All skills
microsoft avatar

/azure-diagnostics

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. WHEN: debug production issues, troubleshoot app service, app service high CPU, app service deployment failure, troubleshoot container apps, troubleshoot functions, troubleshoot AKS, VM RDP, Linux SSH, VM black screen, can't connect to VM, reset VM password, NSG or firewall blocking, kubectl cannot connect, kube-system/CoreDNS failures, pod pending, crashloop, node not ready, upgrade failures, analyze logs, KQL, insights, image pull failures, cold start issues, health probe failures, resource health, root cause of errors, troubleshoot event hubs, troubleshoot service bus, messaging SDK error, AMQP connection failure, message lock lost, service bus dead letter.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-diagnostics

This session only. Nothing lands on disk.

troubleshootingcomputevm-troubleshooting.md

≈846 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure VM Connectivity Troubleshooting

Primary compute troubleshooting guide for incidents routed from ../../SKILL.md. Use for Azure VM RDP/SSH failures, NSG/firewall blocks, credential resets, and VM agent/tooling issues.

Quick Reference

Property Details
Best for RDP/SSH failures, port 3389/22 timeouts, black screen, credential reset, VM agent issues
Primary tools mcp_azure_mcp_compute, mcp_azure_mcp_resourcehealth, mcp_azure_mcp_monitor, CLI fallback
Router references/cannot-connect-to-vm.md

MCP Tools

Tool Purpose
mcp_azure_mcp_compute VM state, instance view, VM agent, extension, NIC evidence
mcp_azure_mcp_resourcehealth Platform health before deeper diagnosis
mcp_azure_mcp_monitor Logs/metrics when workspace or resource scope is known
mcp_azure_mcp_documentation Current Microsoft Learn guidance for the matched symptom

When to Use

  • "can't connect to my VM", "can't RDP", "can't SSH"
  • RDP/SSH timeout, refused, black screen, internal error, session drop
  • reset VM password, wrong credentials, access denied
  • NSG, guest firewall, port 3389/22, public IP, NIC, Serial Console, Run Command, VM agent

Guardrails

  • Default to read-only diagnostics; quote evidence before concluding root cause.
  • Do not run extension-backed commands (az vm user update, az vm user reset-ssh, az vm user reset-remote-desktop, az vm run-command invoke) until Pre-Flight Safety Checks pass.
  • Do not restart, redeploy, deallocate, or delete unless the user explicitly approves remediation.
  • If multiple issues appear, fix network-layer blockers before agent-dependent fixes.

Evidence Order

  1. VM state: power, provisioning, VM agent, extension states.
  2. Network layer: public IP, NIC/subnet NSGs, effective routes, IP flow.
  3. Guest OS: services and firewall via Run Command only when agent checks are safe.

Workflow

  1. Classify intent. If unclear, ask whether the user uses RDP or SSH and what error appears.
  2. Open references/cannot-connect-to-vm.md, choose the matching symptom category, then open that reference.
  3. If a command uses the VM agent/extensions, run pre-flight checks first and stop on any unsafe result.
  4. Use mcp_azure_mcp_documentation to fetch current docs for the selected URL or symptom.
  5. Respond with evidence, likely cause, safe diagnostic/fix commands, and escalation path.
mcp_azure_mcp_documentation
  intent: "find current Azure VM RDP SSH troubleshooting docs for <symptom>"
  parameters:
    query: "<documentation URL or user's symptom>"

Error Handling

Error Action
Docs lookup empty Use the reference quick commands and tell user the doc URL may have changed
VM name/resource group wrong Ask user to verify resource identity
Run Command timeout or VMAgentStatusCommunicationError Do not run extension commands; use Serial Console/offline repair
Serial Console unavailable Enable Boot Diagnostics first
Password reset fails Check VMAccess alternatives in the credential and VM agent references
Extension stuck updating Do not add extensions; use Portal/Serial Console/offline repair

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill is designed for Azure diagnostics and troubleshooting, providing a comprehensive set of guides and scripts that utilize standard tools like the Azure CLI and kubectl. It includes some security considerations, such as the ingestion of logs which provides a surface for indirect prompt injection, and the use of privileged debug pods for advanced diagnostics. These are used within the skill's intended functionality and are accompanied by appropriate guidance for user approval.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.6"
}

README badge

README badge for microsoft/skills/azure-diagnostics