Use 'Azure MCP/documentation' tool to find the minimal role definition that matches the desired permissions the user wants to assign to an identity (If no built-in role matches the desired permissions, use 'Azure MCP/extension_cli_generate' tool to create a custom role definition with the desired permissions). Use 'Azure MCP/extension_cli_generate' tool to generate the CLI commands needed to assign that role to the identity and use the 'Azure MCP/bicepschema' and the 'Azure MCP/get_bestpractices' tool to provide a Bicep code snippet for adding the role assignment.
Ask your Agent
Use this Skill: https://skilld.dev/gh/github/awesome-copilot/azure-role-selector
This session only. Nothing lands on disk.
≈63 tokens always: the name and description. ≈143 when used: this file.
Source: SKILL.md on GitHub
Third-party checks
1 warning16d5 checks · Risk SAFE
- Gen Agent Trust Hub16d
The skill is safe and presents no security issues. It assists users in identifying the minimal Azure roles required for specified permissions and provides relevant Bicep code snippets or CLI commands for implementation.
- Socket16d
No alerts
- Snyk16d
Risk: LOW · No issues
- Runlayer7mo
1/2 files flagged
- ZeroLeaks5mo
Score: 93/100 · 2 sections analyzed
Provenance
Signed by skilld at 78e0b5a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.
Last checked against GitHub 18 hours ago.
Capability
All 4 allowed tools
Topics
- azure
- iam
- rbac
- role-assignment
- least-privilege
- bicep
- access-control
README badge
What it does
Helps select the least-privilege Azure role for a given set of permissions, consulting built-in roles first and generating custom role definitions when needed. Provides both Azure CLI commands and Bicep code for applying the role assignment.
Generated from the current SKILL.md.
Frequently asked
Does this skill help me find the least-privilege role for a given set of permissions?
Can this skill generate CLI commands and Bicep code for role assignment?
What happens if no Azure built-in role matches my permissions requirements?
Does this require access to Azure documentation and best practices?
Generated from the current SKILL.md. These answers refresh after source changes.