All skills
thomast1906 avatar

/api-security-review

@b198c92

Reviews Azure API Management configurations for security vulnerabilities, OWASP API Security Top 10 compliance, VNet Internal mode validation, Private Link verification, and Azure Security Benchmark alignment. Use when performing security audits, pre-deployment validation, or compliance reviews.

Use this Skill: https://skilld.dev/gh/thomast1906/github-copilot-agent-skills/api-security-review

This session only. Nothing lands on disk.

referencesSECURITY_CONTROLS.md

≈700 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security Controls Checklist

This reference file contains the complete 60+ security control checklist across 9 categories for Azure API Management security reviews.

Categories

NS- Network Security

  • VNet Internal mode enabled
  • Private Link / Private Endpoints configured for all PaaS dependencies
  • NSG rules restrict inbound/outbound to required ports only
  • No public IP addresses on internal services
  • Subnet delegation configured correctly
  • DDoS Protection enabled (Standard tier for production)

IM- Identity Management

  • Managed Identity used for all Azure resource authentication
  • No service principals with client secrets where MI is possible
  • Azure AD authentication enforced on APIs where applicable
  • OAuth 2.0 / OIDC configured with correct audience and issuer
  • Subscription keys rotated regularly (or replaced with token auth)
  • Named Values used for all secrets (not inline policy)

PA- Privileged Access

  • RBAC roles follow least privilege
  • No Owner/Contributor assigned to individuals on APIM resource
  • APIM Management REST API access restricted
  • Git integration (if used) secured with short-lived tokens
  • Break-glass accounts documented and monitored

DP- Data Protection

  • TLS 1.2+ enforced on gateway and management endpoints
  • Custom domain with valid certificate (not *.azure-api.net in prod)
  • Cipher suites reviewed and weak ciphers disabled
  • Backend communication uses HTTPS only
  • Secrets stored in Key Vault, not hardcoded in policies

LT- Logging & Threat Detection

  • Diagnostic settings configured and sending to Log Analytics
  • Application Insights connected to APIM instance
  • Azure Monitor alerts for 4xx/5xx error spikes
  • Microsoft Defender for APIs enabled
  • Audit logs retained for minimum 90 days

IR- Incident Response

  • Playbooks defined for common incidents (key compromise, DDoS)
  • Contacts configured in Azure Security Center
  • SIEM integration (Sentinel) for threat detection

PV- Posture & Vulnerability Management

  • Azure Policy applied for APIM compliance
  • Microsoft Defender for Cloud recommendations reviewed
  • Regular penetration testing schedule
  • Dependency scanning for developer portal customizations

ES- Endpoint Security

  • Developer portal hardened (custom domain, HTTPS only)
  • Direct management endpoint access restricted to known IPs
  • Self-hosted gateway nodes secured and monitored

GS- Governance & Strategy

  • APIM instance tagged per CAF naming conventions
  • Resource locks applied to production instances
  • Change management process for policy updates
  • API versioning strategy documented and enforced

Usage

Reference this checklist when running the api-security-review skill to ensure comprehensive coverage across all security domains for Azure API Management deployments.

Source: SKILL.md on GitHub

1 alert14d4 checks · Risk SAFE
  • Gen Agent Trust Hub14d

    The skill is a specialized security auditing tool for Azure API Management. It contains no malicious code or obfuscated patterns. However, it possesses an inherent attack surface for indirect prompt injection because it is designed to ingest and analyze external configuration data such as API policies and cloud environment metadata.

  • Socket14d

    No alerts

  • Snyk14d

    Risk: LOW · No issues

  • Runlayer6mo

    1/1 file flagged

Signed by skilld at b198c92. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 5 months ago
Other metadata
metadata
{
  "author": "Thomas Thornton",
  "version": "1.0.0",
  "last-updated": "2026-05-19",
  "azure-services": "api-management, security-center",
  "compliance-frameworks": "owasp-api-top10,azure-security-benchmark,cis-azure"
}

README badge

README badge for thomast1906/github-copilot-agent-skills/api-security-review