監査履歴
azure-cloud-migrate - 6 監査
バージョン比較
監査済みバージョン間の機能と検出結果の変化(新しい順)。
2026年7月23日 17:55
Most of the 400 presented findings are documentation false positives involving links, code fences, managed identity examples, and visible migration commands. Confirmed risks involve shared cloud keys, decoded secret transfer through CLI arguments, and local secret materialization. The 30 omitted static matches require manual review before publication. Static review was capped at 400/430 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
確認済みのセキュリティ上の懸念 (9)
機能レビュー項目 (14)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
🔑 環境変数 (50)
🌐 ネットワークアクセス (23)
📁 ファイルシステムへのアクセス (7)
⚙️ 外部コマンド (50)
⚡ スクリプトを含む (12)
検出されたパターン
2026年7月8日 08:27
Most static findings are documentation false positives from Markdown links, code fences, Azure managed identity examples, and visible migration commands. Confirmed risks remain where the guides retrieve shared keys, export Kubernetes secrets, or pass decoded secret values through command-line arguments during migration.
確認済みのセキュリティ上の懸念 (9)
機能レビュー項目 (14)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
🔑 環境変数 (52)
🌐 ネットワークアクセス (23)
📁 ファイルシステムへのアクセス (7)
⚙️ 外部コマンド (173)
⚡ スクリプトを含む (12)
検出されたパターン
2026年7月6日 18:58
Manual review found that the static findings are Markdown reference examples, table entries, placeholders, or Azure Functions code samples rather than executable skill logic. I found no evidence of prompt injection, credential exfiltration, arbitrary command execution, malicious networking, or path traversal intent in the cited files.
静的解析の誤検知を無視 (1)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (33)
🔑 環境変数 (20)
🌐 ネットワークアクセス (1)
⚡ スクリプトを含む (12)
2026年7月6日 18:58
Manual review found that the static findings are Markdown reference examples, table entries, placeholders, or Azure Functions code samples rather than executable skill logic. I found no evidence of prompt injection, credential exfiltration, arbitrary command execution, malicious networking, or path traversal intent in the cited files.
静的解析の誤検知を無視 (1)
これらの静的マッチはセマンティックレビューで却下されたか、スキーマのみのトークンに一致したため、透明性のために表示されていますが、品質スコアには影響しません。
リスク要因
⚙️ 外部コマンド (33)
🔑 環境変数 (20)
🌐 ネットワークアクセス (1)
⚡ スクリプトを含む (12)
2026年6月30日 08:02
Static analysis reported many command, credential, URL, and script indicators, but review found them in Markdown guidance and code examples. No prompt injection, credential exfiltration, hidden executable payload, or malicious intent was found. The skill has low operational risk because it guides file creation and uses Azure documentation tools during migration.
機能レビュー項目 (3)
これらは、このスキルに期待される可能性のある実際のローカル機能であるため、レビューが必要ですが、確認済みの悪意ある動作としてはカウントされません。
リスク要因
⚙️ 外部コマンド (3)
🌐 ネットワークアクセス (3)
🔑 環境変数 (3)
⚡ スクリプトを含む (3)
検出されたパターン
2026年3月1日 08:39
This is an official Microsoft skill for migrating AWS Lambda workloads to Azure Functions. Static findings are false positives: backtick usage is markdown code formatting, environment variable access is legitimate Azure authentication, network URLs point to Azure documentation, and the SAM detection refers to AWS Serverless Application Model, not Windows Security Accounts Manager. No malicious code detected.