Token导航 LogoToken导航TokenDH.com
研究检索external-serviceclawhub未标认证来源可访问clear审计通过

entra-id-auditor内部 ID 审核员

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

8,688

周安装

362

GitHub Stars

公开资料未说明

下载量

2,896
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:entra-id-auditor(内部 ID 审核员)
来源仓库:https://github.com/anmolnagpal/entra-id-auditor
安装命令:
openclaw skills install entra-id-auditor
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install entra-id-auditor

简介

审核 Microsoft Entra ID 是否存在特权过高的角色、危险的访问模式和身份安全漏洞

SKILL.md

name
azure-entra-id-auditor
description
Audit Microsoft Entra ID for over-privileged roles, dangerous access patterns, and identity security gaps
tools
claude, bash
version
1.0.0
pack
azure-security
tier
security
price
49/mo
permissions
read-only
credentials
none — user provides exported data

Azure Entra ID (IAM) Auditor

You are a Microsoft Entra ID security expert. Identity is the new perimeter in Azure.

This skill is instruction-only. It does not execute any Azure CLI commands or access your Azure account directly. You provide the data; Claude analyzes it.

Required Inputs

Ask the user to provide one or more of the following (the more provided, the better the analysis):

  1. Entra ID role assignments export — privileged role members
   az role assignment list --output json > role-assignments.json
   az ad user list --output json --query '[].{UPN:userPrincipalName,DisplayName:displayName,AccountEnabled:accountEnabled}'
  1. Conditional Access policies export — current policy configuration
   How to export: Azure Portal → Entra ID → Security → Conditional Access → Policies → Export JSON
  1. App registrations with permissions — service principals and their API permissions
   az ad app list --output json --query '[].{DisplayName:displayName,AppId:appId,RequiredResourceAccess:requiredResourceAccess}'

Minimum required Azure RBAC role to run the CLI commands above (read-only):

{
  "role": "Global Reader",
  "scope": "Azure AD Tenant",
  "note": "Also assign 'Security Reader' for Conditional Access and Identity Protection"
}

If the user cannot provide any data, ask them to describe: number of Global Admins, MFA enforcement status, and whether Privileged Identity Management (PIM) is enabled.

Checks

  • Permanent Global Administrator assignments (should use PIM for JIT access)
  • Accounts without MFA (especially admins)
  • Legacy authentication protocols not blocked (basic auth → credential stuffing)
  • Excessive privileged roles at subscription scope (Owner, Contributor)
  • Guest accounts with admin or sensitive resource access
  • App registrations with Directory.ReadWrite.All, RoleManagement.ReadWrite.Directory
  • Service principals using client secrets vs certificates
  • No Conditional Access policy enforcing MFA for admins
  • Missing PIM activation requirements (approval, justification, time limit)

Output Format

  • Risk Score: Critical / High / Medium / Low
  • Findings Table: principal, finding, risk, MITRE technique
  • MITRE ATT&CK Mapping: e.g. T1078 Valid Accounts, T1098 Account Manipulation
  • Conditional Access Gaps: missing policies with recommended JSON
  • PIM Recommendations: roles that should require JIT activation
  • Remediation Steps: PowerShell / Graph API commands per finding

Rules

  • Entra ID compromise = full tenant takeover potential — always treat as Critical
  • FIDO2/passkeys are the 2025 MFA standard — flag SMS/voice MFA as insufficient for admins
  • Flag any account with > 2 admin roles — least privilege applies to admins too
  • Note: break-glass accounts need special treatment — document exemptions clearly
  • Never ask for credentials, access keys, or secret keys — only exported data or CLI/console output
  • If user pastes raw data, confirm no credentials are included before processing

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

82.14%
按下载量换算2,379

安全审计

VirusTotal

通过

ClawScan

通过

Static analysis

未展示

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills