All skills
lukemurraynz avatar

/azure-sre-agent

@2cc2455

Design, configure, review, and operate production-grade Azure SRE Agent capabilities: response plans, scheduled tasks, HTTP triggers, custom agents, autonomous and review workflows, approval guardrails, AMBA observability, source RCA, connectors, MCP, governance hooks, WAF reviews, AI Foundry posture, Digital Native governance, postmortem generation, and KT discipline.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/azure-sre-agent

This session only. Nothing lands on disk.

README.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure SRE Agent Skill

Production-oriented GitHub Copilot agent skill for designing, configuring, reviewing, and operating Azure SRE Agent in new Azure projects.

Install

Copy this folder to one of the supported Agent Skills locations. Common locations are:

Scope Location
GitHub/Copilot project skill .github/skills/azure-sre-agent/
Claude-compatible project skill .claude/skills/azure-sre-agent/
Cross-agent project skill .agents/skills/azure-sre-agent/
Personal Copilot skill ~/.copilot/skills/azure-sre-agent/
Personal cross-agent skill ~/.agents/skills/azure-sre-agent/

The skill entry point is SKILL.md. Keep that file lean and load deeper files only when the task requires them.

Getting started

  1. Run python scripts/validate-skill.py from the skill root to confirm the package is structurally clean.
  2. Read SKILL.md if you are designing or reviewing an Azure SRE Agent capability.
  3. Read bundles/README.md if you are adding or extending a bundle.
  4. See CHANGELOG.md for version history and QUALITY-REVIEW.md for the latest review and known [VERIFY] items.

What This Skill Covers

  • Azure SRE Agent production baseline design
  • Response plans, scheduled tasks, HTTP-triggered workflows, and custom agents
  • AMBA-aligned Azure Monitor alert baselines, alert-to-response-plan mapping, alert tuning, and policy compliance reviews
  • Source-code RCA, deployment regression analysis, IaC drift triage, and PR remediation readiness
  • AKS, Container Apps, Drasi-on-AKS, App Service, Functions, SQL, Storage, API Management, Key Vault, and edge/network operational bundles
  • Connector and MCP security patterns
  • Managed connector governance, parameter policies, credential isolation, and Ask approval caveats in Autonomous mode
  • Identity, RBAC, OBO fallback, private-network readiness, and approval hooks
  • Cost, AAU, run-mode (ReadOnly/Review/Autonomous), access level, model tier, upgrade channel, 80-tool budget, Application Insights audit events, value tracking, quality-score, and autonomy-promotion controls
  • Resource-boundary guidance for AI Search, Document Intelligence, Storage, Cosmos DB, Key Vault, and observability stores
  • Lightweight KT governance without unnecessary agent runtime overhead
  • Output examples for design reviews, incident triage, autonomy promotion, and HTTP-trigger readiness

See SKILL.md for the current KT depth rules, AMBA baseline posture, stop conditions, anti-hallucination requirements, and production quality gate.

Term aliases

Use these equivalents when searching the package:

  • custom agent = sub-agent
  • approval workflow = human-in-the-loop
  • HTTP trigger = HTTP webhook
  • connectors and managed connectors are the primary tool-calling surface for external systems

Template Status

YAML files in bundles/ are templates. Replace all @@PLACEHOLDER@@ values, verify the current Azure SRE Agent schema, and test in the SRE Agent playground before attaching to production plans/tasks/triggers.

Use parameters.example.yaml as a substitution checklist.

Validation

Run from the skill root:

python scripts/validate-skill.py

The validator checks Agent Skills frontmatter rules, BOM status, YAML/JSON parsing, bundle references, catalog/manifest version parity, required production-factory bundles, local Markdown links, unresolved placeholders, Review-mode defaults, HTTP-trigger safety defaults, custom-agent allowed_skills, accidental secret patterns, duplicate governance artifacts, and top-level skill size.

When available, also run:

gh skill publish --dry-run
# or
skills-ref validate .

See validation-and-release.md for the release checklist.

Source Freshness

Azure SRE Agent capabilities, supported regions, AAU rates, hooks, managed connectors, MCP, HTTP triggers, AMBA policies, audit events, and provider behavior change quickly. Before production cutover, re-check the sources in references/source-map.md.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The Azure SRE Agent skill provides a production-grade framework for managing Azure infrastructure using AI agents. It incorporates extensive safety documentation, approval-based hooks, and least-privilege role templates. The 'low' verdict is assigned due to the inherent risk of indirect prompt injection when the agent processes external incident data and source code, a necessary function for its SRE capabilities.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
compatibility
Azure SRE Agent; GitHub Copilot agent skills; new projects only
Other metadata
metadata
{
  "last_verified": "2026-08-25",
  "version": "2.23.3",
  "risk": "critical",
  "last_updated": "2026-08-25"
}

README badge

README badge for lukemurraynz/hve-agent-skills/azure-sre-agent