cipp-alerts — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cipp-alerts (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
CIPP raises alerts based on standards violations, anomaly detection, and configured thresholds. The two tools in this skill let you triage the alert queue and pull underlying audit log evidence.
cipp_list_alert_queuecipp_list_alert_queue()Returns queued alerts across all tenants — alert type, tenant, severity, raised time, and current status. This is your daily triage list.
cipp_list_audit_logscipp_list_audit_logs(tenantFilter='contoso.onmicrosoft.com',
startDate?, endDate?,
userId?, operation?)Tenant-scoped audit log entries from the M365 unified audit log. Filter by date range, user, or operation to narrow investigation scope. Use to investigate suspicious sign-ins, admin role changes, mailbox access, app consent grants, and policy modifications.
cipp_list_alert_queue — pull the full queuetenant + alertType to spot patterns (one tenant generating most alerts often signals a broken standard or runaway script)cipp_list_audit_logs filtered to the alert windowalerts = cipp_list_alert_queue()
critical = [a for a in alerts if a['severity'] == 'critical']
for a in critical:
logs = cipp_list_audit_logs(
tenantFilter=a['tenantId'],
startDate=a['raisedAt'] - 30 minutes,
endDate=a['raisedAt'] + 5 minutes,
)The 30-minute lookback usually captures the precipitating event (sign-in, admin change, app consent) that caused the alert.
operation value | What it surfaces |
|---|---|
UserLoggedIn | Sign-in events |
Add member to role | Role escalation |
Consent to application | New app permissions granted |
New-InboxRule | Mailbox rule creation (BEC indicator) |
Set-Mailbox | Mailbox config changes |
Add policy | Conditional access policy created |
Update conditional access policy | CA policy modified |
When cipp_bec_check flags a user, supplement it with audit log queries:
UserLoggedIn operations for the user over the last 7 days — look for unusual countries, IPs, or bursts of failed → success patternsNew-InboxRule and Set-Mailbox operations — hidden forwarding/auto-delete rulesConsent to application operations — illicit consent grants are common BEC vectorscipp_list_alert_queue returns active queue items — historic resolved alerts require the CIPP UI.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.