Sentinel
vinayaklatthe/microsoft-security-skills
Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.
Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql .claude/skills/azure-kusto-irql && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azure-kusto-irql" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql into .claude/skills/azure-kusto-irql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irqlType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql .agents/skills/azure-kusto-irql && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azure-kusto-irql" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql into .agents/skills/azure-kusto-irql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql .cursor/skills/azure-kusto-irql && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azure-kusto-irql" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql into .cursor/skills/azure-kusto-irql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/GitHub-Copilot-for-Azure.git --path plugins/azure-kusto-graph-skills/skills/azure-kusto-irql--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql .gemini/skills/azure-kusto-irql && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azure-kusto-irql" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql into .gemini/skills/azure-kusto-irql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irqlInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql .github/skills/azure-kusto-irql && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azure-kusto-irql" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql into .github/skills/azure-kusto-irql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kusto-irql --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql .opencode/skills/azure-kusto-irql && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azure-kusto-irql" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-kusto-graph-skills/skills/azure-kusto-irql into .opencode/skills/azure-kusto-irql/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kusto-irql", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azure-kusto-irqlCompose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations.
Azure Kusto Irql is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. Translates natural language hunting questions into composable IRQL pipelines using Get, Extract, and Enrich functions. WHEN: IRQL query, security hunt, threat hunting KQL, incident response query, compose hunting pipeline, failed logins, phishing investigation, lateral movement, process execution, file creation events.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/EXAMPLES.md`, `references/KUSTO_EXPLORER_LAUNCH.md` and `version.json`).
It sits in DevOps & Cloud, covering Incident response, Red teaming and adversary simulation and Security operations. It works with Microsoft Azure and Microsoft Sentinel. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ce94fce. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are kql).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
kc7001.eastus.kusto.windows.netFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure Kusto Irql loads about 2.6k tokens when it runs, and up to ~3.9k if it reads all its reference files. Until then it costs about 110 tokens; SKILL.md has 855 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from microsoft/GitHub-Copilot-for-Azure at commit ce94fce, republished under its MIT licence (© microsoft). 855 words, ~2,625 tokens.
.claude/skills/azure-kusto-irql/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Compose IRQL function pipelines from selector, extractor, and enricher building blocks. IRQL wraps raw KQL security tables behind intent-revealing, composable functions so analysts (and LLMs) can express hunts without memorizing schemas, cluster locations, or join keys.
Use this skill when the user:
Get_*, Extract_*, or Enrich_* functionsDo not activate for generic security queries (e.g. "find failed logins") unless the user explicitly asks for IRQL. Route those to azure-kusto instead.
Not a natural-language-to-IRQL converter. This skill composes IRQL function pipelines and may handle basic natural-language requests that map directly to known selectors and simple filters. For general NL-to-KQL or NL-to-IRQL conversion, use a dedicated query-generation skill (available separately).
Before generating a pipeline, verify IRQL is available on the target database:
.show functions
| where Name startswith "Get_" or Name startswith "Extract_" or Name startswith "Enrich_"
| project NameIf no IRQL functions are found, inform the user that IRQL is not deployed on the target database and suggest using azure-kusto for raw KQL queries instead. IRQL functions are a prerequisite -- this skill does not deploy base IRQL selectors.
IRQL is a function-based dialect on top of KQL. It provides:
| invoke to build complex hunts from simple stepsGet_* primitives need re-pointingIRQL is not a separate language. It's KQL functions you invoke. Any valid KQL works alongside IRQL functions.
IRQL functions are stored KQL functions (.create-or-alter function). They must already be deployed to the target database before this skill can generate pipelines.
Public example cluster (functions pre-deployed):
https://kc7001.eastus.kusto.windows.netValdyTimes, JoJosHospitalTo port IRQL to a new cluster/database, create Get_* selectors that project your source tables into the unified schema (column names below), then deploy extractors and enrichers. The extractors and enrichers work unchanged as long as the input schema matches.
