Official agent skill

Azure Keyvault Secrets Rust

by microsoft in microsoft/skills

Azure Key Vault Secrets library for Rust. An agent skill from microsoft/skills.

OfficialMITAuto-check passedBackend & APIs

Install Azure Keyvault Secrets Rust

skills CLI
$ npx skills add microsoft/skills --skill azure-keyvault-secrets-rust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/skills azure-keyvault-secrets-rust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/plugins/azure-sdk-rust/skills/azure-keyvault-secrets-rust .claude/skills/azure-keyvault-secrets-rust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-keyvault-secrets-rust
GitHub stars
3.1k
Token cost
~1.5k tokens
SKILL.md length
334 words
Files
1
Skills in repo
150
Repo updated
First seen
Licence
MIT

At a glance

Azure Key Vault Secrets library for Rust. An agent skill from microsoft/skills.

  • Works in 8 steps: Use cargo add to manage dependencies,… → Add azure_core only when importing… → Use DeveloperToolsCredential for local… → …
  • Tasks that involve Secrets management
  • SKILL.md covers Installation, Environment Variables, Authentication and Core Workflow, plus 4 more sections
  • Calls cargo

What it does

Azure Keyvault Secrets Rust is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Key Vault Secrets library for Rust. Store and retrieve secrets, passwords, and API keys. Triggers: "keyvault secrets rust", "SecretClient rust", "get secret rust", "set secret rust", "list secrets rust".

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Secrets management. It works with Azure Key Vault, Rust and Microsoft Azure. The repository describes itself as: Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Secrets management

Example prompts

  • “keyvault secrets rust”
  • “SecretClient rust”
  • “get secret rust”
  • “/azure-keyvault-secrets-rust”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Use cargo add to manage dependencies, never edit Cargo.toml directly. Add and remove Rust SDK dependencies with cargo commands instead of…
  2. Add azure_core only when importing azure_core types directly. If your code imports azure_core::http::Url…
  3. Use DeveloperToolsCredential for local dev, ManagedIdentityCredential for production — Rust does not provide a single…
  4. Never hardcode credentials — use environment variables or managed identity
  5. Use ..Default::default() with #[allow(clippy::needless_update)] for model struct updates
  6. Use ResourceExt to extract resource name/version from secret IDs
  7. Reuse clients — SecretClient is thread-safe; create once, share across tasks
  8. Run cargo clippy -- -D warnings when the prompt, eval, or CI expects lint-clean output

What it can do on your machine

Read from SKILL.md and the folder at commit 354361d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • crates.io
    • docs.rs
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Keyvault Secrets Rust loads about 1.5k tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 334 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~59
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/skills at commit 354361d, republished under its MIT licence (© microsoft). 334 words, ~1,492 tokens.

Download SKILL.mdSave it as .claude/skills/azure-keyvault-secrets-rust/SKILL.md (or your agent's skills folder).
name
azure-keyvault-secrets-rust
description
Azure Key Vault Secrets library for Rust. Store and retrieve secrets, passwords, and API keys. Triggers: "keyvault secrets rust", "SecretClient rust", "get secret rust", "set secret rust", "list secrets rust".
license
MIT
metadata.author
Microsoft
metadata.package
azure_security_keyvault_secrets

Azure Key Vault Secrets library for Rust

Secure storage for passwords, API keys, and connection strings.

Use this skill when:

  • An app needs to store or retrieve secrets from Azure Key Vault in Rust
  • You need to set, get, update, or delete secrets
  • You need to list secret properties with pagination
  • You need error handling for missing secrets

IMPORTANT: Only use the official azure_security_keyvault_secrets crate published by the azure-sdk crates.io user. Do NOT use unofficial or community crates. Official crates use underscores in names and none have version 0.21.0.

Installation

sh
cargo add azure_security_keyvault_secrets azure_identity tokio futures

If your code uses azure_core types directly, add azure_core to Cargo.toml. If you only use azure_security_keyvault_secrets re-exports, direct azure_core dependency is optional.

Environment Variables

bash
AZURE_KEYVAULT_URL=https://<vault-name>.vault.azure.net/ # Required for all operations

Authentication

Rust Azure SDK code must not use DefaultAzureCredential. The Rust identity crate does not provide that type.

rust
use azure_identity::DeveloperToolsCredential;
use azure_security_keyvault_secrets::SecretClient;

#[tokio::main]
async fn main() -> Result<(), Box<dyn std::error::Error>> {
    // Local dev: DeveloperToolsCredential. Production: use ManagedIdentityCredential.
    let credential = DeveloperToolsCredential::new(None)?;
    let client = SecretClient::new(
        "https://<vault-name>.vault.azure.net/",
        credential.clone(),
        None,
    )?;

    let secret = client
        .get_secret("secret-name", None)
        .await?
        .into_model()?;
    println!("Secret: {:?}", secret.value);
    Ok(())
}

Prefer the crate README/examples when checking whether pagers yield items directly and how ResourceExt is used in public examples.

