做什么
引导微软Entra ID应用注册,OAuth 2.0认证,以及MSAL集成. USE FOR:创建应用注册,注册Azure AD应用,配置OAuth,设置认证,添加API权限,生成服务主机,MSAL实例,控制台应用认证,Entra ID设置,Azure AD认证. 不为: 键 断层机密(使用azure-keyvault-expuration-audit),一般Azure资源安全指导.
技能库 智客分类:安全测试 entra-app-registration
引导微软Entra ID应用注册,OAuth 2.0认证,以及MSAL集成. USE FOR:创建应用注册,注册Azure AD应用,配置OAuth,设置认证,添加API权限,生成服务主机,MSAL实例,控制台应用认证,Entra ID设置,Azure AD认证. 不为: 键 断层机密(使用azure-keyvault-expuration-audit),一般Azure资源安全指导.
官方网址:skills.sh
先看中文介绍;官方 description 原文单独保留,不改写 SKILL.md。
引导微软Entra ID应用注册,OAuth 2.0认证,以及MSAL集成. USE FOR:创建应用注册,注册Azure AD应用,配置OAuth,设置认证,添加API权限,生成服务主机,MSAL实例,控制台应用认证,Entra ID设置,Azure AD认证. 不为: 键 断层机密(使用azure-keyvault-expuration-audit),一般Azure资源安全指导.
官方 description 未单独写出 Use when。按规范,代理会在用户任务与这段 description 的关键词匹配时激活本技能。
按 Agent Skills 渐进披露:启动时只加载 name 与 description(约 100 token);任务匹配后才读入整份 SKILL.md 正文;scripts/、references/、assets/ 仅在需要时再读。 本文件正文结构:Overview、Key Concepts、Application Types、Core Workflow、Step 1: Register the Application、Step 2: Configure Authentication。 其中含规范建议的小节:分步指令。
文件分析:除 SKILL.md 外,正文引用了 references/cli-commands.md、references/BICEP-EXAMPLE.bicep、references/api-permissions.md、references/oauth-flows.md、references/console-app-example.md、references/first-app-registration.md,属于带资源的技能包,这些文件按需再读。
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration. USE FOR: create app registration, register Azure AD app, configure OAuth, set up authentication, add API permissions, generate service principal, MSAL example, console app auth, Entra ID setup, Azure AD authentication. DO NOT USE FOR: Key Vault secrets (use azure-keyvault-expiration-audit), general Azure resource security guidance.
OverviewKey ConceptsApplication TypesCore WorkflowStep 1: Register the ApplicationStep 2: Configure AuthenticationStep 3: Configure API PermissionsStep 4: Create Client Credentials (if needed)Step 5: Implement OAuth FlowCommon PatternsPattern 1: First-Time App RegistrationPattern 2: Console Application with User Authentication
· 许可:MIT
来源分类:skills.sh agent-skill
nameentra-app-registrationdescriptionreferences/cli-commands.mdreferences/BICEP-EXAMPLE.bicepreferences/api-permissions.mdreferences/oauth-flows.mdreferences/console-app-example.mdreferences/first-app-registration.md以下路径提取自原文;文件是否齐全请以来源仓库中的完整目录为准。
具体调用语法与可用工具以目标 Agent 客户端为准。 查看调用机制说明 ↗
先选择目标 Agent 和安装范围,保留技能包的附属文件,安装后检查客户端能否发现该技能。
该技能引用了附属文件,请从来源获取完整目录;仅复制 SKILL.md 可能缺少依赖。
复制安装指令给支持 Agent Skills 的代理,确认其中的目标目录与客户端匹配。
把 Agent Skill「entra-app-registration」安装到我的项目:SKILL.md 原文与官方 description 见 https://zicq.com/zh/skills/skl-fecb9bbfa87a60cb-Entra-App-Registration.html 请存为 .cursor/skills/entra-app-registration/SKILL.md 或 .claude/skills/entra-app-registration/SKILL.md,frontmatter 的 name 与 description 保持原样,不要改写。 该技能还带 scripts/、references/、assets/ 等文件,请从 https://github.com/microsoft/azure-skills 取完整目录,不要只建一个 SKILL.md。
需要 Node.js 与 npx。先查看仓库技能列表,确认实际名称。
npx skills add 'https://github.com/microsoft/azure-skills' --list
npx skills add 'https://github.com/microsoft/azure-skills' --skill 'entra-app-registration'
CLI 会交互选择目标 Agent,默认安装到项目;用户级安装使用 -g。先通过查看命令核对仓库内容,再用 npx skills list 检查已安装技能。
Microsoft Entra ID (formerly Azure Active Directory) is Microsoft's cloud-based identity and access management service. App registrations allow applications to authenticate users and access Azure resources securely.
