{"data":{"skill":{"slug":"sickn33-azure-security-keyvault-keys-dotnet","name":"azure-security-keyvault-keys-dotnet","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/azure-security-keyvault-keys-dotnet","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":2},"audit":{"id":"17db0ee1-ed3b-493e-ad6a-d5f5f6608422","skill_id":"b7414cda-d955-4b57-be29-4f66522ac0f6","version":6,"content_hash":"v3:f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526:547f100c9ce56ae7d5fdcf35faddfbe77aa5702b60f8d126b4717c77328f5713:71e784a1bcccaab16b1dfaa0f1bf52064bd0e7db51357751f1e48b772624deab:736b696c6c732f7369636b6e33332f617a7572652d73656375726974792d6b65797661756c742d6b6579732d646f746e6574:a2d64d4bda77446d8be535219ab3ca1f","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"All 82 static findings are false positives caused by Markdown formatting, expected Azure endpoints, and benign SDK terminology. The file is documentation only and contains no executable scripts, prompt injection, credential exfiltration, or malware behavior.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":18,"line_start":15},{"file":"SKILL.md","line_end":24,"line_start":18},{"file":"SKILL.md","line_end":28,"line_start":24},{"file":"SKILL.md","line_end":32,"line_start":28},{"file":"SKILL.md","line_end":49,"line_start":32},{"file":"SKILL.md","line_end":55,"line_start":49},{"file":"SKILL.md","line_end":63,"line_start":55},{"file":"SKILL.md","line_end":67,"line_start":63},{"file":"SKILL.md","line_end":74,"line_start":67},{"file":"SKILL.md","line_end":80,"line_start":74},{"file":"SKILL.md","line_end":114,"line_start":80},{"file":"SKILL.md","line_end":118,"line_start":114},{"file":"SKILL.md","line_end":139,"line_start":118},{"file":"SKILL.md","line_end":143,"line_start":139},{"file":"SKILL.md","line_end":150,"line_start":143},{"file":"SKILL.md","line_end":154,"line_start":150},{"file":"SKILL.md","line_end":167,"line_start":154},{"file":"SKILL.md","line_end":171,"line_start":167},{"file":"SKILL.md","line_end":179,"line_start":171},{"file":"SKILL.md","line_end":185,"line_start":179},{"file":"SKILL.md","line_end":196,"line_start":185},{"file":"SKILL.md","line_end":200,"line_start":196},{"file":"SKILL.md","line_end":215,"line_start":200},{"file":"SKILL.md","line_end":219,"line_start":215},{"file":"SKILL.md","line_end":233,"line_start":219},{"file":"SKILL.md","line_end":237,"line_start":233},{"file":"SKILL.md","line_end":260,"line_start":237},{"file":"SKILL.md","line_end":264,"line_start":260},{"file":"SKILL.md","line_end":277,"line_start":264},{"file":"SKILL.md","line_end":281,"line_start":277},{"file":"SKILL.md","line_end":298,"line_start":281},{"file":"SKILL.md","line_end":304,"line_start":298},{"file":"SKILL.md","line_end":305,"line_start":304},{"file":"SKILL.md","line_end":306,"line_start":305},{"file":"SKILL.md","line_end":307,"line_start":306},{"file":"SKILL.md","line_end":308,"line_start":307},{"file":"SKILL.md","line_end":309,"line_start":308},{"file":"SKILL.md","line_end":310,"line_start":309},{"file":"SKILL.md","line_end":311,"line_start":310},{"file":"SKILL.md","line_end":312,"line_start":311},{"file":"SKILL.md","line_end":313,"line_start":312},{"file":"SKILL.md","line_end":314,"line_start":313},{"file":"SKILL.md","line_end":315,"line_start":314},{"file":"SKILL.md","line_end":316,"line_start":315},{"file":"SKILL.md","line_end":317,"line_start":316},{"file":"SKILL.md","line_end":324,"line_start":317},{"file":"SKILL.md","line_end":325,"line_start":324},{"file":"SKILL.md","line_end":326,"line_start":325},{"file":"SKILL.md","line_end":327,"line_start":326},{"file":"SKILL.md","line_end":328,"line_start":327}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":27,"line_start":27},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"SKILL.md","line_end":194,"line_start":194},{"file":"SKILL.md","line_end":271,"line_start":271},{"file":"SKILL.md","line_end":404,"line_start":404},{"file":"SKILL.md","line_end":405,"line_start":405},{"file":"SKILL.md","line_end":406,"line_start":406},{"file":"SKILL.md","line_end":407,"line_start":407}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":416,"audit_model":"codex","audited_at":"2026-07-23T22:46:06.097+00:00","created_at":"2026-07-26T06:23:00.291325+00:00","static_findings":[{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":18,"severity":"medium","line_start":15},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":24,"severity":"medium","line_start":18},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```bash","category":"external_commands","line_end":28,"severity":"medium","line_start":24},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":32,"severity":"medium","line_start":28},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":49,"severity":"medium","line_start":32},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":55,"severity":"medium","line_start":49},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":63,"severity":"medium","line_start":55},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":67,"severity":"medium","line_start":63},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":74,"severity":"medium","line_start":67},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":80,"severity":"medium","line_start":74},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":114,"severity":"medium","line_start":80},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":118,"severity":"medium","line_start":114},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":139,"severity":"medium","line_start":118},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":143,"severity":"medium","line_start":139},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":150,"severity":"medium","line