Atlas / Skills / microsoft / azure-skills

azure-skillsBLOCK

skills/microsoft/azure-skills

Official agent plugin providing skills and MCP server configurations for Azure scenarios.

Verdict
BLOCK
Grade
D
Trust score
69 /100
Version
1.1.1
Hosts
5 documented
License
MIT
Stars
1,550
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Azure work is not just a code problem. It is a decision problem: which service fits this app, what needs to be validated before deployment, which tools should run, and what guardrails matter. The Azure Skills Plugin packages Azure expertise and MCP-backed execution together so compatible coding agents can do real Azure work instead of giving generic cloud advice.

[Explore the Azure Skills site](https://microsoft.github.io/azure-skills/) Landing page maintenance guide

Install the plugin

One install, three layers of capability

Azure skills: the brain

This plugin ships curated Azure skills that teach an agent how Azure work gets done. They provide workflows, decision trees, and guardrails for scenarios such as:

  • Build, deploy, and evolve with azure-prepare, azure-validate, azure-deploy, azure-upgrade, azure-enterprise-infra-planner, azure-hosted-copilot-sdk, azure-kubernetes, and airunway-aks-setup
  • Troubleshoot, monitor, and govern with azure-diagnostics, appinsights-instrumentation, azure-compliance, azure-resource-lookup, and azure-quotas
  • Optimize architecture and cost with azure-cost, azure-compute, azure-resource-visualizer, and azure-cloud-migrate
  • Work across data, AI, identity, and platform services with azure-ai, azure-aigateway, azure-storage, azure-kusto, azure-messaging, azure-rbac, entra-app-registration, and microsoft-foundry

Azure MCP Server: the hands

The plugin wires in the Azure MCP Server, which gives your agent 200+ structured tools across 40+ Azure services. That is the execution layer for listing resources, checking prices, querying logs, diagnosing issues, and driving real Azure workflows.

Foundry MCP: the AI specialist

The plugin also includes Foundry MCP for Microsoft Foundry scenarios such as model discovery, model deployment, and agent workflows.

Read from source at commit c62955f21fc2OBSERVED · 2026-10-08
02

Install

Commands as the repository documents them. They are shown, not run.

npm install @azure/monitor-opentelemetry
pip install azure-monitor-opentelemetry
pip install azure-monitor-opentelemetry-exporter
pip install azure-monitor-opentelemetry
npm install @azure/monitor-opentelemetry
pip install azure-ai-contentsafety
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
codexmentioned
copilotmentioned
cursormentioned
gemini-climentioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: airunway-aks-setup
description: "Set up AI Runway on AKS — from bare cluster to running model. Covers cluster verification, controller install, GPU assessment, provider setup, and first deployment. WHEN: \"setup AI Runway\", \"onboard AKS cluster\", \"install AI Runway\", \"airunway setup\", \"deploy model to AKS\", \"GPU inference on AKS\", \"KAITO setup on AKS\", \"run LLM on AKS\", \"vLLM on AKS\", \"set up model serving on AKS\", \"AI Runway controller\"."
license: MIT
metadata:
  author: Microsoft
  version: "1.1.1"
argument-hint: "[skip-to-step N]"
---

# AI Runway AKS Setup

This skill walks users from a bare Kubernetes cluster to a running AI model deployment. Follow each step in sequence unless the user provides `skip-to-step N` to resume from a specific phase.

> **Cost awareness:** GPU node pools incur significant compute charges (A100-80GB can cost $3–5+/hr). Confirm the user understands cost implications before provisioning GPU resources.

## Prerequisites

This skill assumes an AKS cluster already exists. If the user does not have a cluster, hand off to the `azure-kubernetes` skill first to provision one (with a GPU node pool unless CPU-only inference is acceptable), then return here.

## Quick Reference

| Property | Value |
|----------|-------|
| Best for | End-to-end AI Runway onboarding on AKS |
| CLI tools | `kubectl`, `make`, `curl` |
| MCP tools | None |
| Related skills | `azure-kubernetes` (cluster setup), `azure-diagnostics` (troubleshooting) |

## When to Use This Skill

Use this skill when the user wants to:
- Set up AI Runway on an existing AKS cluster from scratch
- Install the AI Runway controller and CRDs
- Assess GPU hardware compatibility for model deployment
- Choose and install an inference provider (KAITO, Dynamo, KubeRay)
- Deploy their first AI model to AKS via AI Runway
- Resume a partially-complete AI Runway setup from a specific step

## MCP Tools

This skill uses no MCP tools. All cluster operations are performed directly via `kubectl` and `make`.

