{"data":{"skill":{"slug":"microsoft-azure-upgrade","name":"azure-upgrade","icon":"📦","repo":"https://github.com/microsoft/azure-skills/tree/main/.github/plugins/azure-skills/skills/azure-upgrade/","status":"approved","author":"microsoft","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"7177e07c-5bc0-465e-b64b-ea326c2b08e3","skill_id":"13237b37-fe34-44f6-8dfc-3bad91660935","version":1,"content_hash":"6d8cafe260d37b79fd618a72b57e8497","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"This is an official Microsoft skill providing Azure upgrade documentation. The static scanner detected patterns in markdown code examples - these are FALSE POSITIVES. The skill contains documentation with example Azure CLI commands, not executable code. All detected external_commands, network, and filesystem patterns are in documentation context. No actual code execution occurs - the skill provides guidance to Claude for helping users perform legitimate Azure upgrades.","remediation":[],"risk_factor_evidence":[],"critical_findings":[{"title":"False Positive: Code Execution + Network + Credential Access Heuristic","locations":[],"confidence":0.95,"description":"The static scanner flagged a CRITICAL heuristic for 'suspicious behavior patterns' (code execution + network + credential access). This is a FALSE POSITIVE - the skill is legitimate Microsoft documentation that describes Azure CLI commands for performing upgrades. The 'code execution' is bash/PowerShell examples in markdown documentation, 'network' is Azure API calls made by user-approved Azure CLI operations, and there is no credential exfiltration - the skill uses official Azure MCP tools for authenticated operations.","confidence_reasoning":"This is an official Microsoft skill from the azure-skills repository. The detected patterns are documentation code blocks, not actual code execution. Azure operations are performed through official MCP tools with user authentication."}],"high_findings":[{"title":"False Positive: PowerShell Invocation Detection","locations":[{"file":"references/services/functions/automation.md","line_end":4,"line_start":4},{"file":"references/services/functions/automation.md","line_end":57,"line_start":57},{"file":"references/services/functions/automation.md","line_end":68,"line_start":68},{"file":"references/services/functions/consumption-to-flex.md","line_end":47,"line_start":47}],"confidence":0.92,"description":"Static scanner flagged 'PowerShell invocation' at multiple locations in automation.md and consumption-to-flex.md. These are FALSE POSITIVES - the findings are detecting PowerShell syntax in markdown documentation code blocks, not actual PowerShell execution. The skill provides example commands for users to run in their own Azure Cloud Shell.","confidence_reasoning":"These are documentation code blocks in markdown files - the skill is a documentation reference, not executable code. Users run these commands themselves in their Azure environment."},{"title":"False Positive: Weak Cryptographic Algorithm Detection","locations":[{"file":"references/global-rules.md","line_end":7,"line_start":5},{"file":"references/global-rules.md","line_end":35,"line_start":27},{"file":"SKILL.md","line_end":12,"line_start":3}],"confidence":0.88,"description":"Static scanner flagged 'Weak cryptographic algorithm' at various locations in global-rules.md, automation.md, consumption-to-flex.md, workflow-details.md, and SKILL.md. These are FALSE POSITIVES - the scanner is likely triggered by text mentioning hash functions or authentication methods in documentation context. The skill promotes identity-based authentication (managed identity, DefaultAzureCredential) as documented in global-rules.md.","confidence_reasoning":"The skill explicitly advocates for managed identity over connection strings. These findings are triggered by documentation text mentioning authentication concepts, not actual weak cryptography implementation."}],"medium_findings":[{"title":"False Positive: Shell Command Detection in Documentation","locations":[{"file":"references/services/functions/automation.md","line_end":20,"line_start":10},{"file":"references/services/functions/automation.md","line_end":110,"line_start":110},{"file":"references/services/functions/consumption-to-flex.md","line_end":27,"line_start":25},{"file":"SKILL.md","line_end":29,"line_start":28}],"confidence":0.95,"description":"Static scanner flagged 207 'Ruby/shell backtick execution' and 'Shell command substitution' findings across multiple files. These are FALSE POSITIVES - the findings are triggered by code blocks (backtick fences) in markdown documentation describing Azure CLI commands. The skill does not execute any commands - it provides documentation and guidance.","confidence_reasoning":"All 207 findings are in markdown documentation files. The skill uses markdown code fences to display example Azure CLI commands. No actual shell execution occurs - these are documentation examples for users to follow."},{"title":"False Positive: Network Hardcoded URL Detection","locations":[{"file":"references/services/functions/automation.md","line_end":6,"line_start":6},{"file":"references/services/functions/consumption-to-flex.md","line_end":6,"line_start":6}],"confidence":0.98,"description":"Static scanner flagged 'Hardcoded URL' findings at various locations. These are FALSE POSITIVES - the URLs point to official Microsoft Learn documentation (learn.microsoft.com), which is expected for an official Microsoft skill.","confidence_reasoning":"The hardcoded URLs are legitimate Microsoft Learn documentation links. This is expected and appropriate for an official Microsoft skill."},{"title":"False Positive: Filesystem Detection","locations":[{"file":"references/services/functions/automation.md","line_end":357,"line_start":357},{"file":"references/services/functions/automation.md","line_end":375,"line_start":375}],"confidence":0.9,"description":"Static scanner flagged 'Standard device file access' at locations in automation.md. These are FALSE POSITIVES - the findings are triggered by documentation text about file paths and logs, not actual filesystem operations.","confidence_reasoning":"These are documentation references to log files and output paths in example commands. No actual filesystem operations occur - the skill is documentation-only."}],"low_findings":[{"title":"False Positive: System Reconnaissance Detection","locations":[{"file":"references/services/functions/assessment.md","line_end":56,"line_start":20},{"file":"references/services/functions/automation.md","line_end":245,"line_start":91}],"confidence":0.85,"description":"Static scanner flagged 'System reconnaissance' findings at various locations. These are FALSE POSITIVES - the skill documents how to assess Azure resources (list apps, check compatibility) which is a legitimate upgrade assessment workflow, not system reconnaissance.","confidence_reasoning":"These findings are triggered by documentation describing Azure resource queries (list apps, check settings). This is standard Azure administration for upgrade assessment, not malicious reconnaissance."}],"dangerous_patterns":[],"files_scanned":6,"total_lines":955,"audit_model":"claude","audited_at":"2026-03-17T08:23:44.52+00:00","created_at":"2026-03-17T10:18:43.497812+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":7,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}