All skills
lukemurraynz avatar

/azure-sre-agent

@2cc2455

Design, configure, review, and operate production-grade Azure SRE Agent capabilities: response plans, scheduled tasks, HTTP triggers, custom agents, autonomous and review workflows, approval guardrails, AMBA observability, source RCA, connectors, MCP, governance hooks, WAF reviews, AI Foundry posture, Digital Native governance, postmortem generation, and KT discipline.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/azure-sre-agent

This session only. Nothing lands on disk.

referencesconnector-token-security.md

≈796 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Connector Token Security and Operations

Use this guide for secure production connector credential practices.

Security Defaults

  1. Use service accounts for production connectors.
  2. Avoid personal tokens for long-lived integrations.
  3. Grant least privilege required for each connector.
  4. Store tokens in secure secret stores and rotate on schedule.
  5. Monitor token usage and revoke on suspicion or personnel change.
  6. Scope tokens by operation, environment, and resource where the provider supports it.
  7. Do not give agent-accessible connectors root, owner, tenant-wide, or account-wide destructive permissions when narrower scopes exist.
  8. Use separate credentials for read-only, write, admin/RBAC, and destructive tool groups.
  9. Prefer just-in-time or short-lived credentials for production write or destructive workflows.
  10. Require an external approval or policy gate before issuing or using credentials that can delete, reset, rotate, migrate, transfer, or overwrite production resources.

PagerDuty Token Pattern

Preferred model:

  1. dedicated PagerDuty service account
  2. role scoped to required operations (Responder/Observer style)
  3. user API token format in connector auth (Token @@CONNECTOR_TOKEN@@)

Do not use account-level API key where user token is required by MCP server.

Azure Managed Grafana Token Pattern

Preferred model:

  1. Grafana service account token for persistent agent connectivity
  2. Viewer role by default
  3. elevate to Editor/Admin only when required

Alternative:

  • Entra ID token for managed identity/service principal, with role assignment.
  • Treat Entra token flow as short-lived and refresh-aware.

Dynatrace Token Pattern

Use platform token with minimum scopes:

  1. MCP gateway invoke/read scopes
  2. add only required query/problem/security scopes for enabled workflows

Keep scoped token per environment (dev/stage/prod), not global.

Rotation and Ownership

Set a default connector token policy:

  1. owner: team mailbox + on-call group, not individual user
  2. rotation cadence: 30-90 days based on risk
  3. immediate rotation triggers:
    • role change/offboarding
    • credential leak suspicion
    • failed audit

Validation After Rotation

After each credential rotation:

  1. verify connector state is Connected
  2. run one read-only tool test
  3. run one workflow test (if applicable)
  4. confirm no degraded automations

Incident Response for Token Failures

When status flips to Failed:

  1. check auth header format
  2. verify endpoint URL and region
  3. verify token scopes/roles
  4. rotate token if uncertain
  5. retest and document recovery

Sources

Bundle Mapping

Connector templates live in:

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The Azure SRE Agent skill provides a production-grade framework for managing Azure infrastructure using AI agents. It incorporates extensive safety documentation, approval-based hooks, and least-privilege role templates. The 'low' verdict is assigned due to the inherent risk of indirect prompt injection when the agent processes external incident data and source code, a necessary function for its SRE capabilities.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
compatibility
Azure SRE Agent; GitHub Copilot agent skills; new projects only
Other metadata
metadata
{
  "last_verified": "2026-08-25",
  "version": "2.23.3",
  "risk": "critical",
  "last_updated": "2026-08-25"
}

README badge

README badge for lukemurraynz/hve-agent-skills/azure-sre-agent