security-alert-review

作者: microsoft

列出并审查Azure DevOps仓库的高级安全警报。显示依赖项漏洞、机密泄露以及代码扫描发现结果,并附带…

npx skills add https://github.com/microsoft/azure-devops-skills --skill security-alert-review

Security alert review

This skill works in the context of a project and a repository. Both are required to retrieve alerts.

Project selection

  • If the user provides a project name in their request (for example, "for Contoso"), use that project directly and do not call core_list_projects.
  • If the user does not provide a project name, first ask the user once to provide the project name.
  • If the project name is still not provided after asking once, call core_list_projects to return a list of projects the user can choose from.

Repository selection

  • If the user provides a repository name, use that repository directly.
  • If the user does not specify a repository, ask the user once for the repository name.
  • If the repository name is still not provided after asking once, call repo_list_repos_by_project to list available repositories for the user to choose from.

Tools

Use Azure DevOps MCP Server tools for all interactions with Azure DevOps.

  • core_list_projects: Get a list of projects in the organization.
  • repo_list_repos_by_project: Get a list of repositories for a project.
  • advsec_get_alerts: Get Advanced Security alerts for a repository, with optional filters for severity, state, alert type, and confidence level.
  • advsec_get_alert_details: Get detailed information about a specific alert by ID.

Rules

1. List alerts for a repository

  • When the user asks to list alerts, show security alerts, or review alerts, call advsec_get_alerts for the specified project and repository.
  • Apply filters based on the user's request:
    • Severity: filter by severities (for example, "show critical alerts" → ["Critical"]).
    • State: filter by states (for example, "show active alerts" → ["Active"]).
    • Alert type: filter by alertType (for example, "show dependency alerts" → "Dependency"). Valid types are: Dependency, Secret, Code.
  • Always include confidenceLevels: ["High", "Other"] on every call to advsec_get_alerts unless the user explicitly requests a specific confidence filter.
  • If the user does not specify filters, show all active alerts on the default branch by default (use onlyDefaultBranch: true, states: ["Active"], and confidenceLevels: ["High", "Other"]).
  • Show the results in a table.
  • If there are no alerts, explicitly state that there are no alerts matching the criteria for this repository.

Example

  • "show security alerts for repo MyApp in project Contoso"
  • "list critical dependency alerts for repo MyApp"
  • "show all active secret alerts in repo MyApp"

2. Get details for a specific alert

  • When the user asks about a specific alert (for example, "alert 42" or "tell me about alert 42"), call advsec_get_alert_details with the alert ID, project, and repository.
  • Show all available detail fields including the affected file, line number, description, remediation guidance, and rule information.

Example

  • "show details for alert 42 in repo MyApp, project Contoso"
  • "what is alert 42 about?"

3. Summary view

  • When the user asks for a summary or overview of alerts, call advsec_get_alerts (with no severity or type filter, states: ["Active"], and confidenceLevels: ["High", "Other"]) and present a summary grouped by:
    1. Alert type (Dependency, Secret, Code) with count.
    2. Severity (Critical, High, Medium, Low, Other) with count per type.
  • Show the summary as a compact table followed by the total count.
  • Note: advsec_get_alerts returns up to 100 alerts by default. If the results include a continuation token, let the user know the summary is based on the first batch of alerts and that additional alerts exist.

Example

  • "give me a security overview for repo MyApp"
  • "summarize the alerts in repo MyApp for project Contoso"

Display results

When displaying alert lists, show in a table:

  • Alert ID
  • Title (the alert title or rule name)
  • Severity with emoji: 🔴 Critical, 🟠 High, 🟡 Medium, 🟢 Low
  • State (Active, Dismissed, Fixed, AutoDismissed)
  • Alert type (Dependency, Secret, Code)
  • Rule (the rule ID or name)
  • First seen formatted as MM/DD/YYYY

When displaying alert details, show:

  • All fields from the list view, plus:
  • Description — full text of what the alert means.
  • File path and line number (if applicable) — where the issue was found.
  • Remediation — guidance on how to fix the issue (if available from the alert details).
  • Confidence — High or Other (for secret alerts).
  • Validity — Active, Inactive, or Unknown (for secret alerts).
  • Tool name — the scanning tool that found the alert.

When displaying the summary view, show:

Alert Type🔴 Critical🟠 High🟡 Medium🟢 LowOtherTotal
Dependencycountcountcountcountcountcount
Secretcountcountcountcountcountcount
Codecountcountcountcountcountcount
Totalcountcountcountcountcountcount

The Other column includes any alerts with severity values outside Critical/High/Medium/Low (for example, Note, Warning, Error, or Undefined).

来自 microsoft 的更多技能

oss-growth
microsoft
OSS增长黑客角色
agent-framework-azure-ai-py
microsoft
使用Microsoft Agent Framework Python SDK(agent-framework-azure-ai)构建Azure AI Foundry代理。在创建使用AzureAIAgentsProvider的持久化代理、使用托管工具(代码解释器、文件搜索、网络搜索)、集成MCP服务器、管理对话线程或实现流式响应时使用。涵盖函数工具、结构化输出和多工具代理。
development
airunway-aks-setup
microsoft
在AKS上设置AI Runway——从裸集群到运行模型。涵盖集群验证、控制器安装、GPU评估、提供商设置和首次部署。适用场景:“设置AI Runway”、“接入AKS集群”、“安装AI Runway”、“airunway设置”、“将模型部署到AKS”、“在AKS上进行GPU推理”、“在AKS上配置KAITO”、“在AKS上运行LLM”、“在AKS上使用vLLM”、“在AKS上设置模型服务”、“AI Runway控制器”。
devops
appinsights-instrumentation
microsoft
使用Azure Application Insights对Web应用进行插桩的指南。提供遥测模式、SDK设置和配置参考。适用场景:如何对应用进行插桩、App Insights SDK、遥测模式、什么是App Insights、Application Insights指南、插桩示例、APM最佳实践。
devops
applicationinsights-web-ts
microsoft
使用Application Insights JavaScript SDK(@microsoft/applicationinsights-web)为浏览器/Web应用添加检测。用于真实用户监控(RUM)——页面视图、点击、AJAX/fetch依赖项、异常、自定义事件,以及与后端OpenTelemetry追踪关联的浏览器端GenAI代理追踪。涵盖SDK加载器脚本和npm设置、框架扩展(React、React Native、Angular)、点击分析、遥测初始化器,以及从浏览器发出的代理/工具/模型跨度所遵循的OTel GenAI语义约定。
devops
azure-ai-anomalydetector-java
microsoft
使用适用于 Java 的 Azure AI 异常检测器 SDK 构建异常检测应用程序。在实现单变量/多变量异常检测、时间序列分析或 AI 驱动的监控时使用。
development
azure-ai-language-conversations-py
microsoft
使用azure-ai-language-conversations Python SDK实现对话语言理解(CLU)。当使用ConversationAnalysisClient分析对话意图和实体、构建NLP功能或将语言理解集成到应用程序中时使用。
development
azure-ai-ml-py
microsoft
Azure Machine Learning SDK v2 for Python。用于机器学习工作区、作业、模型、数据集、计算资源和管道。 触发词:“azure-ai-ml”、“MLClient”、“工作区”、“模型注册表”、“训练作业”、“数据集”。
development