Agent skill

Azure Key Vault

by Kilo-Org in Kilo-Org/kilo-marketplace

Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

MITAuto-check passedBackend & APIs

Install Azure Key Vault

skills CLI
$ npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Kilo-Org/kilo-marketplace azure-key-vault --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Kilo-Org/kilo-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-key-vault .claude/skills/azure-key-vault && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-key-vault
GitHub stars
190
Used in
1 other repo
Token cost
~1.9k tokens
SKILL.md length
826 words
Files
2
Skills in repo
86
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

  • Works in 7 steps: Use Azure RBAC for the data plane —… → App access via managed identity + Key… → Enable soft delete + purge protection —… → …
  • Certificate authority design (use pki-design)
  • SKILL.md covers When to use, Pick the vault type and access…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Azure Key Vault is an agent skill from Kilo-Org/kilo-marketplace. Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. Covers when to use standard Key Vault vs Managed HSM (FIPS 140-3 Level 3), one-vault-per-app blast radius principle, and Key Vault references in App Service / Functions. WHEN: Azure Key Vault, store secrets, manage certificates, encryption keys, secret rotation, Key Vault RBAC, purge protection, soft delete, private…

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in Backend & APIs, covering Secrets management, Authorization and RBAC and Cryptography. It works with Azure Key Vault, Microsoft Azure and Microsoft Entra ID. The repository describes itself as: Kilo Marketplace - A curated collection of Skills, MCP Servers, and Modes for enhancing AI agent capabilities across the Kilo ecosystem—including Kilo Code (VS Code extension)… The licence is MIT.

When your agent uses it

  • Certificate authority design (use pki-design)
  • Entra app credentials only (use entra-id)
  • PaaS networking topology (use azure-network-security-design)

Example prompts

  • “/azure-key-vault”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Use Azure RBAC for the data plane — Switch the vault to RBAC permission model (not
  2. App access via managed identity + Key Vault references — App authenticates with a
  3. Enable soft delete + purge protection — Soft delete is on by default; **turn on
  4. Restrict network access — For sensitive vaults, disable public network access and
  5. One vault per app per environment — Per-app blast radius. Cross-app reads are then a
  6. Automate rotation + monitor expiry — Set expiry on secrets / certs; use **rotation
  7. Monitor + Defender — Enable diagnostic logs to Log Analytics; turn on **Defender for

What it can do on your machine

Read from SKILL.md and the folder at commit ff51758. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Key Vault loads about 1.9k tokens when it runs. Until then it costs about 199 tokens; SKILL.md has 826 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~199
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Kilo-Org/kilo-marketplace at commit ff51758, republished under its MIT licence (© Kilo-Org). 826 words, ~1,940 tokens.

Download SKILL.mdSave it as .claude/skills/azure-key-vault/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
azure-key-vault
description
Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. Covers when to use standard Key Vault vs Managed HSM (FIPS 140-3 Level 3), one-vault-per-app blast radius principle, and Key Vault references in App Service / Functions. WHEN: Azure Key Vault, store secrets, manage certificates, encryption keys, secret rotation, Key Vault RBAC, purge protection, soft delete, private endpoint Key Vault, managed identity access secrets, Managed HSM, Key Vault references, BYOK CMK. DO NOT USE for certificate authority design (use pki-design), entra app credentials only (use entra-id), or PaaS networking topology (use azure-network-security-design).
metadata.author
Microsoft
metadata.version
0.1.0
metadata.category
development

Azure Key Vault

Azure Key Vault centrally and securely stores secrets, keys, and certificates, providing RBAC-based access control, network isolation, logging, and lifecycle automation - so applications never embed credentials and crypto material has a managed lifecycle.

When to use

Managing application secrets, encryption keys (including customer-managed keys / BYOK), and TLS certificates. Use this skill to pick standard vs Managed HSM, design access, and plan rotation.

Do not use this skill for CA design (pki-design), Entra app credentials only (entra-id), or PaaS networking topology (azure-network-security-design).

Pick the vault type and access model

RequirementChoiceNotes
Application secrets, TLS certs, software-protected keysStandard Key VaultDefault; FIPS 140-2 Level 2
Single-tenant HSM with FIPS 140-3 Level 3 keys (CMK, root CA)Managed HSMRegulated workloads
Per-app, per-environment isolationOne vault per app per environmentLimits blast radius
App reading secrets at runtimeManaged identity + RBAC (Key Vault Secrets User)No secrets in code
App Service / Functions secret in configKey Vault references in app settingsNo code change
Customer-managed key for Storage / SQLKey in Key Vault (or HSM) + identity grantRotate independently

Rule of thumb: one vault per app per environment (dev / test / prod). Don't share a vault across apps - a compromise of one app's identity reads all the others' secrets. Use Managed HSM only when the regulator or CMK boundary requires FIPS 140-3 Level 3.

Approach

  1. Use Azure RBAC for the data plane — Switch the vault to RBAC permission model (not legacy access policies). Assign least-privilege roles (Key Vault Secrets User, Key Vault Crypto User) to managed identities, not user accounts. Verify: vault enableRbacAuthorization = true; no users with Key Vault Administrator in prod.

  2. App access via managed identity + Key Vault references — App authenticates with a system-assigned or user-assigned managed identity, fetches secrets at runtime. For App Service / Functions, use Key Vault references in app settings - @Microsoft.KeyVault(SecretUri=...) - no SDK code change. Verify: source code contains no plaintext secrets; managed identity has only the secrets role on the target vault.

  3. Enable soft delete + purge protection — Soft delete is on by default; turn on purge protection to make accidental or malicious key deletion non-recoverable for 90 days. Required for CMK and most compliance scenarios. Verify: softDeleteRetentionInDays >= 7; enablePurgeProtection = true.

  4. Restrict network access — For sensitive vaults, disable public network access and use private endpoint in the workload VNet. Firewall the rest with service tags or selected networks. Verify: publicNetworkAccess = Disabled; private endpoint resolves; public IP test from internet = blocked.

  5. One vault per app per environment — Per-app blast radius. Cross-app reads are then a role grant, audited. Don't lump secrets into a shared vault.

  6. Automate rotation + monitor expiry — Set expiry on secrets / certs; use rotation policies for certificate auto-renewal from issuer; for secrets, use Event Grid → Logic App / Function to rotate at the source and update the secret. Verify: no secret in production has a NULL expiry; alerts fire 60 days before any cert or secret expires.

  7. Monitor + Defender — Enable diagnostic logs to Log Analytics; turn on Defender for Key Vault for anomalous access detection.

Show full SKILL.md (319 more words)Show less

Guardrails

  • One vault per app per environment limits blast radius and simplifies access control. Shared vaults are an over-permission anti-pattern.
  • Purge protection is irreversible once on - required for CMK and many compliance scenarios. Turn it on knowingly.
  • Never store secrets in source / config; use managed identity + Key Vault references. Code-stored secrets leak via repo, logs, env-var dumps.
  • Disable public network access for sensitive vaults. Open-to-internet Key Vault is a brute-force / credential-spray target.
  • RBAC, not access policies. RBAC is the modern model with proper inheritance and PIM-eligible roles.
  • Don't grant Key Vault Administrator to apps. Apps need read on secrets / keys, not admin.

Common anti-patterns

  • "Shared 'enterprise' Key Vault for all apps" - Compromise of one app reads everyone's secrets. Per-app per-environment.
  • "Access policies because we've always used them" - Legacy; harder to audit. Use RBAC.
  • "No purge protection - we might need to delete" - First malicious / accidental purge = data loss. Turn it on; deal with the irrevocability.
  • "Public network access on for convenience" - Internet exposure. Private endpoint
    • firewall.
  • "Secrets in App Service application settings as plaintext" - Visible to anyone with config read. Use Key Vault references.
  • "No expiry / no rotation" - Long-lived secrets are a perpetual liability. Expiry + rotation policy.
  • "Same vault for app + CA root key" - Mix of blast radii. CA / HSM keys in Managed HSM, separate from app secret vault.

Example prompts

  • Set up Azure Key Vault with RBAC, purge protection, and a private endpoint.
  • Configure an App Service to read secrets via managed identity and Key Vault references.
  • When should I use Managed HSM instead of standard Key Vault?
  • Plan one-vault-per-app-per-environment for our microservices estate.
  • Automate certificate rotation in Key Vault with a 60-day expiry alert.
  • Review my Key Vault access model for least privilege.

Microsoft Learn

© Kilo-Org, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/azure-key-vault of Kilo-Org/kilo-marketplace.

  • SKILL.md
  • LICENSE

Open the folder on GitHubat commit ff51758

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Kilo-Org/kilo-marketplace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Azure Key Vault next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Key Vault compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Key Vault this skillKilo-Org/kilo-marketplace1901 repos~1.9kAutomated safety check: PassMIT
Pki Designvinayaklatthe/microsoft-security-skills175—~2.1kAutomated safety check: PassMIT
Apex Entra App Registrationjonathan-vella/apex217—~1.3kAutomated safety check: PassMIT
Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Azure Keyvault Pymicrosoft/skills3.1k—~2.4kAutomated safety check: PassMIT
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT

Similar skills

  • Pki Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.