_start":143},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":154,"severity":"medium","line_start":150},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":167,"severity":"medium","line_start":154},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":171,"severity":"medium","line_start":167},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":179,"severity":"medium","line_start":171},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":185,"severity":"medium","line_start":179},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":196,"severity":"medium","line_start":185},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":200,"severity":"medium","line_start":196},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":215,"severity":"medium","line_start":200},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":219,"severity":"medium","line_start":215},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":233,"severity":"medium","line_start":219},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":237,"severity":"medium","line_start":233},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":260,"severity":"medium","line_start":237},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":264,"severity":"medium","line_start":260},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":277,"severity":"medium","line_start":264},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":281,"severity":"medium","line_start":277},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":298,"severity":"medium","line_start":281},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":304,"severity":"medium","line_start":298},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `KeyClient` | Key management operations |","category":"external_commands","line_end":305,"severity":"medium","line_start":304},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `CryptographyClient` | Cryptographic operations |","category":"external_commands","line_end":306,"severity":"medium","line_start":305},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `KeyResolver` | Resolve key ID to CryptographyClient |","category":"external_commands","line_end":307,"severity":"medium","line_start":306},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `KeyVaultKey` | Key with cryptographic material |","category":"external_commands","line_end":308,"severity":"medium","line_start":307},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `KeyProperties` | Key metadata (no crypto material) |","category":"external_commands","line_end":309,"severity":"medium","line_start":308},{"id":"external_commands:SKILL.md:309:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `CreateRsaKeyOptions` | RSA key creation options |","category":"external_commands","line_end":310,"severity":"medium","line_start":309},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `CreateEcKeyOptions` | EC key creation options |","category":"external_commands","line_end":311,"severity":"medium","line_start":310},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `CreateOctKeyOptions` | Symmetric key options |","category":"external_commands","line_end":312,"severity":"medium","line_start":311},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `EncryptResult` | Encryption result |","category":"external_commands","line_end":313,"severity":"medium","line_start":312},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `DecryptResult` | Decryption result |","category":"external_commands","line_end":314,"severity":"medium","line_start":313},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `SignResult` | Signing result |","category":"external_commands","line_end":315,"severity":"medium","line_start":314},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `VerifyResult` | Verification result |","category":"external_commands","line_end":316,"severity":"medium","line_start":315},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `WrapResult` | Key wrap result |","category":"external_commands","line_end":317,"severity":"medium","line_start":316},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `UnwrapResult` | Key unwrap result |","category":"external_commands","line_end":324,"severity":"medium","line_start":317},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `RsaOaep` | RSA | RSA-OAEP |","category":"external_commands","line_end":325,"severity":"medium","line_start":324},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `RsaOaep256` | RSA | RSA-OAEP-256 |","category":"external_commands","line_end":326,"severity":"medium","line_start":325},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Rsa15` | RSA | RSA 1.5 (legacy) |","category":"external_commands","line_end":327,"severity":"medium","line_start":326},{"id":"external_commands:SKILL.md:327:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `A128Gcm` | Oct | AES-128-GCM |","category":"external_commands","line_end":328,"severity":"medium","line_start":327},{"id":"external_commands:SKILL.md:328:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `A256Gcm` | Oct | AES-256-GCM |","category":"external_commands","line_end":333,"severity":"medium","line_start":328},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `RS256` | RSA | RSASSA-PKCS1-v1_5 SHA-256 |","category":"external_commands","line_end":334,"severity":"medium","line_start":333},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `RS384` | RSA | RSASSA-PKCS1-v1_5 SHA-384 |","category":"external_commands","line_end":335,"severity":"medium","line_start":334},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `RS512` | RSA | RSASSA-PKCS1-v1_5 SHA-512 |","category":"external_commands","line_end":336,"severity":"medium","line_start":335},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `PS256` | RSA | RSASSA-PSS SHA-256 |","category":"external_commands","line_end":337,"severity":"medium","line_start":336},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ES256` | EC | ECDSA P-256 SHA-256 |","category":"external_commands","line_end":338,"severity":"medium","line_start":337},{"id":"external_commands:SKILL.md:338:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ES384` | EC | ECDSA P-384 SHA-384 |","category":"external_commands","line_end":339,"severity":"medium","line_start":338},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `ES512` | EC | ECDSA P-521 SHA-512 |","category":"external_commands","line_end":344,"severity":"medium","line_start":339},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `RsaOaep` | RSA | RSA-OAEP |","category":"external_commands","line_end":345,"severity":"medium","line_start":344},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `RsaOaep256` | RSA | RSA-OAEP-256 |","category":"external_commands","line_end":346,"severity":"medium","line_start":345},{"id":"external_commands:SKILL.md:346:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `A128KW` | Oct | AES-128 Key Wrap |","category":"external_commands","line_end":347,"severity":"medium","line_start":346},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `A256KW` | Oct | AES-256 Key Wrap |","category":"external_commands","line_end":351,"severity":"medium","line_start":347},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"1. **Use Managed Identity** — Prefer `DefaultAzureCredential` over secrets","category":"external_commands","line_end":353,"severity":"medium","line_start":351},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"3. **Use HSM-backed keys** — Set `HardwareProtected = true` for sensitive keys","category":"external_commands","line_end":355,"severity":"medium","line_start":353},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"5. **Limit key operations** — Only enable required `KeyOperations`","category":"external_commands","line_end":356,"severity":"medium","line_start":355},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"6. **Set expiration dates** — Always set `ExpiresOn` for keys","category":"external_commands","line_end":362,"severity":"medium","line_start":356},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```csharp","category":"external_commands","line_end":381,"severity":"medium","line_start":362},{"id":"external_commands:SKILL.md:381:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```","category":"external_commands","line_end":395,"severity":"medium","line_start":381},{"id":"external_commands:SKILL.md:395:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Azure.Security.KeyVault.Keys` | Keys (this SDK) | `dotnet add package Azure.Security.KeyVault.Key","category":"external_commands","line_end":395,"severity":"medium","line_start":395},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Azure.Security.KeyVault.Secrets` | Secrets | `dotnet add package Azure.Security.KeyVault.Secrets`","category":"external_commands","line_end":396,"severity":"medium","line_start":396},{"id":"external_commands:SKILL.md:397:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Azure.Security.KeyVault.Certificates` | Certificates | `dotnet add package Azure.Security.KeyVaul","category":"external_commands","line_end":397,"severity":"medium","line_start":397},{"id":"external_commands:SKILL.md:398:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"| `Azure.Identity` | Authentication | `dotnet add package Azure.Identity` |","category":"external_commands","line_end":398,"severity":"medium","line_start":398},{"id":"network:SKILL.md:27:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"AZURE_KEYVAULT_URL=https://<vault-name>.vault.azure.net","category":"network","line_end":27,"severity":"low","line_start":27},{"id":"network:SKILL.md:60:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"var kvUri = $\"https://{keyVaultName}.vault.azure.net\";","category":"network","line_end":60,"severity":"low","line_start":60},{"id":"network:SKILL.md:194:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"new Uri(\"https://myvault.vault.azure.net/keys/my-rsa-key/version\"),","category":"network","line_end":194,"severity":"low","line_start":194},{"id":"network:SKILL.md:271:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"new Uri(\"https://myvault.vault.azure.net/keys/my-key/version\"));","category":"network","line_end":271,"severity":"low","line_start":271},{"id":"network:SKILL.md:404:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| NuGet Package | https://www.nuget.org/packages/Azure.Security.KeyVault.Keys |","category":"network","line_end":404,"severity":"low","line_start":404},{"id":"network:SKILL.md:405:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| API Reference | https://learn.microsoft.com/dotnet/api/azure.security.keyvault.keys |","category":"network","line_end":405,"severity":"low","line_start":405},{"id":"network:SKILL.md:406:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| Quickstart | https://learn.microsoft.com/azure/key-vault/keys/quick-create-net |","category":"network","line_end":406,"severity":"low","line_start":406},{"id":"network:SKILL.md:407:hardcoded-url","file":"SKILL.md","pattern":"Hardcoded URL","snippet":"| GitHub Source | https://github.com/Azure/azure-sdk-for-net/tree/main/sdk/keyvault/Azure.Security.K","category":"network","line_end":407,"severity":"low","line_start":407},{"id":"sensitive:SKILL.md:405:certificate-key-files","file":"SKILL.md","pattern":"Certificate/key files","snippet":"| API Reference | https://learn.microsoft.com/dotnet/api/azure.security.keyvault.keys |","category":"sensitive","line_end":405,"severity":"high","line_start":405},{"id":"blocker:SKILL.md:232:ransomware-file-extensions","file":"SKILL.md","pattern":"Ransomware file extensions","snippet":"wrapResult.EncryptedKey);","category":"blocker","line_end":232,"severity":"high","line_start":232}],"finding_verdicts":[{"id":"external_commands:SKILL.md:15:ruby-shell-backtick-execution","reason":"The match is a Markdown Bash code-fence delimiter, not Ruby or shell backtick execution. The enclosed commands install official Azure SDK packages.