{"data":{"skill":{"slug":"sickn33-azure-mgmt-apimanagement-dotnet","name":"azure-mgmt-apimanagement-dotnet","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/azure-mgmt-apimanagement-dotnet","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"bb456221-a7ca-4db9-aee8-51bf6debd5a8","skill_id":"5db7edbd-8a9d-4861-9d00-cf4c510e3494","version":5,"content_hash":"v3:f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526:61a285e3acc9e9b9f06dfa57f6a50302f949d02e719ca7e3265f652e04290d94:41536dc26cc92e0cf922f6df95b481ccc672a02c1ed3a8331eab5715a5a156f7:736b696c6c732f7369636b6e33332f617a7572652d6d676d742d6170696d616e6167656d656e742d646f746e6574:ea0c615bd130226c013556616ce1eb3f","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"All 51 static findings are false positives caused by Markdown formatting, placeholder configuration, sample URLs, or official documentation links. The skill contains no prompt injection or covert execution behavior. One high-severity semantic issue remains: an example prints an APIM subscription key to console output.","remediation":[{"issue":"The subscription example prints the primary key to console output.","severity":"high","suggestion":"Remove the key output and demonstrate secure storage or direct secret consumption without logging the value."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":22,"line_start":19},{"file":"SKILL.md","line_end":28,"line_start":22},{"file":"SKILL.md","line_end":34,"line_start":28},{"file":"SKILL.md","line_end":38,"line_start":34},{"file":"SKILL.md","line_end":51,"line_start":38},{"file":"SKILL.md","line_end":55,"line_start":51},{"file":"SKILL.md","line_end":79,"line_start":55},{"file":"SKILL.md","line_end":85,"line_start":79},{"file":"SKILL.md","line_end":110,"line_start":85},{"file":"SKILL.md","line_end":114,"line_start":110},{"file":"SKILL.md","line_end":130,"line_start":114},{"file":"SKILL.md","line_end":134,"line_start":130},{"file":"SKILL.md","line_end":157,"line_start":134},{"file":"SKILL.md","line_end":161,"line_start":157},{"file":"SKILL.md","line_end":180,"line_start":161},{"file":"SKILL.md","line_end":184,"line_start":180},{"file":"SKILL.md","line_end":214,"line_start":184},{"file":"SKILL.md","line_end":218,"line_start":214},{"file":"SKILL.md","line_end":232,"line_start":218},{"file":"SKILL.md","line_end":238,"line_start":232},{"file":"SKILL.md","line_end":239,"line_start":238},{"file":"SKILL.md","line_end":240,"line_start":239},{"file":"SKILL.md","line_end":241,"line_start":240},{"file":"SKILL.md","line_end":242,"line_start":241},{"file":"SKILL.md","line_end":243,"line_start":242},{"file":"SKILL.md","line_end":244,"line_start":243},{"file":"SKILL.md","line_end":245,"line_start":244},{"file":"SKILL.md","line_end":246,"line_start":245},{"file":"SKILL.md","line_end":247,"line_start":246},{"file":"SKILL.md","line_end":248,"line_start":247},{"file":"SKILL.md","line_end":249,"line_start":248},{"file":"SKILL.md","line_end":255,"line_start":249},{"file":"SKILL.md","line_end":256,"line_start":255},{"file":"SKILL.md","line_end":257,"line_start":256},{"file":"SKILL.md","line_end":258,"line_start":257},{"file":"SKILL.md","line_end":259,"line_start":258},{"file":"SKILL.md","line_end":263,"line_start":259},{"file":"SKILL.md","line_end":264,"line_start":263},{"file":"SKILL.md","line_end":265,"line_start":264},{"file":"SKILL.md","line_end":266,"line_start":265},{"file":"SKILL.md","line_end":267,"line_start":266},{"file":"SKILL.md","line_end":268,"line_start":267},{"file":"SKILL.md","line_end":268,"line_start":268},{"file":"SKILL.md","line_end":294,"line_start":274}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":120,"line_start":120},{"file":"SKILL.md","line_end":309,"line_start":309},{"file":"SKILL.md","line_end":310,"line_start":310},{"file":"SKILL.md","line_end":311,"line_start":311}]},{"factor":"env_access","evidence":[{"file":"SKILL.md","line_end":31,"line_start":31},{"file":"SKILL.md","line_end":32,"line_start":32},{"file":"SKILL.md","line_end":33,"line_start":33}]}],"critical_findings":[],"high_findings":[{"title":"Sensitive Subscription Key Logging","locations":[{"file":"SKILL.md","line_end":179,"line_start":177}],"confidence":0.99,"description":"The example retrieves APIM subscription secrets and prints the primary key, which can expose credentials in terminal output or captured logs.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"Lines 177-179 explicitly retrieve subscription secrets and send the primary key to Console.WriteLine, creating a direct credential-disclosure path."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":320,"audit_model":"codex","audited_at":"2026-07-23T21:02:16.751+00:00","created_at":"2026-07-26T05:23:57.483877+00:00","static_findings":[{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":22,"severity":"medium","line_start":19},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":28,"severity":"medium","line_start":22},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":34,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":38,"severity":"medium","line_start":34},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":51,"severity":"medium","line_start":38},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":55,"severity":"medium","line_start":51},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":79,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":85,"severity":"medium","line_start":79},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":110,"severity":"medium","line_start":85},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":114,"severity":"medium","line_start":110},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":130,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":134,"severity":"medium","line_start":130},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":157,"severity":"medium","line_start":134},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":161,"severity":"medium","line_start":157},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":180,"severity":"medium","line_start":161},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":184,"severity":"medium","line_start":180},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":214,"severity":"medium","line_start":184},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":218,"severity":"medium","line_start":214},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":232,"severity":"medium","line_start":218},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":238,"severity":"medium","line_start":232},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ArmClient` | Entry point for all ARM operations |","category":"external_commands","line_end":239,"severity":"medium","line_start":238},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiManagementServiceResource` | Represents an APIM service instance |","category":"external_commands","line_end":240,"severity":"medium","line_start":239},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiManagementServiceCollection` | Collection for service CRUD |","category":"external_commands","line_end":241,"severity":"medium","line_start":240},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiResource` | Represents an API |","category":"external_commands","line_end":242,"severity":"medium","line_start":241},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiManagementProductResource` | Represents a product |","category":"external_commands","line_end":243,"severity":"medium","line_start":242},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiManagementSubscriptionResource` | Represents a subscription |","category":"external_commands","line_end":244,"severity":"medium","line_start":243},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiManagementPolicyResource` | Service-level policy |","category":"external_commands","line_end":245,"severity":"medium","line_start":244},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiPolicyResource` | API-level policy |","category":"external_commands","line_end":246,"severity":"medium","line_start":245},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiManagementUserResource` | Represents a user |","category":"external_commands","line_end":247,"severity":"medium","line_start":246},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiManagementGroupResource` | Represents a group |","category":"external_commands","line_end":248,"severity":"medium","line_start":247},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiManagementBackendResource` | Represents a backend service |","category":"external_commands","line_end":249,"severity":"medium","line_start":248},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ApiManagementGatewayResource` | Represents a self-hosted gateway |","category":"external_commands","line_end":255,"severity":"medium","line_start":249},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Developer` | Development/testing (no SLA) | 1 |","category":"external_commands","line_end":256,"severity":"medium","line_start":255},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Basic` | Entry-level production | 1-2 |","category":"external_commands","line_end":257,"severity":"medium","line_start":256},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Standard` | Medium workloads | 1-4 |","category":"external_commands","line_end":258,"severity":"medium","line_start":257},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Premium` | High availability, multi-region | 1-12 per region |","category":"external_commands","line_end":259,"severity":"medium","line_start":258},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Consumption` | Serverless, pay-per-call | N/A |","category":"external_commands","line_end":263,"severity":"medium","line_start":259},{"id":"external_commands:SKILL.md:263:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Use `WaitUntil.Completed`** for operations that must finish before proceeding","category":"external_commands","line_end":264,"severity":"medium","line_start":263},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"2. **Use `WaitUntil.Started`** for long operations like service creation (30+ min)","category":"external_commands","line_end":265,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Always use `DefaultAzureCredential`** — never hardcode keys","category":"external_commands","line_end":266,"severity":"medium","line_start":265},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"4. **Handle `RequestFailedException`** for ARM API errors","category":"external_commands","line_end":267,"severity":"medium","line_start":266},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Use `CreateOrUpdateAsync`** for idempotent operations","category":"external_commands","line_end":268,"severity":"medium","line_start":267},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Navigate hierarchy** via `Get*` methods (e.g., `service.GetApis()`)","category":"external_commands","line_end":268,"severity":"medium","line_start":268},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":294,"severity":"medium","line_start":274},{"id":"network:SKILL.md:120:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"ServiceUri = new Uri(\"https://backend.contoso.com/api\")","category":"network","line_end":120,"severity":"low","line_start":120},{"id":"network:SKILL.md:309:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| [API Management Documentation](https://learn.microsoft.com/en-us/azure/api-management/) | Official","category":"network","line_end":309,"severity":"low","line_start":309},{"id":"network:SKILL.md:310:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| [Policy Reference](https://learn.microsoft.com/en-us/azure/api-management/api-management-policies)","category":"network","line_end":310,"severity":"low","line_start":310},{"id":"network:SKILL.md:311:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| [SDK Reference](https://learn.microsoft.com/en-us/dotnet/api/azure.resourcemanager.apimanagement) ","category":"network","line_end":311,"severity":"low","line_start":311},{"id":"env_access:SKILL.md:31:azure-credential-environment-variables","file":"SKILL.md","pattern":"Azure credential environment variables","snippet":"AZURE_TENANT_ID=<tenant-id>","category":"env_access","line_end":31,"severity":"high","line_start":31},{"id":"env_access:SKILL.md:32:azure-credential-environment-variables","file":"SKILL.md","pattern":"Azure credential environment variables","snippet":"AZURE_CLIENT_ID=<client-id>","category":"env_access","line_end":32,"severity":"high","line_start":32},{"id":"env_access:SKILL.md:33:azure-credential-environment-variables","file":"SKILL.md","pattern":"Azure credential environment variables","snippet":"AZURE_CLIENT_SECRET=<client-secret>","category":"env_access","line_end":33,"severity":"high","line_start":33}],"finding_verdicts":[{"id":"external_commands:SKILL.md:19:ruby-shell-backtick-execution","reason":"The match is a Markdown fence around fixed dotnet package installation commands, not Ruby backtick execution or dynamic command construction.