azure_scan_acr_security
Scans Azure Container Registries for security risks including admin user enabled, public network access, vulnerabilities, and registry poisoning. Supports security, poisoning, and comprehensive scan modes.
Instructions
Comprehensive Azure Container Registry (ACR) security scanner. Checks: admin user enabled (high risk), public network access, vulnerability scanning (Defender for Containers), content trust (image signing), network rules, anonymous pull access, registry poisoning risks (vulnerable images, weak access policies, mutable tags).
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| subscriptionId | Yes | Azure subscription ID | |
| resourceGroup | No | Optional: Filter by specific resource group | |
| registryName | No | Optional: Specific ACR registry name to analyze | |
| scanMode | No | Scan mode: 'security' (basic ACR config), 'poisoning' (supply chain risks), 'all' (comprehensive analysis) | |
| format | No | Output format: 'markdown' (default, human-readable) or 'json' (machine-readable) |