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:18:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown Bash code fence. They are documentation syntax and cannot execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:24:ruby-shell-backtick-execution","reason":"The match opens a Markdown Bash example containing environment variable placeholders. It is not an executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:28:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown Bash code fence. No shell evaluation mechanism exists in the document.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:32:ruby-shell-backtick-execution","reason":"The match opens a plain Markdown diagram fence. The client hierarchy text is not a shell command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:49:ruby-shell-backtick-execution","reason":"The matched backticks close the Markdown client hierarchy diagram. They do not invoke Ruby or a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:55:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# example for KeyClient authentication. It is documentation syntax, not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:63:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. They have no execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:67:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# service-principal example using placeholders. It does not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:74:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. No backtick-based command is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:80:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# example for creating keys. It is not Ruby or shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:114:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. They cannot launch an external process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:118:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# example for retrieving keys. It is static documentation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:139:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. No command interpreter evaluates them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:143:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# key-property update example. It does not invoke a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:150:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. They are not executable syntax in Markdown.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:154:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# deletion and recovery example. It is reference content, not an automatic command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:167:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. No external process is started.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:171:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# backup and restore example. It does not execute through backticks.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:179:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. This is formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:185:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# CryptographyClient example. It is not an external command invocation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:196:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. They have no shell execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:200:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# encryption example. The document does not execute the sample.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:215:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. They are not a Ruby or shell expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:219:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# key-wrap example. It is documentation and contains no process execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:233:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. No command is evaluated.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:237:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# signing example. It cannot invoke Ruby or a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:260:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. They provide formatting only.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:264:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# KeyResolver example. It is static instructional content.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:277:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. They do not execute an external command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:281:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# key-rotation example. It is not shell execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:298:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. No interpreter executes them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:304:ruby-shell-backtick-execution","reason":"The backticks format the KeyClient type inside a Markdown table. They are not evaluated as a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:305:ruby-shell-backtick-execution","reason":"The backticks format the CryptographyClient type inside a Markdown table. They have no execution semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:306:ruby-shell-backtick-execution","reason":"The backticks format the KeyResolver type inside a Markdown table. They do not invoke a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:307:ruby-shell-backtick-execution","reason":"The backticks format the KeyVaultKey type inside a Markdown table. This is inline-code formatting.