Core Workflow

Set Secret
rust
use azure_security_keyvault_secrets::{models::SetSecretParameters, ResourceExt};

let params = SetSecretParameters {
    value: Some("secret-value".into()),
    ..Default::default()
};

let secret = client
    .set_secret("secret-name", params.try_into()?, None)
    .await?
    .into_model()?;

println!(
    "Name: {:?}, Version: {:?}",
    secret.resource_id()?.name,
    secret.resource_id()?.version
);
Update Secret Properties
rust
use azure_security_keyvault_secrets::models::UpdateSecretPropertiesParameters;
use std::collections::HashMap;

#[allow(clippy::needless_update)]
let params = UpdateSecretPropertiesParameters {
    content_type: Some("text/plain".into()),
    tags: Some(HashMap::from_iter(vec![(
        "env".into(),
        "prod".into(),
    )])),
    ..Default::default()
};

client
    .update_secret_properties("secret-name", params.try_into()?, None)
    .await?
    .into_model()?;
Delete Secret
rust
client.delete_secret("secret-name", None).await?;
List Secrets (Pagination)

list_secret_properties returns a Pager<T> — iterate items directly:

rust
use azure_security_keyvault_secrets::ResourceExt;
use futures::TryStreamExt as _;

let mut pager = client.list_secret_properties(None)?;
while let Some(secret) = pager.try_next().await? {
    println!("Found: {}", secret.resource_id()?.name);
}

Error Handling

rust
match client.get_secret("secret-name", None).await {
    Ok(response) => println!("Secret Value: {:?}", response.into_model()?.value),
    Err(err) => println!("Error: {:#?}", err.into_inner()?),
}

// Error output includes structured ErrorResponse with code and message

RBAC Roles

For Entra ID auth, assign one of these roles:

RoleAccess
Key Vault Secrets UserRead secrets
Key Vault Secrets OfficerFull secret management

Best Practices

  1. Use cargo add to manage dependencies, never edit Cargo.toml directly. Add and remove Rust SDK dependencies with cargo commands instead of manual manifest edits.
  2. Add azure_core only when importing azure_core types directly. If your code imports azure_core::http::Url, azure_core::http::RequestContent, or azure_core::error::ErrorKind, include azure_core; otherwise a direct dependency is optional.
  3. Use DeveloperToolsCredential for local dev, ManagedIdentityCredential for production — Rust does not provide a single DefaultAzureCredential type
  4. Never hardcode credentials — use environment variables or managed identity
  5. Use ..Default::default() with #[allow(clippy::needless_update)] for model struct updates
  6. Use ResourceExt to extract resource name/version from secret IDs
  7. Reuse clients — SecretClient is thread-safe; create once, share across tasks
  8. Run cargo clippy -- -D warnings when the prompt, eval, or CI expects lint-clean output

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/plugins/azure-sdk-rust/skills/azure-keyvault-secrets-rust of microsoft/skills.

Open the folder on GitHubat commit 354361d

Compare with similar skills

Azure Keyvault Secrets Rust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Keyvault Secrets Rust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Keyvault Secrets Rust this skillmicrosoft/skills3.1k—~1.5kAutomated safety check: PassMIT
Azure Key VaultKilo-Org/kilo-marketplace1891 repos~1.9kAutomated safety check: PassMIT
Azure Keyvaultsickn33/agentic-awesome-skills47k2 repos~3.2kAutomated safety check: PassMIT
Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure2552 repos~2.1kAutomated safety check: PassMIT
Managing Workflow Secretsbitwarden/ai-plugins154—~4kAutomated safety check: PassCustom licence
Azure Usagefcakyon/claude-codex-settings1.2k1 repos~461Automated safety check: PassApache-2.0

Similar skills

  • Azure Key Vault

    Kilo-Org/kilo-marketplace

    Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.

    189 GitHub starsUsed in 1 repo~1.9k tokens
    Backend & APIsAuto-check passed
  • Azure Keyvault

    sickn33/agentic-awesome-skills

    Manage secrets and certificates in Azure Key Vault. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.2k tokens
    DevOps & CloudAuto-check passed
  • Entra App Registration

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.

