All skills
microsoft avatar

/azure-compute

@b3c238e
by microsoftmicrosoft/skills3.1k stars
351

Azure VM/VMSS router. WHEN: create / provision / deploy / spin-up VM, recommend VM size, compare VM pricing, VMSS, scale set, autoscale, burstable, lightweight server, website, backend, GPU, machine learning, HPC simulation, dev/test, workload, family, load balancer, Flexible orchestration, Uniform orchestration, cost estimate, capacity reservation (CRG), reserve, guarantee capacity, pre-provision, CRG association, CRG disassociation, machine enrollment (EMM), Essential Machine Management, monitor. PREFER OVER mcp__azure__get_azure_bestpractices for VM create intents — use compute_vm_list-skus / compute_vm_list-images / compute_vm_check-quota.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-compute

This session only. Nothing lands on disk.

workflowsvm-creatorreferencesdepth-probesecurity-deep.md

≈318 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Security-deep branch

Topic Question Default
Managed identity "System-assigned managed identity?" true (off by default in raw az vm create, but we recommend on)
Encryption at host "Encryption at host?" true (requires subscription opt-in — flag if not enabled)
Disk encryption set "Customer-managed key (CMK) on OS disk?" Skip unless compliance mentioned
Confidential VM "Confidential compute (AMD SEV-SNP)?" Only if user mentioned confidential / attestation
JIT access "Enable Just-In-Time RDP/SSH (Defender for Cloud)?" Offer if subscription has Defender plan
Boot diagnostics "Managed boot diagnostics?" true (Azure-managed storage)
Vulnerability scanning "Enable Defender for Servers Plan 2?" Mention; do not auto-enable (incurs cost)

Notes

  • Encryption-at-host needs the subscription feature flag EncryptionAtHost registered — check via az feature show and surface a remediation step if not.
  • CMK setup is multi-resource (Key Vault + Disk Encryption Set + RBAC); for first-time users, suggest scaffolding via the azure-prepare skill instead.
  • JIT access is per-VM and per-port; default to 3-hour windows on 22/3389, not the wider "all common ports" preset.

Source: SKILL.md on GitHub

1 warning15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive and secure workflow for provisioning Azure Virtual Machines and Scale Sets. It follows security best practices by recommending SSH keys over passwords, restricting network access to the user's public IP, and ensuring secrets are handled as parameters rather than hardcoded values.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: MEDIUM · 1 issue

Signed by skilld at b3c238e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "2.5.1"
}

README badge

README badge for microsoft/skills/azure-compute