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:308:ruby-shell-backtick-execution","reason":"The backticks format the KeyProperties type inside a Markdown table. They cannot execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:309:ruby-shell-backtick-execution","reason":"The backticks format the CreateRsaKeyOptions type inside a Markdown table. No command execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:310:ruby-shell-backtick-execution","reason":"The backticks format the CreateEcKeyOptions type inside a Markdown table. They are documentation syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:311:ruby-shell-backtick-execution","reason":"The backticks format the CreateOctKeyOptions type inside a Markdown table. They do not execute a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:312:ruby-shell-backtick-execution","reason":"The backticks format the EncryptResult type inside a Markdown table. This is benign inline-code markup.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:313:ruby-shell-backtick-execution","reason":"The backticks format the DecryptResult type inside a Markdown table. No shell context exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:314:ruby-shell-backtick-execution","reason":"The backticks format the SignResult type inside a Markdown table. They are not executable.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:315:ruby-shell-backtick-execution","reason":"The backticks format the VerifyResult type inside a Markdown table. They cannot launch a process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:316:ruby-shell-backtick-execution","reason":"The backticks format the WrapResult type inside a Markdown table. This is static text.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:317:ruby-shell-backtick-execution","reason":"The backticks format the UnwrapResult type inside a Markdown table. No command interpreter is involved.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:324:ruby-shell-backtick-execution","reason":"The backticks format the RsaOaep algorithm name inside a Markdown table. They do not execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:325:ruby-shell-backtick-execution","reason":"The backticks format the RsaOaep256 algorithm name inside a Markdown table. This is inline-code markup.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:326:ruby-shell-backtick-execution","reason":"The backticks format the legacy Rsa15 algorithm name inside a Markdown table. They have no execution behavior.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:327:ruby-shell-backtick-execution","reason":"The backticks format the A128Gcm algorithm name inside a Markdown table. No external command is present.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:328:ruby-shell-backtick-execution","reason":"The backticks format the A256Gcm algorithm name inside a Markdown table. They are documentation syntax.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:333:ruby-shell-backtick-execution","reason":"The backticks format the RS256 signature algorithm inside a Markdown table. They are not shell syntax in this context.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:334:ruby-shell-backtick-execution","reason":"The backticks format the RS384 signature algorithm inside a Markdown table. No command execution occurs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:335:ruby-shell-backtick-execution","reason":"The backticks format the RS512 signature algorithm inside a Markdown table. They cannot execute code.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:336:ruby-shell-backtick-execution","reason":"The backticks format the PS256 signature algorithm inside a Markdown table. This is benign inline-code markup.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:337:ruby-shell-backtick-execution","reason":"The backticks format the ES256 signature algorithm inside a Markdown table. No shell is invoked.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:338:ruby-shell-backtick-execution","reason":"The backticks format the ES384 signature algorithm inside a Markdown table. They are not executable.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:339:ruby-shell-backtick-execution","reason":"The backticks format the ES512 signature algorithm inside a Markdown table. They have no command semantics.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:344:ruby-shell-backtick-execution","reason":"The backticks format the RsaOaep key-wrap algorithm inside a Markdown table. They do not invoke an external process.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:345:ruby-shell-backtick-execution","reason":"The backticks format the RsaOaep256 key-wrap algorithm inside a Markdown table. This is static documentation.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:346:ruby-shell-backtick-execution","reason":"The backticks format the A128KW key-wrap algorithm inside a Markdown table. No command execution is possible.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:347:ruby-shell-backtick-execution","reason":"The backticks format the A256KW key-wrap algorithm inside a Markdown table. They are inline-code delimiters.