| Concept | Description | |---------|-------------| | App Registration | Configuration that allows an app to use Microsoft identity platform | | Application (Client) ID | Unique identifier for your application | | Tenant ID | Unique identifier for your Azure AD tenant/directory | | Client Secret | Password for the application (confidential clients only) | | Redirect URI | URL where authentication responses are sent | | API Permissions | Access scopes your app requests | | Service Principal | Identity created in your tenant when you register an app |
| Type | Use Case | |------|----------| | Web Application | Server-side apps, APIs | | Single Page App (SPA) | JavaScript/React/Angular apps | | Mobile/Native App | Desktop, mobile apps | | Daemon/Service | Background services, APIs |
Create an app registration in the Azure portal or using Azure CLI.
Portal Method:
CLI Method: See references/cli-commands.md IaC Method: See references/BICEP-EXAMPLE.bicep
It's highly recommended to use the IaC to manage Entra app registration if you already use IaC in your project, need a scalable solution for managing lots of app registrations or need fine-grained audit history of the configuration changes.
Set up authentication settings based on your application type.
http://localhost or custom URI schemeGrant your application permission to access Microsoft APIs or your own APIs.
Common Microsoft Graph Permissions:
User.Read - Read user profileUser.ReadWrite.All - Read and write all usersDirectory.Read.All - Read directory dataMail.Send - Send mail as a userDetails: See references/api-permissions.md
For confidential client applications (web apps, services), create a client secret, certificate or federated identity credential.
Client Secret:
Certificate: For production environments, use certificates instead of secrets for enhanced security. Upload certificate via "Certificates & secrets" section.
Federated Identity Credential: For dynamically authenticating the confidential client to Entra platform.
Integrate the OAuth flow into your application code.
See:
Walk user through their first app registration step-by-step.
Required Information:
Script: See references/first-app-registration.md
Create a .NET/Python/Node.js console app that authenticates users.
Required Information:
Example: See references/console-app-example.md
Set up daemon/service authentication without user interaction.
Required Information:
Implementation: Use Client Credentials flow (see references/oauth-flows.md#client-credentials-flow)
| Command | Purpose |
|---------|---------|
| az ad app create | Create new app registration |
| az ad app list | List app registrations |
| az ad app show | Show app details |
| az ad app permission add | Add API permission |
| az ad app credential reset | Generate new client secret |
| az ad sp create | Create service principal |
Complete reference: See references/cli-commands.md
MSAL is the recommended library for integrating Microsoft identity platform.
Supported Languages:
Microsoft.Identity.Client@azure/msal-browser, @azure/msal-nodemsalExamples: See references/console-app-example.md
| Practice | Recommendation | |----------|---------------| | Never hardcode secrets | Use environment variables, Azure Key Vault, or managed identity | | Rotate secrets regularly | Set expiration, automate rotation | | Use certificates over secrets | More secure for production | | Least privilege permissions | Request only required API permissions | | Enable MFA | Require multi-factor authentication for users | | Use managed identity | For Azure-hosted apps, avoid secrets entirely | | Validate tokens | Always validate issuer, audience, expiration | | Use HTTPS only | All redirect URIs must use HTTPS (except localhost) | | Monitor sign-ins | Use Entra ID sign-in logs for anomaly detection |
安全测试
人工智能特工的安全第一技能审查。 在安装来自 ClawdHub, GitHub 或其他来源的任何技能之前使用 。 检查红旗,许可范围,可疑图案.
安全测试
MoltGuard——由OpenGuardrails担任OpenClaw保安. 安装 MoltGuard 以保护你和你的人类免受迅速注射、数据过滤和恶意命令的影响。 资料来源:https://github.com/openguardrails/openguardrails/tre…
安全测试
用于审查安全漏洞代码,实施认证流,审计OWASP Top 10,配置CORS/CSP头,处理秘密,输入验证,SQL注射预防,XSS保护,或任何与安全相关的代码审查.
安全测试
安装任何AI代理技能前的安全审查协议. 红旗侦取入证盗取,疏通密码,放出. 风险分类:低/中/高/高。 编制结构化审查报告。 不先运行此功能, 绝不安装不信任的技能 .