Official agent skill

Azure Confidential Computing

by MicrosoftDocs in MicrosoftDocs/Agent-Skills

Expert knowledge for Azure Confidential Computing development including decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and…

OfficialCC-BY-4.0Auto-check: notesDevOps & Cloud

Install Azure Confidential Computing

skills CLI
$ npx skills add MicrosoftDocs/Agent-Skills --skill azure-confidential-computing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MicrosoftDocs/Agent-Skills azure-confidential-computing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MicrosoftDocs/Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-confidential-computing .claude/skills/azure-confidential-computing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-confidential-computing
GitHub stars
775
Token cost
~2.9k tokens
SKILL.md length
767 words
Files
1
Skills in repo
149
Repo updated
First seen
Licence
CC-BY-4.0

At a glance

Expert knowledge for Azure Confidential Computing development including decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and…

  • Building SGX/SEV-SNP apps
  • SKILL.md covers How to Use This Skill and Category Index
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • AKS confidential containers

What it does

Azure Confidential Computing is an agent skill from MicrosoftDocs/Agent-Skills, published by the product's own GitHub organization. Expert knowledge for Azure Confidential Computing development including decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building SGX/SEV-SNP apps, AKS confidential containers, vTPM/CVMs, Fortanix/Key Vault SKR, or clean rooms, and other Azure Confidential Computing related development tasks. Not for Azure Enclave (use azure-enclave), Azure Dedicated HSM (use azure-dedicated-hsm), Azure Cloud Hsm (use…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires network access. Uses mcpmicrosoftdocs:microsoftdocsfetch or fetchwebpage to retrieve documentation.

It sits in DevOps & Cloud, covering Design patterns, Secrets management and Deployment. It works with Microsoft Azure. The repository describes itself as: Curated Agent Skills for Microsoft & Azure – giving AI coding assistants structured, real-time expertise from Microsoft Learn docs. The licence is CC-BY-4.0.

When your agent uses it

  • Building SGX/SEV-SNP apps
  • AKS confidential containers
  • Fortanix/Key Vault SKR
  • Other Azure Confidential Computing related development tasks

Example prompts

  • “/azure-confidential-computing”

Requirements

  • Compatibility (from SKILL.md): Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.

What it can do on your machine

Read from SKILL.md and the folder at commit ba74e8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.

    From compatibility in the SKILL.md frontmatter.

Context cost

Azure Confidential Computing loads about 2.9k tokens when it runs. Until then it costs about 148 tokens; SKILL.md has 767 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~148
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:73
    | Harden Linux images by removing sudo users for confidential VMs | https://learn.microsoft.com/en-us/azure/confidential

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MicrosoftDocs/Agent-Skills at commit ba74e8f, republished under its CC-BY-4.0 licence (© MicrosoftDocs). 767 words, ~2,854 tokens.

Download SKILL.mdSave it as .claude/skills/azure-confidential-computing/SKILL.md (or your agent's skills folder).
name
azure-confidential-computing
description
Expert knowledge for Azure Confidential Computing development including decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building SGX/SEV-SNP apps, AKS confidential containers, vTPM/CVMs, Fortanix/Key Vault SKR, or clean rooms, and other Azure Confidential Computing related development tasks. Not for Azure Enclave (use azure-enclave), Azure Dedicated HSM (use azure-dedicated-hsm), Azure Cloud Hsm (use azure-cloud-hsm), Azure Payment Hsm (use azure-payment-hsm).
compatibility
Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.
metadata.generated_at
2026-09-13
metadata.generator
docs2skills/1.0.0