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:351:ruby-shell-backtick-execution","reason":"The backticks format DefaultAzureCredential in a Markdown best-practice item. They do not evaluate a command.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:353:ruby-shell-backtick-execution","reason":"The backticks format a C# HardwareProtected assignment in Markdown. No shell context or command execution exists.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:355:ruby-shell-backtick-execution","reason":"The backticks format the KeyOperations property in Markdown. They are not an executable backtick expression.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:356:ruby-shell-backtick-execution","reason":"The backticks format the ExpiresOn property in Markdown. They cannot invoke Ruby or a shell.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:362:ruby-shell-backtick-execution","reason":"The match opens a Markdown C# error-handling example. It is not command execution.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:381:ruby-shell-backtick-execution","reason":"The matched backticks close a Markdown C# code fence. No interpreter evaluates them.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:395:ruby-shell-backtick-execution","reason":"The backticks format an official Azure package name and installation example in a Markdown table. The document does not execute it.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:396:ruby-shell-backtick-execution","reason":"The backticks format an official Azure package name and installation example in a Markdown table. No automatic command runs.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:397:ruby-shell-backtick-execution","reason":"The backticks format an official Azure package name and installation example in a Markdown table. They are documentation markup.","verdict":"false_positive","confidence":0.99},{"id":"external_commands:SKILL.md:398:ruby-shell-backtick-execution","reason":"The backticks format the official Azure.Identity package and installation example in a Markdown table. No process is launched.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:27:hardcoded-url","reason":"This is a placeholder Azure Key Vault endpoint for user configuration. It targets the expected vault.azure.net service and sends no data by itself.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:60:hardcoded-url","reason":"This C# sample constructs the expected Azure Key Vault URI from a vault name. It contains no unsolicited external destination or data transfer.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:194:hardcoded-url","reason":"This is an illustrative vault.azure.net key URI for constructing CryptographyClient. It contains no real tenant identifier and no exfiltration destination.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:271:hardcoded-url","reason":"This is an illustrative vault.azure.net key URI for KeyResolver. It uses placeholder names and represents the expected Azure service.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:404:hardcoded-url","reason":"The URL is a reference link to the official NuGet package page. The Markdown document does not fetch it or transmit data.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:405:hardcoded-url","reason":"The URL is a reference link to Microsoft Learn API documentation. It is not an untrusted endpoint or an automatic network request.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:406:hardcoded-url","reason":"The URL is a reference link to an official Microsoft Learn quickstart. No request is issued by the skill.","verdict":"false_positive","confidence":0.99},{"id":"network:SKILL.md:407:hardcoded-url","reason":"The URL points to the official Azure SDK source repository on GitHub. It is a documentation link without automatic network behavior.","verdict":"false_positive","confidence":0.99},{"id":"sensitive:SKILL.md:405:certificate-key-files","reason":"The match is a Microsoft Learn URL whose path names the Key Vault Keys API. It does not reference or access a certificate or private-key file.","verdict":"false_positive","confidence":0.99},{"id":"blocker:SKILL.md:232:ransomware-file-extensions","reason":"EncryptedKey is an Azure SDK property holding wrapped key material, not a ransomware file extension. There is no filesystem traversal, bulk encryption, or malicious intent.","verdict":"false_positive","confidence":1}],"semantic_findings":[],"subject_marketplace_commit_sha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","subject_content_hash":"547f100c9ce56ae7d5fdcf35faddfbe77aa5702b60f8d126b4717c77328f5713","subject_tree_hash":"71e784a1bcccaab16b1dfaa0f1bf52064bd0e7db51357751f1e48b772624deab","subject_plugin_path":"skills/sickn33/azure-security-keyvault-keys-dotnet","audit_payload_hash":"a2d64d4bda77446d8be535219ab3ca1f","confirmed_risk_level":"safe","scanner_version":"3.0.0","policy_version":"skillstore-security-audit-policy-v1","subject":{"marketplaceCommitSha":"f9e2c34b4f19c7f3e6b0a1e93227b5f77cc12526","contentHash":"547f100c9ce56ae7d5fdcf35faddfbe77aa5702b60f8d126b4717c77328f5713","treeHash":"71e784a1bcccaab16b1dfaa0f1bf52064bd0e7db51357751f1e48b772624deab","pluginPath":"skills/sickn33/azure-security-keyvault-keys-dotnet","auditPayloadHash":"a2d64d4bda77446d8be535219ab3ca1f"},"scannerVersion":"3.0.0","policyVersion":"skillstore-security-audit-policy-v1"},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"issued","url":"/api/skills/sickn33-azure-security-keyvault-keys-dotnet/audits/6/attestation","status":"active"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"active","verificationState":"not_verified"},"isLatest":true}}