    175 GitHub stars~2.1k tokensUpdated 3 mo ago
    SecurityAuto-check passed
  • Apex Entra App Registration

    jonathan-vella/apex

    WORKFLOW SKILL — Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    217 GitHub stars~1.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Azure Keyvault Py

    microsoft/skills

    Official

    Azure Key Vault SDK for Python. An agent skill from microsoft/skills.

    3.1k GitHub stars~2.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Official

    Azure Key Vault Secrets library for Rust. An agent skill from microsoft/skills.

    3.1k GitHub stars~1.5k tokensUpdated today
    Backend & APIsAuto-check passed

More from Kilo-Org/kilo-marketplace

All 86 skills in this repo
  • AzureML Project Scaffolding

    Kilo-Org/kilo-marketplace

    Sets up and maintains AzureML-ready Python projects as uv workspaces with devcontainers, a Makefile and job YAML, so local runs match cloud jobs and experiments stay reproducible.

    190 GitHub stars~3.1k tokensUpdated 11 days ago
    Auto-check: notes
  • Jupyter Notebook Builder

    Kilo-Org/kilo-marketplace

    Creates, inspects, edits and runs Jupyter notebooks, scaffolding experiment or tutorial notebooks from templates and preferring a Jupyter MCP server over raw JSON edits.

    190 GitHub stars~1.3k tokensUpdated 11 days ago
    Auto-check passed
  • Tableau Dashboard Creator

    Kilo-Org/kilo-marketplace

    Takes a plain-language dashboard request through brand setup, data exploration, planning, an interactive HTML mock and a Tableau implementation spec.

    190 GitHub stars~3.8k tokensUpdated 11 days ago
    Auto-check: notes
  • Elasticsearch File Ingest

    Kilo-Org/kilo-marketplace

    Ingest and transform data files (CSV/JSON/Parquet/Arrow IPC) into Elasticsearch with stream processing and custom transforms.

    190 GitHub stars~2.8k tokensUpdated 11 days ago
    Auto-check passed
  • Nifi Flow Layout

    Kilo-Org/kilo-marketplace

    A skill your agent uses when arranging Apache NiFi processors, process groups, ports, comments, numbering, crossing connections, dense fan-in/fan-out, or reusable readable canvas layouts.

    190 GitHub stars~1.5k tokensUpdated 11 days ago
    Auto-check passed
  • Splunk Ingest Processor Setup

    Kilo-Org/kilo-marketplace

    Render Cisco Data Fabric ingest-time routing workflows and Splunk Cloud Platform Ingest Processor setup plans with SPL2 pipelines, source types, destinations, lifecycle handoffs, queue and…

    190 GitHub stars~1.2k tokensUpdated 11 days ago
    Auto-check passed

Questions about Azure Key Vault

What does Azure Key Vault do?

Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation. Azure Key Vault is an agent skill from Kilo-Org/kilo-marketplace. Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

When should I use Azure Key Vault?

Azure Key Vault fits situations like: certificate authority design (use pki-design); entra app credentials only (use entra-id); paaS networking topology (use azure-network-security-design).

How do I install Azure Key Vault in Claude Code?

Run `npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a claude-code`. Or copy the skill folder (skills/azure-key-vault in Kilo-Org/kilo-marketplace) into .claude/skills/azure-key-vault in your project. Claude Code loads it when a task matches its description.

How do I install Azure Key Vault in Codex?

Run `npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a codex`. Or copy the skill folder (skills/azure-key-vault in Kilo-Org/kilo-marketplace) into .agents/skills/azure-key-vault in your project. Codex loads it when a task matches its description.

Can I use Azure Key Vault in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Kilo-Org/kilo-marketplace --skill azure-key-vault -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-key-vault, .gemini/skills/azure-key-vault, .github/skills/azure-key-vault and .opencode/skills/azure-key-vault in your project.

What does Azure Key Vault need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Key Vault is instructions for the agent only.

Does Azure Key Vault access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Azure Key Vault safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Key Vault use?

Azure Key Vault is published under the MIT licence (from the LICENSE file in the skill folder). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Key Vault use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Key Vault?

Skills that share tags, products or a category with Azure Key Vault: Pki Design (vinayaklatthe/microsoft-security-skills, 175 stars), Apex Entra App Registration (jonathan-vella/apex, 217 stars), Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Azure Keyvault Py (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Key Vault?

Kilo-Org (a GitHub organization) maintains it in Kilo-Org/kilo-marketplace, which has 190 GitHub stars. The repository holds 86 skills in this directory. The repository was last updated on September 28, 2026.

Source: Kilo-Org/kilo-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.