## Rules

1. Execute steps in sequence — load the reference for each step as you reach it
2. Report cluster state at each step: ✓ healthy, ✗ missing/failed
3. Ask for user confirmation before any install or deployment action
4. If a step is already complete, report status and skip to the next step
5. If the user provides `skip-to-step N`, start at step N; assume prior steps are complete

## Steps

| # | Step | Reference |
|---|------|-----------|
| 1 | **Cluster Verification** — context check, node inventory, GPU detection | [step-1-verify.md](references/steps/step-1-verify.md) |
| 2 | **Controller Installation** — CRD + controller deployment | [step-2-controller.md](references/steps/step-2-controller.md) |
| 3 | **GPU Assessment** — detect GPU models, flag dtype/attention constraints | [step-3-gpu.md](references/steps/step-3-gpu.md) |
| 4 | **Provider Setup** — recommend and install inference provider | [step-4-provider.md](references/steps/step-4-provider.md) |
| 5 | **First Deployment** — pick a model, deploy, verify Ready | [step-5-deploy.md](references/steps/step-5-deploy.md) |
| 6 | **Summary** — recap, smoke test, next steps | [step-6-summary.md](references/steps/step-6-summary.md) |

## Error Handling

| Error / Symptom | Likely Cause | Remediation |
|-----------------|--------------|-------------|
| No kubeconfig context | Not connected to a cluster | Run `az aks get-credentials` or equivalent |
| Controller in CrashLoopBackOff | Config or RBAC issue | `kubectl logs -n airunway-system -l control-plane=controller-manager --previous` |
| Provider not ready | Image pull or RBAC issue | `kubectl logs <pod-name> -n <namespace>` for the provider pod |
| ModelDeployment stuck in Pending | GPU scheduling failure or provider not ready | `kubectl describe modeldeployment <name> -n <namespace>` events |
| `bfloat16` errors at inference | T4 or V100 lacks bfloat16 support | Add `--dtype float16` to serving args |

For full error handling and rollback procedures, see [troubleshooting.md](references/troubleshooting.md).
05

Trust audit

BLOCKgrade D · trust 69/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeFAIL
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
none-observed
Shell
declared (1 observation(s))
Dependencies
not all pinned
Secrets in source
none-found

Findings (25)

HIGHCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
skills/microsoft-foundry/finetuning/scripts/calibrate_grader.py:54
exec(compile(source, grader_path, "exec"), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
HIGHPrompt injection · prompt.hidden_comment · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-aigateway/references/policies.md:178
<!-- Jailbreak detection is automatic when content safety is enabled -->
Why it matters. directive hidden in a comment the user does not see rendered
Fix. remove the comment
HIGHPrompt injection · prompt.hidden_comment · CWE-94, CWE-1427
skills/azure-aigateway/references/policies.md:178
<!-- Jailbreak detection is automatic when content safety is enabled -->
Why it matters. directive hidden in a comment the user does not see rendered
Fix. remove the comment
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-reliability/SKILL.md:247
After patching, **the skill runs the deploy itself** (do not stop and tell the user to run it). Detect the deployment tool and confirm once before executing:
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-reliability/SKILL.md:348
3. On **yes**, **the skill runs the deploy itself** (`azd up` / `az deployment group create` / `terraform apply`) and streams output. Do not stop and tell the user to run it.
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-reliability/references/iac-patching-bicep.md:178
After patching, **the skill executes the deploys itself** — do not stop and tell the user to run commands. Confirm once with the user before each deploy, then run it.
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-reliability/references/iac-patching-terraform.md:109
After patching, **the skill executes the deploys itself** — do not stop and tell the user to run commands. Confirm once with the user before each deploy, then run it.
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.hide_from_user · CWE-94, CWE-1427
skills/azure-reliability/SKILL.md:247
After patching, **the skill runs the deploy itself** (do not stop and tell the user to run it). Detect the deployment tool and confirm once before executing:
Why it matters. asks the agent to act without the user's knowledge
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
.github/plugins/azure-cost/skills/cost-analysis/references/cost-query/workflow.md:52
| Date outside 92 days | Narrow the period; fallback does not bypass this guardrail. |
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-aigateway/references/policies.md:168
### Jailbreak Detection
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.override · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-aigateway/references/policies.md:170
Block prompt injection attacks that attempt to bypass AI safety guardrails.
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-app-onboard-prereq/references/dependency-compatibility.md:1
Dependency compatibility checks for Azure. Part of the [deployability check](deployability-check.md).
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
skills/azure-app-onboard-prereq/references/dependency-compatibility.md:1
Dependency compatibility checks for Azure. Part of the [deployability check](deployability-check.md).
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
LOWCode injection · code.eval_exec · CWE-78, CWE-94, CWE-95
.github/plugins/azure-skills/skills/microsoft-foundry/finetuning/scripts/calibrate_grader.py:54
exec(compile(source, grader_path, "exec"), namespace)
Why it matters. evaluates text as code
Fix. remove; use a parser or a dispatch table
LOWFilesystem / path · fs.credential_store · CWE-22, CWE-59
.github/plugins/foundry-iq-skills/skills/foundry-iq/helpers/file_ingest.py:113
or lowered[-1] in {"id_rsa", "id_dsa", "id_ecdsa", "id_ed25519"}
Why it matters. touches a credential store
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-app-deploy/knowledge-packs/frameworks/django.md:162
Gunicorn logs the port on startup: `Listening at: http://0.0.0.0:8000`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-app-deploy/knowledge-packs/frameworks/fastapi.md:157
Uvicorn logs the port on startup: `Uvicorn running on http://0.0.0.0:8000`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-app-deploy/knowledge-packs/frameworks/flask.md:172
Gunicorn logs the port on startup: `Listening at: http://0.0.0.0:8000`
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/plugins/azure-skills/skills/entra-agent-id/references/sdk-sidecar-deployment.md:168
value: "http://127.0.0.1:5000"
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
.github/plugins/azure-skills/skills/entra-agent-id/references/sdk-sidecar-deployment.md:184
1. **Bind to localhost** — `Kestrel__Endpoints__Http__Url=http://127.0.0.1:5000`
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
landing-page/package.json
@astrojs/check, @iconify-json/lucide, @iconify-json/simple-icons, @tailwindcss/postcss, @types/node, astro, astro-expressive-code, astro-icon
Why it matters. 13 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-aigateway/SKILL.md:3
description: "Configure Azure API Management as an AI Gateway for AI models, MCP tools, and agents. WHEN: semantic caching, token limit, content safety, load balancing, AI model governance, MCP rate l
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.override · CWE-94, CWE-1427
.github/plugins/azure-skills/skills/azure-aigateway/SKILL.md:23
| **Agent Governance** | "content safety", "jailbreak detection", "filter harmful content" |
Why it matters. asks the agent to drop prior instructions or safety
Fix. remove the instruction
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.github/plugins/azure-kusto-graph-skills/CHANGELOG.md:33
- feat: report session start telemetry ([#3216](https://github.com/microsoft/GitHub-Copilot-for-Azure/pull/3216))
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
.github/plugins/azure-local-skills/CHANGELOG.md:33
- feat: report session start telemetry ([#3216](https://github.com/microsoft/GitHub-Copilot-for-Azure/pull/3216))
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: instruction_override, no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha c62955f21fc2full audit observations/trust-audit/skill/microsoft__azure-skills.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-08c62955f21fc2BLOCKD69first audit
07

Questions

What does the azure-skills skill do?

Official agent plugin providing skills and MCP server configurations for Azure scenarios.

Is azure-skills safe to install?

No — not without reading the findings first. The audit graded it D (69/100) and found 13 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What can azure-skills access on my machine?

The audit observed that it runs shell commands and reads or writes files. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does azure-skills work with?

Its documentation mentions claude-code, codex, copilot, cursor and gemini-cli. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (c62955f21fc2), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement