Cloud & App Security Posture (CSPM/SSPM) - **name_fr:** Posture de sécurité cloud et apps (CSPM/SSPM) - **tl_en:** Posture management across Azure, AWS, GCP and SaaS — Defender for Cloud CSPM + Cloud Apps SSPM, Secure Score, attack paths - **tl_fr:** Gestion de posture multicloud et SaaS — CSPM Defender for Cloud + SSPM Cloud Apps, Secure Score, chemins d'attaque - **creator:** @vinayaklatthe - **type:** Agent skill - **url:** https://github.com/vinayaklatthe/microsoft-security-skills - **cat:** Security - **kws:** cspm, sspm, defender for cloud, secure score, posture, multicloud, saas security, attack path, mcsb - **license:** MIT **Description EN:** Curated by Skill Harbor — security posture management across two layers: CSPM for cloud infrastructure (Defender for Cloud over Azure/AWS/GCP — Secure Score, MCSB benchmarks, attack-path analysis) and SSPM for SaaS (Defender for Cloud Apps over Microsoft 365, Salesforce, ServiceNow, GitHub) — with a lens-picker for what to harden and guidance on when to enable the paid Defender CSPM plan. By @vinayaklatthe, listed here with credit to its creator. Honest caveats: foundational CSPM is free with Defender for Cloud; attack-path analysis, the cloud security graph and agentless scanning need the paid Defender CSPM plan; requires your clouds onboarded to Defender (multicloud connectors). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — gestion de la posture de sécurité sur deux couches : CSPM pour l'infrastructure cloud (Defender for Cloud sur Azure/AWS/GCP — Secure Score, benchmarks MCSB, analyse des chemins d'attaque) et SSPM pour le SaaS (Defender for Cloud Apps sur Microsoft 365, Salesforce, ServiceNow, GitHub) — avec un sélecteur de lentille pour ce qu'il faut durcir et des conseils sur quand activer le plan payant Defender CSPM. Crédit : @vinayaklatthe. Bémols honnêtes : le CSPM de fondation est gratuit avec Defender for Cloud ; l'analyse des chemins d'attaque, le graphe de sécurité cloud et le scan agentless nécessitent le plan payant Defender CSPM ; nécessite vos clouds onboardés dans Defender (connecteurs multicloud). Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: Azure/AWS/GCP accounts to assess, onboarded (or ready to onboard) to Microsoft Defender for Cloud; the attack-path features need the paid Defender CSPM plan Install "Cloud & App Security Posture (CSPM/SSPM)" for me. Give my agent the posture-management guidance — Defender for Cloud CSPM and Defender for Cloud Apps SSPM, Secure Score and MCSB, the posture-lens picker, governance, and when the paid Defender CSPM plan is worth it Repository: https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/cloud-app-security-posture/SKILL.md 1. Fetch the SKILL.md file for the vinayaklatthe-microsoft-security-skills-cloud-app-security-posture skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "vinayaklatthe-microsoft-security-skills-cloud-app-security-posture". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. onboard my clouds to Defender for Cloud; enable the paid plan if I want attack paths). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : comptes Azure/AWS/GCP à évaluer, onboardés (ou prêts à l'être) dans Microsoft Defender for Cloud ; les fonctionnalités de chemins d'attaque nécessitent le plan payant Defender CSPM Installe-moi « Posture de sécurité cloud et apps (CSPM/SSPM) ». Donne à mon agent les conseils de gestion de posture — CSPM Defender for Cloud et SSPM Defender for Cloud Apps, Secure Score et MCSB, le sélecteur de lentille de posture, la gouvernance, et quand le plan payant Defender CSPM vaut le coup Dépôt : https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/cloud-app-security-posture/SKILL.md 1. Récupère le fichier SKILL.md du skill vinayaklatthe-microsoft-security-skills-cloud-app-security-posture depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md dans le répertoire des skills de l'agent, dans un dossier nommé « vinayaklatthe-microsoft-security-skills-cloud-app-security-posture ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. onboarder mes clouds dans Defender for Cloud ; activer le plan payant si je veux les chemins d'attaque). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
Posture management across Azure, AWS, GCP and SaaS — Defender for Cloud CSPM + Cloud Apps SSPM, Secure Score, attack paths - **tl_fr:** Gestion de posture multicloud et SaaS — CSPM Defender for Cloud + SSPM Cloud Apps, Secure Score, chemins d'attaque - **creator:** @vinayaklatthe - **type:** Agent skill - **url:** https://github.com/vinayaklatthe/microsoft-security-skills - **cat:** Security - **kws:** cspm, sspm, defender for cloud, secure score, posture, multicloud, saas security, attack path, mcsb - **license:** MIT **Description EN:** Curated by Skill Harbor — security posture management across two layers: CSPM for cloud infrastructure (Defender for Cloud over Azure/AWS/GCP — Secure Score, MCSB benchmarks, attack-path analysis) and SSPM for SaaS (Defender for Cloud Apps over Microsoft 365, Salesforce, ServiceNow, GitHub) — with a lens-picker for what to harden and guidance on when to enable the paid Defender CSPM plan. By @vinayaklatthe, listed here with credit to its creator. Honest caveats: foundational CSPM is free with Defender for Cloud; attack-path analysis, the cloud security graph and agentless scanning need the paid Defender CSPM plan; requires your clouds onboarded to Defender (multicloud connectors). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — gestion de la posture de sécurité sur deux couches : CSPM pour l'infrastructure cloud (Defender for Cloud sur Azure/AWS/GCP — Secure Score, benchmarks MCSB, analyse des chemins d'attaque) et SSPM pour le SaaS (Defender for Cloud Apps sur Microsoft 365, Salesforce, ServiceNow, GitHub) — avec un sélecteur de lentille pour ce qu'il faut durcir et des conseils sur quand activer le plan payant Defender CSPM. Crédit : @vinayaklatthe. Bémols honnêtes : le CSPM de fondation est gratuit avec Defender for Cloud ; l'analyse des chemins d'attaque, le graphe de sécurité cloud et le scan agentless nécessitent le plan payant Defender CSPM ; nécessite vos clouds onboardés dans Defender (connecteurs multicloud). Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: Azure/AWS/GCP accounts to assess, onboarded (or ready to onboard) to Microsoft Defender for Cloud; the attack-path features need the paid Defender CSPM plan Install "Cloud & App Security Posture (CSPM/SSPM)" for me. Give my agent the posture-management guidance — Defender for Cloud CSPM and Defender for Cloud Apps SSPM, Secure Score and MCSB, the posture-lens picker, governance, and when the paid Defender CSPM plan is worth it Repository: https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/cloud-app-security-posture/SKILL.md 1. Fetch the SKILL.md file for the vinayaklatthe-microsoft-security-skills-cloud-app-security-posture skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "vinayaklatthe-microsoft-security-skills-cloud-app-security-posture". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. onboard my clouds to Defender for Cloud; enable the paid plan if I want attack paths). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : comptes Azure/AWS/GCP à évaluer, onboardés (ou prêts à l'être) dans Microsoft Defender for Cloud ; les fonctionnalités de chemins d'attaque nécessitent le plan payant Defender CSPM Installe-moi « Posture de sécurité cloud et apps (CSPM/SSPM) ». Donne à mon agent les conseils de gestion de posture — CSPM Defender for Cloud et SSPM Defender for Cloud Apps, Secure Score et MCSB, le sélecteur de lentille de posture, la gouvernance, et quand le plan payant Defender CSPM vaut le coup Dépôt : https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/cloud-app-security-posture/SKILL.md 1. Récupère le fichier SKILL.md du skill vinayaklatthe-microsoft-security-skills-cloud-app-security-posture depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md dans le répertoire des skills de l'agent, dans un dossier nommé « vinayaklatthe-microsoft-security-skills-cloud-app-security-posture ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. onboarder mes clouds dans Defender for Cloud ; activer le plan payant si je veux les chemins d'attaque). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- What
- Posture management across Azure, AWS, GCP and SaaS — Defender for Cloud CSPM + Cloud Apps SSPM, Secure Score, attack paths - **tl_fr:** Gestion de posture multicloud et SaaS — CSPM Defender for Cloud + SSPM Cloud Apps, Secure Score, chemins d'attaque - **creator:** @vinayaklatthe - **type:** Agent skill - **url:** https://github.com/vinayaklatthe/microsoft-security-skills - **cat:** Security - **kws:** cspm, sspm, defender for cloud, secure score, posture, multicloud, saas security, attack path, mcsb - **license:** MIT **Description EN:** Curated by Skill Harbor — security posture management across two layers: CSPM for cloud infrastructure (Defender for Cloud over Azure/AWS/GCP — Secure Score, MCSB benchmarks, attack-path analysis) and SSPM for SaaS (Defender for Cloud Apps over Microsoft 365, Salesforce, ServiceNow, GitHub) — with a lens-picker for what to harden and guidance on when to enable the paid Defender CSPM plan. By @vinayaklatthe, listed here with credit to its creator. Honest caveats: foundational CSPM is free with Defender for Cloud; attack-path analysis, the cloud security graph and agentless scanning need the paid Defender CSPM plan; requires your clouds onboarded to Defender (multicloud connectors). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh. **Description FR:** Sélectionné par Skill Harbor — gestion de la posture de sécurité sur deux couches : CSPM pour l'infrastructure cloud (Defender for Cloud sur Azure/AWS/GCP — Secure Score, benchmarks MCSB, analyse des chemins d'attaque) et SSPM pour le SaaS (Defender for Cloud Apps sur Microsoft 365, Salesforce, ServiceNow, GitHub) — avec un sélecteur de lentille pour ce qu'il faut durcir et des conseils sur quand activer le plan payant Defender CSPM. Crédit : @vinayaklatthe. Bémols honnêtes : le CSPM de fondation est gratuit avec Defender for Cloud ; l'analyse des chemins d'attaque, le graphe de sécurité cloud et le scan agentless nécessitent le plan payant Defender CSPM ; nécessite vos clouds onboardés dans Defender (connecteurs multicloud). Skill Harbor ne vérifie jamais le code, examinez-le vous-même avant usage. Découvert via skills.sh. **Install prompt EN:** ``` Prerequisites: Azure/AWS/GCP accounts to assess, onboarded (or ready to onboard) to Microsoft Defender for Cloud; the attack-path features need the paid Defender CSPM plan Install "Cloud & App Security Posture (CSPM/SSPM)" for me. Give my agent the posture-management guidance — Defender for Cloud CSPM and Defender for Cloud Apps SSPM, Secure Score and MCSB, the posture-lens picker, governance, and when the paid Defender CSPM plan is worth it Repository: https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/cloud-app-security-posture/SKILL.md 1. Fetch the SKILL.md file for the vinayaklatthe-microsoft-security-skills-cloud-app-security-posture skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "vinayaklatthe-microsoft-security-skills-cloud-app-security-posture". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. onboard my clouds to Defender for Cloud; enable the paid plan if I want attack paths). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me. ``` **Install prompt FR:** ``` Prérequis : comptes Azure/AWS/GCP à évaluer, onboardés (ou prêts à l'être) dans Microsoft Defender for Cloud ; les fonctionnalités de chemins d'attaque nécessitent le plan payant Defender CSPM Installe-moi « Posture de sécurité cloud et apps (CSPM/SSPM) ». Donne à mon agent les conseils de gestion de posture — CSPM Defender for Cloud et SSPM Defender for Cloud Apps, Secure Score et MCSB, le sélecteur de lentille de posture, la gouvernance, et quand le plan payant Defender CSPM vaut le coup Dépôt : https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/cloud-app-security-posture/SKILL.md 1. Récupère le fichier SKILL.md du skill vinayaklatthe-microsoft-security-skills-cloud-app-security-posture depuis le dépôt dans un dossier temporaire et résume en une ou deux phrases ce qu'il fait. 2. Contrôle de sécurité : examine le SKILL.md pour tout contenu suspect (appels réseau inattendus, commandes shell, récolte d'identifiants). Ce dépôt ne doit contenir aucun secret dans le code ; les identifiants passent uniquement par le coffre sécurisé, les hôtes autorisés sont déclarés dans le SKILL.md. Vérifie que c'est bien le cas ; STOP sur le moindre signal d'alerte et préviens-moi. 3. Installe-le comme skill : copie SKILL.md dans le répertoire des skills de l'agent, dans un dossier nommé « vinayaklatthe-microsoft-security-skills-cloud-app-security-posture ». 4. Vérifie sans aucun appel réseau : frontmatter valide, fichiers en place. 5. Indique ce qui a été installé, où, et ce qu'il me reste à faire moi-même (p. ex. onboarder mes clouds dans Defender for Cloud ; activer le plan payant si je veux les chemins d'attaque). GitHub est optionnel : si j'ai un compte GitHub ou la CLI gh, tu peux l'utiliser ; sinon l'accès public suffit. Ne jamais l'exiger sauf si c'est dans les prérequis ci-dessus. Règles : ne touche à rien en dehors du dossier temporaire et de la cible d'installation. Si quelque chose semble anormal, arrête-toi et demande-moi. ``` ---
- Cost
- Free
- Needs
- Azure/AWS/GCP accounts to assess, onboarded (or ready to onboard) to Microsoft Defender for Cloud; the attack-path features need the paid Defender CSPM plan
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — security posture management across two layers: CSPM for cloud infrastructure (Defender for Cloud over Azure/AWS/GCP — Secure Score, MCSB benchmarks, attack-path analysis) and SSPM for SaaS (Defender for Cloud Apps over Microsoft 365, Salesforce, ServiceNow, GitHub) — with a lens-picker for what to harden and guidance on when to enable the paid Defender CSPM plan. By @vinayaklatthe, listed here with credit to its creator. Honest caveats: foundational CSPM is free with Defender for Cloud; attack-path analysis, the cloud security graph and agentless scanning need the paid Defender CSPM plan; requires your clouds onboarded to Defender (multicloud connectors). Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: Azure/AWS/GCP accounts to assess, onboarded (or ready to onboard) to Microsoft Defender for Cloud; the attack-path features need the paid Defender CSPM plan Install "Cloud & App Security Posture (CSPM/SSPM)" for me. Give my agent the posture-management guidance — Defender for Cloud CSPM and Defender for Cloud Apps SSPM, Secure Score and MCSB, the posture-lens picker, governance, and when the paid Defender CSPM plan is worth it Repository: https://github.com/vinayaklatthe/microsoft-security-skills/blob/main/skills/cloud-app-security-posture/SKILL.md 1. Fetch the SKILL.md file for the vinayaklatthe-microsoft-security-skills-cloud-app-security-posture skill from the repository into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md into the agent's skills directory, in a folder named "vinayaklatthe-microsoft-security-skills-cloud-app-security-posture". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. onboard my clouds to Defender for Cloud; enable the paid plan if I want attack paths). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.