{"slug":"detecting-azure-service-principal-abuse","source_name":"detecting-azure-service-principal-abuse","name":"Detecting Azure Service Principal Abuse","description":"Detect and investigate Azure service principal abuse including privilege escalation, credential compromise, admin consent bypass, and unauthorized enumeration in Microsoft Entra ID environments.","version":1,"lift":{"pass_rate_delta_pts":18.18,"pass_rate_pct":22.7,"total_cases":22,"passed_cases":5,"tokens_delta_pct":51.7,"turns_delta_pct":0,"verdict":"mixed","benchmark_model":"gemini-3.6-flash","grading_method":"judged","completed_at":"2026-07-28T01:59:34.629974+00:00"},"skill_score":0.2273,"benchmark_models":[{"model":"gemini-3.6-flash","headline":true,"delta_pts":18.18,"with_pass_pct":22.7,"without_pass_pct":4.5,"tokens_delta_pct":51.7,"turns_delta_pct":0,"total_cases":22,"cases_aggregated":22,"verdict":"mixed","never_hurt":true,"completed_at":"2026-07-28T01:59:34.629974+00:00","run_id":"a39e290f-f832-42fe-a859-b49dd074dc4e","version_number":1,"is_latest_version":true,"gate":null}],"trust":{"skill_safety":"passed","safety_status":"clean","intent_verdict":null,"content_status":"clean","indexable":true},"license":"Apache-2.0","install_count":0,"manifest_hash":"6ced2bf6fbdaecdc366e1e9c7284032e1cdb533e626164a2875dad0aa545b05c","raw_url":"https://app.decimal.ai/s/detecting-azure-service-principal-abuse/SKILL.md","scorecard_url":"https://app.decimal.ai/skills/detecting-azure-service-principal-abuse"}