Get_*Return projected, schema-unified views of source tables. Use the minimal form by default; use _All when extra columns are needed.
| Function | Columns |
|---|---|
Get_Event_Authentication | EnvTime, Hostname, ClientIp, Username, Result |
Get_Event_Authentication_All | + Description, UserAgent, PasswordHash |
Get_Email | EnvTime, EmailSender, EmailRecipient, Subject, Url |
Get_Email_All | + ReplyTo, Verdict |
Get_Employees | Name, ClientIp, Email, Username, Hostname, Role |
Get_Employees_All | + HireDate, UserAgent, Domain |
Get_Event_FileCreation | EnvTime, Hostname, Filename, Path |
Get_Event_FileCreation_All | + Username, Sha256, ProcessName |
Get_Event_NetworkInbound | EnvTime, ClientIp, Url |
Get_Event_NetworkInbound_All | + Method, UserAgent, StatusCode |
Get_Event_NetworkOutbound | EnvTime, ClientIp, Url |
Get_Event_NetworkOutbound_All | + Method, UserAgent |
Get_Dns_All | EnvTime, Domain, ClientIp |
Get_Event_Process | EnvTime, ProcessCommandLine, ProcessName, Hostname, Username |
Get_Event_Process_All | + ParentProcessName, ParentProcessHash, ProcessHash |
Get_SecurityAlerts_All | EnvTime, AlertType, Severity, Description, Indicators |
Get_Network_Connection_All | EnvTime, SourceIp, SourcePort, DestinationIp, DestinationPort, Protocol, Bytes |
Extract_*Derive a new column from an existing one. Invoke after a selector.
| Function | Input Column | Adds |
|---|---|---|
Extract_Email_Sender_Domain(T) | EmailSender | Domain |
Extract_Employee_Firstname(T) | Name | Firstname |
Extract_Event_Network_Domain(T) | Url | DomainName |
Enrich_*Left-join helpers that attach context from a related table.
| Function | Key Column | Enriches With |
|---|---|---|
Enrich_Event_Authentication_Username(T) | Username | Auth events for user |
Enrich_Ip_Employee(T) | ClientIp | Employee identity from IP |
Enrich_Username_Employee(T) | Username | Employee identity from username |
Enrich_Ip_Domain(T) | ClientIp | DNS domains resolved to IP |
Enrich_Ip_Event_NetworkOutbound(T) | ClientIp | Outbound network from IP |
Enrich_Ip_Network_Connection(T) | ClientIp | Network flows from IP |
| Function | Source | Requirement |
|---|---|---|
Enrich_Sha256_VirusTotal(T) | VirusTotal file report | API key + callout policy |
Get_CISA_KEV() / Enrich_CISA_KEV(T) | CISA KEV catalog | Callout policy |
Selector -> Extract -> Filter -> Enrich -> Summarize/ProjectGet_Event_Authentication, Get_Email, etc.| invoke Extract_Email_Sender_Domain()| where Result == "Failed Login"| invoke Enrich_Username_Employee()Always pipe (|) between steps. Extractors and Enrichers use | invoke FunctionName().
_Allwhere filters as early as possiblesummarize for aggregations, project for final column selectionorder by + take to limit outputFor additional prompts and worked examples, see references/EXAMPLES.md.
Get_Event_Authentication
| where Result == "Failed Login"
| summarize FailedCount = count() by Username
| where FailedCount > 19
| invoke Enrich_Username_Employee()
| project Username, Name, Role, Email, FailedCount
| order by FailedCount descGet_Email
| invoke Extract_Email_Sender_Domain()
| project EnvTime, EmailSender, Domain, Username = EmailRecipient, Subject, Url
| invoke Enrich_Username_Employee()
| extend Seniority = case(
Role has_any ("CEO", "Chief", "Director", "VP", "President"), 3,
Role has_any ("Manager", "Lead", "Senior"), 2,
1)
| summarize
TotalEmails = count(),
SeniorityScore = sum(Seniority),
Recipients = make_set(Name, 50),
DistinctRecipients = dcount(Username)
by Domain
| where DistinctRecipients >= 2
| order by SeniorityScore desc
| take 20let victims =
Get_Event_FileCreation_All
| where Filename has "<INDICATOR>"
| distinct Hostname;
Get_Event_Process
| where Hostname in (victims)
| where ProcessCommandLine has_any ("rundll32", "regsvr32", "powershell", "systeminfo")
| project EnvTime, Hostname, Username, ProcessName, ProcessCommandLine
| order by EnvTime ascGet_Event_NetworkOutbound
| invoke Extract_Event_Network_Domain()
| where DomainName has_any ("<SUSPICIOUS_DOMAIN_1>", "<SUSPICIOUS_DOMAIN_2>")
| invoke Enrich_Ip_Employee()
| project EnvTime, Name, Role, DomainName, Url, ClientIp
| order by EnvTime descGet_Event_Authentication_All
| where not(ClientIp startswith "10.") and not(ClientIp startswith "192.168.")
| summarize
Attempts = count(),
Failures = countif(Result == "Failed Login"),
Users = make_set(Username)
by ClientIp
| order by Failures desc
| take 20| Tool | Purpose |
|---|---|
kusto_query | Execute IRQL pipelines against a Kusto database |
kusto_table_schema_get | Discover available tables and columns |
kusto_cluster_list | List available ADX clusters |
kusto_database_list | List databases in a cluster |
Optional convenience feature. The default workflow is to output the KQL in chat and let the user copy it into Kusto Explorer or the VS Code Kusto extension manually. Auto-launch is opt-in only.