    255 GitHub starsUsed in 2 repos~2.1k tokens
    Backend & APIsAuto-check passed
  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    154 GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azure Usage

    fcakyon/claude-codex-settings

    This skill should be used when user asks to "query Azure resources", "list storage accounts", "manage Key Vault secrets", "work with Cosmos DB", "check AKS clusters", "use Azure MCP", or interact…

    1.2k GitHub starsUsed in 1 repo~461 tokens
    DevOps & CloudAuto-check passed
  • Azure Compliance

    microsoft/GitHub-Copilot-for-Azure

    Official

    Run Azure compliance and security audits with azqr plus Key Vault expiration checks.

    255 GitHub starsUsed in 2 repos~997 tokens
    SecurityAuto-check passed

More from microsoft/skills

All 150 skills in this repo
  • Official

    Reference for building on Microsoft Foundry with the azure-ai-projects Python SDK: project clients, versioned agents, evaluations, connections, datasets and indexes.

    3.1k GitHub starsUsed in 6 repos~2.8k tokens
    Auto-check passed
  • Official

    Python guidance for the Azure AI Search SDK covering vector, hybrid and semantic search, index management and indexers, with Entra ID authentication preferred over keys.

    3.1k GitHub starsUsed in 6 repos~4.4k tokens
    Auto-check passed
  • Official

    Covers producer, consumer, and checkpoint-store setup for Azure Event Hubs streaming in Python, with Entra ID auth and partition targeting.

    3.1k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Pydantic Models Py

    microsoft/skills

    Official

    Create Pydantic models following the multi-model pattern with Base, Create, Update, Response, and InDB variants.

    3.1k GitHub starsUsed in 6 repos~496 tokens
    Auto-check passed
  • Official

    Builds podcast-style audio narration from text with Azure OpenAI's GPT Realtime Mini over WebSocket, from a Python FastAPI backend to a React player.

    3.1k GitHub starsUsed in 1 repo~947 tokens
    Auto-check passed
  • Frontend UI Dark TS

    microsoft/skills

    Official

    Build dark-themed React applications using Tailwind CSS with custom theming, glassmorphism effects, and Framer Motion animations.

    3.1k GitHub starsUsed in 5 repos~3.6k tokens
    Auto-check passed

Questions about Azure Keyvault Secrets Rust

What does Azure Keyvault Secrets Rust do?

Azure Key Vault Secrets library for Rust. An agent skill from microsoft/skills. Azure Keyvault Secrets Rust is an agent skill from microsoft/skills, published by the product's own GitHub organization. Azure Key Vault Secrets library for Rust.

When should I use Azure Keyvault Secrets Rust?

Azure Keyvault Secrets Rust fits situations like: tasks that involve Secrets management.

How do I install Azure Keyvault Secrets Rust in Claude Code?

Run `npx skills add microsoft/skills --skill azure-keyvault-secrets-rust -a claude-code`. Or copy the skill folder (.github/plugins/azure-sdk-rust/skills/azure-keyvault-secrets-rust in microsoft/skills) into .claude/skills/azure-keyvault-secrets-rust in your project. Claude Code loads it when a task matches its description.

How do I install Azure Keyvault Secrets Rust in Codex?

Run `npx skills add microsoft/skills --skill azure-keyvault-secrets-rust -a codex`. Or copy the skill folder (.github/plugins/azure-sdk-rust/skills/azure-keyvault-secrets-rust in microsoft/skills) into .agents/skills/azure-keyvault-secrets-rust in your project. Codex loads it when a task matches its description.

Can I use Azure Keyvault Secrets Rust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/skills --skill azure-keyvault-secrets-rust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-keyvault-secrets-rust, .gemini/skills/azure-keyvault-secrets-rust, .github/skills/azure-keyvault-secrets-rust and .opencode/skills/azure-keyvault-secrets-rust in your project.

What does Azure Keyvault Secrets Rust need to run?

Going by SKILL.md and its folder, Azure Keyvault Secrets Rust needs the command-line tools its instructions call (cargo).

Does Azure Keyvault Secrets Rust access the network?

SKILL.md names 3 domains. As links in the text: crates.io, docs.rs and github.com. This is read from the text; nothing was executed.

Is Azure Keyvault Secrets Rust safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Keyvault Secrets Rust use?

Azure Keyvault Secrets Rust is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Keyvault Secrets Rust use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Keyvault Secrets Rust?

Skills that share tags, products or a category with Azure Keyvault Secrets Rust: Azure Key Vault (Kilo-Org/kilo-marketplace, 189 stars), Azure Keyvault (sickn33/agentic-awesome-skills, 47k stars), Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Managing Workflow Secrets (bitwarden/ai-plugins, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Keyvault Secrets Rust?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/skills, which has 3,086 GitHub stars. The repository holds 150 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.