Azure Confidential Computing Skill

This skill provides expert guidance for Azure Confidential Computing. Covers decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
Decision MakingL35-L46Guidance on choosing Azure confidential computing options: VMs (AMD/Intel), containers, GPUs, deployment models, capabilities, products, and use cases for secure workloads.
Architecture & Design PatternsL47-L56Architectural patterns and design guidance for using Azure confidential VMs, SGX enclaves, AKS, and multi-party analytics to build secure AI and containerized workloads.
Limits & QuotasL57-L62Intel SGX capacity, quotas, and sizing for Azure confidential computing: AKS confidential node limits, SGX VM sizing guidance, and FAQ on SGX resource constraints.
SecurityL63-L77Security, attestation, and key/secrets management for Azure confidential workloads: SGX enclaves, CVMs, vTPM, AKS confidential containers, clean rooms, and hardening Linux images.
ConfigurationL78-L89Configuring and deploying Azure confidential VMs and AKS (SGX, containers), managing keys and secure key release policies, and using/opt-ing out of VMMD metablob disks.
Integrations & Coding PatternsL90-L100Coding patterns and samples for building, running, and attesting Intel SGX/AMD SEV-SNP confidential apps and containers, including SKR flows, tools, and Fortanix/Key Vault integrations.
DeploymentL101-L109How to deploy and migrate Azure confidential VMs/VMSS and AKS (SGX and confidential node pools), create custom images, and set up Fortanix CCM using CLI and ARM templates.
Decision Making
Architecture & Design Patterns
Show full SKILL.md (316 more words)Show less
Limits & Quotas
Security
TopicURL
Configure attestation for Azure SGX enclaveshttps://learn.microsoft.com/en-us/azure/confidential-computing/attestation
Use attestation types for Azure confidential workloadshttps://learn.microsoft.com/en-us/azure/confidential-computing/attestation-solutions
Security model for AKS Confidential Containershttps://learn.microsoft.com/en-us/azure/confidential-computing/confidential-containers-aks-security-policy
Understand security details for Azure confidential VMshttps://learn.microsoft.com/en-us/azure/confidential-computing/confidential-vm-faq
Configure guest attestation for Azure confidential VMshttps://learn.microsoft.com/en-us/azure/confidential-computing/guest-attestation-confidential-vms
Secure confidential VMs with Defender for Cloud and guest attestationhttps://learn.microsoft.com/en-us/azure/confidential-computing/guest-attestation-defender-for-cloud
Harden Linux images by removing Azure guest agenthttps://learn.microsoft.com/en-us/azure/confidential-computing/harden-a-linux-image-to-remove-azure-guest-agent
Harden Linux images by removing sudo users for confidential VMshttps://learn.microsoft.com/en-us/azure/confidential-computing/harden-the-linux-image-to-remove-sudo-users
Leverage vTPM features in Linux confidential VMshttps://learn.microsoft.com/en-us/azure/confidential-computing/how-to-leverage-virtual-tpms-in-azure-confidential-vms
Manage secrets and keys in Azure confidential computinghttps://learn.microsoft.com/en-us/azure/confidential-computing/secret-key-management
Use virtual TPMs in Azure confidential VMs securelyhttps://learn.microsoft.com/en-us/azure/confidential-computing/virtual-tpms-in-azure-confidential-vm
Configuration
Integrations & Coding Patterns
Deployment

© MicrosoftDocs, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-confidential-computing of MicrosoftDocs/Agent-Skills.

Open the folder on GitHubat commit ba74e8f

Compare with similar skills

Azure Confidential Computing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Confidential Computing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Confidential Computing this skillMicrosoftDocs/Agent-Skills775—~2.9kAutomated safety check: NotesCC-BY-4.0
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Letta Configurationletta-ai/skills147—~1.3kAutomated safety check: NotesMIT
CD Pipeline GeneratorArabelaTso/Skills-4-SE253—~1.3kAutomated safety check: PassApache-2.0
Deploying Cloud Deception With Decoy Resourcesmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Configure Env Variablesmicrosoft/power-platform-skills967—~8.5kAutomated safety check: NotesMIT

Similar skills

  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Letta Configuration

    letta-ai/skills

    Configure LLM models and providers for Letta agents and servers.

    147 GitHub stars~1.3k tokensUpdated 5 days ago
    DevOps & CloudAuto-check: notes
  • CD Pipeline Generator

    ArabelaTso/Skills-4-SE

    Generate GitHub Actions deployment workflows for automated deployment to staging and production environments on cloud platforms (AWS, GCP, Azure).

