Pki Design
vinayaklatthe/microsoft-security-skills
Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.
Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.
$ npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Kilo-Org/kilo-marketplace azure-key-vault --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-key-vault .claude/skills/azure-key-vault && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azure-key-vault" agent skill from https://github.com/Kilo-Org/kilo-marketplace/tree/main/skills/azure-key-vault into .claude/skills/azure-key-vault/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-key-vault", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Kilo-Org/kilo-marketplace/tree/main/skills/azure-key-vaultType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Kilo-Org/kilo-marketplace azure-key-vault --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/azure-key-vault .agents/skills/azure-key-vault && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azure-key-vault" agent skill from https://github.com/Kilo-Org/kilo-marketplace/tree/main/skills/azure-key-vault into .agents/skills/azure-key-vault/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-key-vault", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Kilo-Org/kilo-marketplace azure-key-vault --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/azure-key-vault .cursor/skills/azure-key-vault && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azure-key-vault" agent skill from https://github.com/Kilo-Org/kilo-marketplace/tree/main/skills/azure-key-vault into .cursor/skills/azure-key-vault/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-key-vault", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Kilo-Org/kilo-marketplace.git --path skills/azure-key-vault--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Kilo-Org/kilo-marketplace azure-key-vault --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/azure-key-vault .gemini/skills/azure-key-vault && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azure-key-vault" agent skill from https://github.com/Kilo-Org/kilo-marketplace/tree/main/skills/azure-key-vault into .gemini/skills/azure-key-vault/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-key-vault", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Kilo-Org/kilo-marketplace azure-key-vaultInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/azure-key-vault .github/skills/azure-key-vault && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azure-key-vault" agent skill from https://github.com/Kilo-Org/kilo-marketplace/tree/main/skills/azure-key-vault into .github/skills/azure-key-vault/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-key-vault", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Kilo-Org/kilo-marketplace azure-key-vault --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/azure-key-vault .opencode/skills/azure-key-vault && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azure-key-vault" agent skill from https://github.com/Kilo-Org/kilo-marketplace/tree/main/skills/azure-key-vault into .opencode/skills/azure-key-vault/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-key-vault", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azure-key-vaultGuidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.
Azure Key Vault is an agent skill from Kilo-Org/kilo-marketplace. Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. Covers when to use standard Key Vault vs Managed HSM (FIPS 140-3 Level 3), one-vault-per-app blast radius principle, and Key Vault references in App Service / Functions. WHEN: Azure Key Vault, store secrets, manage certificates, encryption keys, secret rotation, Key Vault RBAC, purge protection, soft delete, private…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.
It sits in Backend & APIs, covering Secrets management, Authorization and RBAC and Cryptography. It works with Azure Key Vault, Microsoft Azure and Microsoft Entra ID. The repository describes itself as: Kilo Marketplace - A curated collection of Skills, MCP Servers, and Modes for enhancing AI agent capabilities across the Kilo ecosystem—including Kilo Code (VS Code extension)… The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ff51758. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure Key Vault loads about 1.9k tokens when it runs. Until then it costs about 199 tokens; SKILL.md has 826 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Kilo-Org/kilo-marketplace at commit ff51758, republished under its MIT licence (© Kilo-Org). 826 words, ~1,940 tokens.
.claude/skills/azure-key-vault/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Azure Key Vault centrally and securely stores secrets, keys, and certificates, providing RBAC-based access control, network isolation, logging, and lifecycle automation - so applications never embed credentials and crypto material has a managed lifecycle.
Managing application secrets, encryption keys (including customer-managed keys / BYOK), and TLS certificates. Use this skill to pick standard vs Managed HSM, design access, and plan rotation.
Do not use this skill for CA design (pki-design), Entra app credentials only
(entra-id), or PaaS networking topology (azure-network-security-design).
| Requirement | Choice | Notes |
|---|---|---|
| Application secrets, TLS certs, software-protected keys | Standard Key Vault | Default; FIPS 140-2 Level 2 |
| Single-tenant HSM with FIPS 140-3 Level 3 keys (CMK, root CA) | Managed HSM | Regulated workloads |
| Per-app, per-environment isolation | One vault per app per environment | Limits blast radius |
| App reading secrets at runtime | Managed identity + RBAC (Key Vault Secrets User) | No secrets in code |
| App Service / Functions secret in config | Key Vault references in app settings | No code change |
| Customer-managed key for Storage / SQL | Key in Key Vault (or HSM) + identity grant | Rotate independently |
Rule of thumb: one vault per app per environment (dev / test / prod). Don't share a vault across apps - a compromise of one app's identity reads all the others' secrets. Use Managed HSM only when the regulator or CMK boundary requires FIPS 140-3 Level 3.
Use Azure RBAC for the data plane — Switch the vault to RBAC permission model (not
legacy access policies). Assign least-privilege roles (Key Vault Secrets User,
Key Vault Crypto User) to managed identities, not user accounts.
Verify: vault enableRbacAuthorization = true; no users with Key Vault Administrator
in prod.
App access via managed identity + Key Vault references — App authenticates with a
system-assigned or user-assigned managed identity, fetches secrets at runtime.