Always output the complete KQL query in the chat response with Step 1 (connect) and Step 2 (query) clearly labeled:
// Step 1: Connect to your cluster (skip if already connected)
// Example: uncomment to connect to the KC7 training cluster
// #connect cluster('kc7001.eastus.kusto.windows.net').database('ValdyTimes')
// Or replace with your own cluster:
// #connect cluster('<YOUR_CLUSTER>').database('<YOUR_DATABASE>')
// Step 2: Run the query below
<KQL_QUERY>If the user asks to save or open in Kusto Explorer, follow the procedure in references/KUSTO_EXPLORER_LAUNCH.md. Key rules:
ask_user to confirm before writing files or launching executablesSet-Content/Add-Content.kql file and suggest the VS Code Kusto extension or ADX Web Explorerazure-kusto-graph and azure-kusto-irql-graph© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in plugins/azure-kusto-graph-skills/skills/azure-kusto-irql of microsoft/GitHub-Copilot-for-Azure.
Open the folder on GitHubat commit ce94fce
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.
Azure Kusto Irql next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure Kusto Irql this skillmicrosoft/GitHub-Copilot-for-Azure | 255 | — | ~2.6k | Automated safety check: Pass | MIT | |
| Sentinelvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Detecting Azure Service Principal Abusemukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.1k | Automated safety check: Pass | Apache-2.0 | |
| Analyzing Azure Activity Logs For Threatsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~609 | Automated safety check: Pass | Apache-2.0 | |
| Deploying Cloud Deception With Decoy Resourcesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Conducting Cloud Incident Responsemukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 |
vinayaklatthe/microsoft-security-skills
Guidance for designing and operating Microsoft Sentinel, the cloud-native SIEM and SOAR delivered through the Defender portal.
mukul975/Anthropic-Cybersecurity-Skills
Detect Azure service principal abuse in Microsoft Entra ID using KQL detection queries (Sentinel/Splunk) against Azure AD Audit and Sign-in Logs, covering added credentials, privileged role…
mukul975/Anthropic-Cybersecurity-Skills
Queries Azure Monitor activity logs and sign-in logs via azure-monitor-query to detect suspicious administrative operations, impossible travel, privilege escalation, and resource modifications.
mukul975/Anthropic-Cybersecurity-Skills
Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…
mukul975/Anthropic-Cybersecurity-Skills
Respond to security incidents in AWS, Azure, and GCP via identity-based containment, cloud-native log analysis (CloudTrail, Azure Activity Logs, GCP Audit Logs), resource isolation, and forensic…
trilwu/secskills
Investigate security incidents in Microsoft Azure (resource and subscription control plane) -- reconstruct attacker activity from the Azure Activity Log and resource/data-plane diagnostic logs…
microsoft/GitHub-Copilot-for-Azure
Discovers available Azure OpenAI model capacity across regions and projects.
microsoft/GitHub-Copilot-for-Azure
Unified Azure OpenAI model deployment skill with intelligent intent-based routing.
microsoft/GitHub-Copilot-for-Azure
Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.
microsoft/GitHub-Copilot-for-Azure
Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.
microsoft/GitHub-Copilot-for-Azure
Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…
microsoft/GitHub-Copilot-for-Azure
Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.
Works with
Categories
Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. Azure Kusto Irql is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations.
Azure Kusto Irql fits situations like: tasks that involve Incident response; tasks that involve Red teaming and adversary simulation; tasks that involve Security operations.
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql -a claude-code`. Or copy the skill folder (plugins/azure-kusto-graph-skills/skills/azure-kusto-irql in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/azure-kusto-irql in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql -a codex`. Or copy the skill folder (plugins/azure-kusto-graph-skills/skills/azure-kusto-irql in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/azure-kusto-irql in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kusto-irql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-kusto-irql, .gemini/skills/azure-kusto-irql, .github/skills/azure-kusto-irql and .opencode/skills/azure-kusto-irql in your project.
SKILL.md names no scripts, command-line tools or credentials: Azure Kusto Irql is instructions for the agent only.
SKILL.md names 1 domain. In commands or code: kc7001.eastus.kusto.windows.net; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azure Kusto Irql is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Azure Kusto Irql: Sentinel (vinayaklatthe/microsoft-security-skills, 175 stars), Detecting Azure Service Principal Abuse (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Analyzing Azure Activity Logs For Threats (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Deploying Cloud Deception With Decoy Resources (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 9, 2026.
Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.