensitive:cost-optimization/auth-best-practices.md:105:environment-file-access","reason":"This is an authentication best-practice example that selects credentials by runtime environment. It does not read environment files, expose secrets, or transmit credentials, and it recommends managed identity.","verdict":"false_positive","confidence":0.93},{"id":"network:cost-optimization/azure-aks-anomalies.md:13:hardcoded-url","reason":"The URL is an official Azure management or portal endpoint used for the expected cost-management workflow. It is not an unknown callback or data exfiltration destination.","verdict":"false_positive","confidence":0.92},{"id":"blocker:cost-optimization/azure-aks-anomalies.md:7:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:cost-optimization/azure-quick-review.md:25:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:cost-optimization/report-template.md:47:ruby-shell-backtick-execution","reason":"The match is PowerShell line-continuation syntax or a backticked file path inside documentation, not Ruby shell execution. The surrounding examples are explicit Azure cost-analysis commands with fixed methods and placeholders.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:cost-optimization/report-template.md:67:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"network:cost-optimization/report-template.md:56:hardcoded-url","reason":"The URL is an official Azure management or portal endpoint used for the expected cost-management workflow. It is not an unknown callback or data exfiltration destination.","verdict":"false_positive","confidence":0.92},{"id":"filesystem:cost-optimization/sdk/azure-resource-manager-redis-dotnet.md:13:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:cost-optimization/sdk/azure-resource-manager-redis-dotnet.md:24:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:cost-optimization/workflow.md:176:ruby-shell-backtick-execution","reason":"The match is PowerShell line-continuation syntax or a backticked file path inside documentation, not Ruby shell execution. The surrounding examples are explicit Azure cost-analysis commands with fixed methods and placeholders.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:cost-optimization/workflow.md:178:ruby-shell-backtick-execution","reason":"The match is PowerShell line-continuation syntax or a backticked file path inside documentation, not Ruby shell execution. The surrounding examples are explicit Azure cost-analysis commands with fixed methods and placeholders.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:cost-optimization/workflow.md:180:ruby-shell-backtick-execution","reason":"The match is PowerShell line-continuation syntax or a backticked file path inside documentation, not Ruby shell execution. The surrounding examples are explicit Azure cost-analysis commands with fixed methods and placeholders.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:cost-optimization/workflow.md:20:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:cost-optimization/workflow.md:112:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:cost-optimization/workflow.md:170:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"filesystem:cost-optimization/workflow.md:5:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:cost-optimization/workflow.md:119:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"filesystem:cost-optimization/workflow.md:152:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"blocker:cost-query/dimensions-by-scope.md:64:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-query/dimensions-by-scope.md:180:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-query/error-handling.md:9:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-query/error-handling.md:21:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-query/error-handling.md:23:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-query/error-handling.md:26:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-query/error-handling.md:28:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"filesystem:cost-query/examples.md:3:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"blocker:cost-query/guardrails.md:3:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-query/guardrails.md:95:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-query/guardrails.md:105:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"blocker:cost-query/guardrails.md:106:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:cost-query/workflow.md:79:ruby-shell-backtick-execution","reason":"The match is PowerShell line-continuation syntax or a backticked file path inside documentation, not Ruby shell execution. The surrounding examples are explicit Azure cost-analysis commands with fixed methods and placeholders.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:cost-query/workflow.md:110:ruby-shell-backtick-execution","reason":"The match is PowerShell line-continuation syntax or a backticked file path inside documentation, not Ruby shell execution. The surrounding examples are explicit Azure cost-analysis commands with fixed methods and placeholders.","verdict":"false_positive","confidence":0.91},{"id":"external_commands:cost-query/workflow.md:73:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"external_commands:cost-query/workflow.md:108:powershell-invocation","reason":"The line is a Markdown code-fence label for an explicit Azure CLI example, not an automatic invocation. The documented commands use authenticated Azure tooling with placeholders for user-approved scopes.","verdict":"false_positive","confidence":0.89},{"id":"filesystem:cost-query/workflow.md:7:path-traversal-sequence","reason":"The path traversal sequence appears in a Markdown cross-reference between skill documents. There is no filesystem read, write, delete, or user-controlled path operation.","verdict":"false_positive","confidence":0.96},{"id":"blocker:cost-query/workflow.md:132:system-reconnaissance","reason":"This line documents Azure Cost Management API validation, scope, or error behavior, not local system reconnaissance. It does not request host details, secrets, users, or network inventory.","verdict":"false_positive","confidence":0.94},{"id":"external_commands:SKILL.md:30:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:31:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:33:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:40:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:41:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:42:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:43:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:44:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:46:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:69:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:70:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:71:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:72:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:73:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:115:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92},{"id":"external_commands:SKILL.md:127:ruby-shell-backtick-execution","reason":"The match is inline Markdown naming Azure endpoints, MCP tools, scope paths, or CLI names. It is not executable package code or hidden command execution.","verdict":"false_positive","confidence":0.92}],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}