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:22:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown Bash example containing placeholder environment assignments; they do not execute a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:34:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:38:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown C# example; they are documentation syntax and do not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:51:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The matched backticks delimit a plain-text resource hierarchy diagram, with no executable command or Ruby expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:79:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:85:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown C# example; they are documentation syntax and do not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:110:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown C# example; they are documentation syntax and do not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:130:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:134:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown C# example; they are documentation syntax and do not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:157:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:161:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown C# example; they are documentation syntax and do not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:180:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:184:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown C# example; they are documentation syntax and do not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:214:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:218:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown C# example; they are documentation syntax and do not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:232:ruby-shell-backtick-execution","reason":"The match is a Markdown code-block delimiter in documentation, not a Ruby backtick operator or executable shell construct.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:238:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:239:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:240:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:241:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:242:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:243:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:244:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:245:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:246:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:247:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:248:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:249:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:255:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:256:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:257:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:258:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:259:ruby-shell-backtick-execution","reason":"The backticks format a type or SKU name inside a Markdown table; the text is not evaluated or executed.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:263:ruby-shell-backtick-execution","reason":"The backticks format an API identifier in Markdown prose; they do not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The backticks format an API identifier in Markdown prose; they do not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:265:ruby-shell-backtick-execution","reason":"The backticks format an API identifier in Markdown prose; they do not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:266:ruby-shell-backtick-execution","reason":"The backticks format an API identifier in Markdown prose; they do not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:267:ruby-shell-backtick-execution","reason":"The backticks format an API identifier in Markdown prose; they do not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:268:ruby-shell-backtick-execution","reason":"The backticks format an API identifier in Markdown prose; they do not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:274:ruby-shell-backtick-execution","reason":"The matched backticks open a Markdown C# example; they are documentation syntax and do not invoke a shell or Ruby runtime.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:120:hardcoded-url","reason":"The URL uses the reserved contoso.com example domain as a placeholder backend in sample C# and does not transmit data by itself.","verdict":"false_positive","confidence":0.98},{"id":"network:SKILL.md:309:hardcoded-url","reason":"The URL is an official learn.microsoft.com documentation reference, not a hidden request, webhook, or data-exfiltration endpoint.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:310:hardcoded-url","reason":"The URL is an official learn.microsoft.com documentation reference, not a hidden request, webhook, or data-exfiltration endpoint.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:311:hardcoded-url","reason":"The URL is an official learn.microsoft.com documentation reference, not a hidden request, webhook, or data-exfiltration endpoint.","verdict":"false_positive","confidence":0.99},{"id":"env_access:SKILL.md:31:azure-credential-environment-variables","reason":"The line documents a placeholder Azure credential variable with no real secret value, automatic access, transmission, or exfiltration behavior.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:32:azure-credential-environment-variables","reason":"The line documents a placeholder Azure credential variable with no real secret value, automatic access, transmission, or exfiltration behavior.","verdict":"false_positive","confidence":0.98},{"id":"env_access:SKILL.md:33:azure-credential-environment-variables","reason":"The line documents a placeholder Azure credential variable with no real secret value, automatic access, transmission, or exfiltration behavior.","verdict":"false_positive","confidence":0.98}],"semantic_findings":[{"title":"Sensitive Subscription Key Logging","severity":"high","locations":[{"file":"SKILL.md","line_end":179,"line_start":177}],"confidence":0.99,"description":"The example retrieves APIM subscription secrets and prints the primary key, which can expose credentials in terminal output or captured logs.","confidence_reasoning":"Lines 177-179 explicitly retrieve subscription secrets and send the primary key to Console.WriteLine, creating a direct credential-disclosure path."}],"subject_marketplace_commit_sha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","subject_content_hash":"61a285e3acc9e9b9f06dfa57f6a50302f949d02e719ca7e3265f652e04290d94","subject_tree_hash":"41536dc26cc92e0cf922f6df95b481ccc672a02c1ed3a8331eab5715a5a156f7","subject_plugin_path":"skills/sickn33/azure-mgmt-apimanagement-dotnet","audit_payload_hash":"ea0c615bd130226c013556616ce1eb3f","confirmed_risk_level":"high","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","contentHash":"61a285e3acc9e9b9f06dfa57f6a50302f949d02e719ca7e3265f652e04290d94","treeHash":"41536dc26cc92e0cf922f6df95b481ccc672a02c1ed3a8331eab5715a5a156f7","pluginPath":"skills/sickn33/azure-mgmt-apimanagement-dotnet","auditPayloadHash":"ea0c615bd130226c013556616ce1eb3f"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-azure-mgmt-apimanagement-dotnet/audits/5/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}