All skills
lukemurraynz avatar

/azure-sre-agent

@2cc2455

Design, configure, review, and operate production-grade Azure SRE Agent capabilities: response plans, scheduled tasks, HTTP triggers, custom agents, autonomous and review workflows, approval guardrails, AMBA observability, source RCA, connectors, MCP, governance hooks, WAF reviews, AI Foundry posture, Digital Native governance, postmortem generation, and KT discipline.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/azure-sre-agent

This session only. Nothing lands on disk.

referencesknowledge-lifecycle.md

≈611 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Knowledge Lifecycle Reference

Use knowledge capture to make future investigations faster without creating stale runbook sprawl.

Capture Only Reusable Knowledge

Capture confirmed patterns, detection signals, safe diagnostic commands, mitigation decision criteria, and prevention actions. Avoid copying long incident transcripts or speculative hypotheses.

Lifecycle

  1. After useful incidents, draft a known-error record or focused runbook update.
  2. Review knowledge quality before publishing.
  3. Set owner and review date.
  4. Run scheduled stale-runbook reviews.
  5. Retire or rewrite outdated content.

Evaluation Data Quality Tiers

Use quality tiers to gate autonomy promotion. An agent workflow is only ready for L3 (Autonomous) when its evaluation data includes Gold-quality entries validated against real incidents.

Tier Source Use for
Bronze Auto-generated from incident metadata, heuristic labels, or agent-suggested mitigations Initial training data, broad coverage, cold-start
Silver Programmatically generated but calibrated against Gold data; minimum confidence threshold enforced Nightly evaluations, regression gates, release readiness
Gold Human-verified mitigation labels; exact action, parameters, and outcome confirmed Autonomy promotion gates, precision/recall measurement

Generating Gold data without overhead: When an oncaller declares an incident mitigated, auto-suggest the exact mitigation applied (action, target, parameters). The SRE accepts, modifies, or rejects during their standard workflow, this feeds Gold labels back into the evaluation pipeline with zero extra steps.

Calibration: Silver data must be mathematically calibrated against Gold to measure True Precision (not Observed Precision). Use stratified sampling to surface diverse incidents for manual Gold review, this catches edge cases that heuristic Bronze labels miss.

When to use each tier:

  • New workflow in Review → Bronze is sufficient for initial training.
  • Promoting to L3 Autonomous → must have Silver-calibrated evaluation data.
  • High-risk or write-heavy workflows → require Gold-verified entries before any autonomous execution.

KT Fit

  • P1/P2: include full KT summary where useful.
  • P3/P4: capture concise symptom, cause, action, and validation.
  • Read-only health checks: only capture knowledge when a repeated pattern is found.

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The Azure SRE Agent skill provides a production-grade framework for managing Azure infrastructure using AI agents. It incorporates extensive safety documentation, approval-based hooks, and least-privilege role templates. The 'low' verdict is assigned due to the inherent risk of indirect prompt injection when the agent processes external incident data and source code, a necessary function for its SRE capabilities.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
compatibility
Azure SRE Agent; GitHub Copilot agent skills; new projects only
Other metadata
metadata
{
  "last_verified": "2026-08-25",
  "version": "2.23.3",
  "risk": "critical",
  "last_updated": "2026-08-25"
}

README badge

README badge for lukemurraynz/hve-agent-skills/azure-sre-agent