Harden Tool Url Inputs
microsoft/mcp/.github/skills/harden-tool-url-inputsdevopsOfficial
Official Provider SkillView repo
Audit and harden one or more tool directories against URL hijacking and SSRF by tracing MCP inputs to URL construction and applying EndpointValidator with cloud-specific Azure endpoint allow-lists. Use when: validate URL inputs, secure endpoints, prevent URL hijacking, SSRF hardening, audit tool directories, apply EndpointValidator.
Files1 files
SKILL.md272 lines
Loading editor…
Install
RecommendedOne command — your agent picks it up automatically.
Select an AI agent above to see the install command.
or
Manual Install
More stepsDownload the file and paste it into your agent's system prompt.
Skill details
Versionv1.0.0
AuthorMicrosoft
Categorydevops
Skill IDmicrosoft/mcp/.github/skills/harden-tool-url-inputs
Related skills
Add Azure Mcp ToolsAdd a new tool/command to any Azure MCP toolset. Full lifecycle from scaffolding through PR submission. USE WHEN: add new command, create tool, new MCP tool, scaffold command, implement operation, add azure service tool, create new toolset.Agentic WorkflowsRoute gh-aw workflow design/create/debug/upgrade requests to the right prompts.Azurebackup Add ToolAdd a new tool/command to the Azure Backup MCP toolset. Covers the full lifecycle: command implementation, option definitions, service layer, input validation, unit tests, live tests, recorded test playback, CI validation, spell check, changelog entry, tool description evaluation, and PR checklist. USE WHEN: add new backup command, create backup tool, implement backup operation, new azurebackup command, add MCP tool for backup, new vault operation, new policy command, new governance command.Azurebackup Telemetry ReportGenerate weekly telemetry reports and customer adoption reports for Azure Backup MCP tools. Runs KQL queries against the Kusto telemetry cluster, analyzes error patterns with 3-way classification (Customer/Azure Service/MCP Tool Bug), identifies customers via P360/C360 cross-cluster joins, compares week-over-week metrics, correlates with merged PRs and releases, and produces an Outlook-compatible HTML report. USE WHEN: weekly telemetry report, Azure Backup MCP telemetry, error analysis, telemetrMcp Code ReviewerReview MCP pull requests with repository-specific security, correctness, architecture, testing, and completeness checks. Use when: review PR, review pull request, code review, inspect PR, check PR, PR feedback.Resilience Management OperationsOperate all Azure Resilience Management MCP tools and automate new tool delivery from API selection through implementation, live testing, recording, PR creation, review fixes, and merge-conflict resolution. Use when: list/get/create/update/delete resilience resources; configure, validate, run, resync, or end drills; include/exclude recovery resources; check readiness; validate or execute recovery operations; monitor, retry, or resume recovery jobs; implement, add, test, record, or deliver a Resi