For App Service / Functions, use Key Vault references in app settings -
@Microsoft.KeyVault(SecretUri=...) - no SDK code change.
Verify: source code contains no plaintext secrets; managed identity has only the
secrets role on the target vault.
Enable soft delete + purge protection — Soft delete is on by default; turn on
purge protection to make accidental or malicious key deletion non-recoverable for
90 days. Required for CMK and most compliance scenarios.
Verify: softDeleteRetentionInDays >= 7; enablePurgeProtection = true.
Restrict network access — For sensitive vaults, disable public network access and
use private endpoint in the workload VNet. Firewall the rest with service tags or
selected networks.
Verify: publicNetworkAccess = Disabled; private endpoint resolves; public IP test
from internet = blocked.
One vault per app per environment — Per-app blast radius. Cross-app reads are then a role grant, audited. Don't lump secrets into a shared vault.
Automate rotation + monitor expiry — Set expiry on secrets / certs; use rotation policies for certificate auto-renewal from issuer; for secrets, use Event Grid → Logic App / Function to rotate at the source and update the secret. Verify: no secret in production has a NULL expiry; alerts fire 60 days before any cert or secret expires.
Monitor + Defender — Enable diagnostic logs to Log Analytics; turn on Defender for Key Vault for anomalous access detection.
Key Vault Administrator to apps. Apps need read on secrets / keys, not
admin.Set up Azure Key Vault with RBAC, purge protection, and a private endpoint.Configure an App Service to read secrets via managed identity and Key Vault references.When should I use Managed HSM instead of standard Key Vault?Plan one-vault-per-app-per-environment for our microservices estate.Automate certificate rotation in Key Vault with a 60-day expiry alert.Review my Key Vault access model for least privilege.© Kilo-Org, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/azure-key-vault of Kilo-Org/kilo-marketplace.
Open the folder on GitHubat commit ff51758
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Kilo-Org/kilo-marketplace, which our catalogue first saw on October 7, 2026.
Azure Key Vault next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure Key Vault this skillKilo-Org/kilo-marketplace | 190 | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Pki Designvinayaklatthe/microsoft-security-skills | 175 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Apex Entra App Registrationjonathan-vella/apex | 217 | — | ~1.3k | Automated safety check: Pass | MIT | |
| Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure | 255 | 2 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Azure Keyvault Pymicrosoft/skills | 3.1k | — | ~2.4k | Automated safety check: Pass | MIT | |
| API Security Designvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT |
vinayaklatthe/microsoft-security-skills
Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.
jonathan-vella/apex
WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.
microsoft/GitHub-Copilot-for-Azure
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.
microsoft/skills
Azure Key Vault SDK for Python. An agent skill from microsoft/skills.
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
microsoft/skills
Azure Key Vault Secrets library for Rust. An agent skill from microsoft/skills.
Kilo-Org/kilo-marketplace
Sets up and maintains AzureML-ready Python projects as uv workspaces with devcontainers, a Makefile and job YAML, so local runs match cloud jobs and experiments stay reproducible.
Kilo-Org/kilo-marketplace
Creates, inspects, edits and runs Jupyter notebooks, scaffolding experiment or tutorial notebooks from templates and preferring a Jupyter MCP server over raw JSON edits.
Kilo-Org/kilo-marketplace
Takes a plain-language dashboard request through brand setup, data exploration, planning, an interactive HTML mock and a Tableau implementation spec.
Kilo-Org/kilo-marketplace
Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.
Kilo-Org/kilo-marketplace
A skill your agent uses when arranging Apache NiFi processors, process groups, ports, comments, numbering, crossing connections, dense fan-in/fan-out, or reusable readable canvas layouts.
Kilo-Org/kilo-marketplace
Render Cisco Data Fabric ingest-time routing workflows and Splunk Cloud Platform Ingest Processor setup plans with SPL2 pipelines, source types, destinations, lifecycle handoffs, queue and…
Categories
Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. Azure Key Vault is an agent skill from Kilo-Org/kilo-marketplace. Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.
Azure Key Vault fits situations like: certificate authority design (use pki-design); entra app credentials only (use entra-id); paaS networking topology (use azure-network-security-design).
Run `npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a claude-code`. Or copy the skill folder (skills/azure-key-vault in Kilo-Org/kilo-marketplace) into .claude/skills/azure-key-vault in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a codex`. Or copy the skill folder (skills/azure-key-vault in Kilo-Org/kilo-marketplace) into .agents/skills/azure-key-vault in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-key-vault, .gemini/skills/azure-key-vault, .github/skills/azure-key-vault and .opencode/skills/azure-key-vault in your project.
SKILL.md names no scripts, command-line tools or credentials: Azure Key Vault is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azure Key Vault is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Azure Key Vault: Pki Design (vinayaklatthe/microsoft-security-skills, 175 stars), Apex Entra App Registration (jonathan-vella/apex, 217 stars), Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Azure Keyvault Py (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Kilo-Org (a GitHub organization) maintains it in Kilo-Org/kilo-marketplace, which has 190 GitHub stars. The repository holds 86 skills in this directory. The repository was last updated on September 28, 2026.
Source: Kilo-Org/kilo-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.