    253 GitHub stars~1.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Deploying Cloud Deception With Decoy Resources

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy cloud-native deception across AWS, Azure, and GCP using decoy (honey) resources whose only purpose is to generate a high-fidelity alert the instant an attacker touches them: canary IAM access…

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Configure Env Variables

    microsoft/power-platform-skills

    Official

    Configures environment variables for Power Pages site settings to support ALM across environments.

    967 GitHub stars~8.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Aspire

    microsoft/aspire.dev

    Official

    Orchestrates Aspire distributed applications using the Aspire CLI for running, debugging, and managing distributed apps.

    196 GitHub starsUsed in 4 repos~1.1k tokens
    DevOps & CloudAuto-check passed

More from MicrosoftDocs/Agent-Skills

All 149 skills in this repo
  • Azure Personalizer

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Personalizer development including troubleshooting, decision making, security, configuration, and integrations & coding patterns.

    775 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Azure Architecture Advisor

    MicrosoftDocs/Agent-Skills

    Official

    Guides Azure solution design by category, from reference architectures and design patterns to technology choices and migrations, fetching current Microsoft Learn pages over the network.

    775 GitHub stars~15k tokensUpdated yesterday
    Auto-check passed
  • Azure Advisor Guidance

    MicrosoftDocs/Agent-Skills

    Official

    Reference guidance for Azure Advisor work: recommendations, alerts and digests, workbooks, RBAC access and sovereign-cloud limits, fetched from Microsoft Learn.

    775 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Azure AI Vision Reference

    MicrosoftDocs/Agent-Skills

    Official

    Looks up Microsoft Learn guidance for Azure AI Vision: Image Analysis, Read OCR containers, smart-crop thumbnails, background removal and video frame analysis, plus limits and deployment.

    775 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Azure Analysis Services

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Analysis Services development including troubleshooting.

    775 GitHub stars~608 tokensUpdated yesterday
    Auto-check passed
  • Azure Anomaly Detector

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Anomaly Detector development including troubleshooting, best practices, limits & quotas, configuration, and deployment.

    775 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Azure Confidential Computing

What does Azure Confidential Computing do?

Expert knowledge for Azure Confidential Computing development including decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and…. Azure Confidential Computing is an agent skill from MicrosoftDocs/Agent-Skills, published by the product's own GitHub organization. Expert knowledge for Azure Confidential Computing development including decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment.

When should I use Azure Confidential Computing?

Azure Confidential Computing fits situations like: building SGX/SEV-SNP apps; AKS confidential containers; fortanix/Key Vault SKR; other Azure Confidential Computing related development tasks.

How do I install Azure Confidential Computing in Claude Code?

Run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-confidential-computing -a claude-code`. Or copy the skill folder (skills/azure-confidential-computing in MicrosoftDocs/Agent-Skills) into .claude/skills/azure-confidential-computing in your project. Claude Code loads it when a task matches its description.

How do I install Azure Confidential Computing in Codex?

Run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-confidential-computing -a codex`. Or copy the skill folder (skills/azure-confidential-computing in MicrosoftDocs/Agent-Skills) into .agents/skills/azure-confidential-computing in your project. Codex loads it when a task matches its description.

Can I use Azure Confidential Computing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-confidential-computing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-confidential-computing, .gemini/skills/azure-confidential-computing, .github/skills/azure-confidential-computing and .opencode/skills/azure-confidential-computing in your project.

What does Azure Confidential Computing need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Confidential Computing is instructions for the agent only. Compatibility (from SKILL.md): Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation..

Does Azure Confidential Computing access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Azure Confidential Computing safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Azure Confidential Computing use?

Azure Confidential Computing is published under the CC-BY-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Confidential Computing use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Confidential Computing?

Skills that share tags, products or a category with Azure Confidential Computing: Azure Bicep Skill (timothywarner-org/claude-code, 224 stars), Letta Configuration (letta-ai/skills, 147 stars), CD Pipeline Generator (ArabelaTso/Skills-4-SE, 253 stars) and Deploying Cloud Deception With Decoy Resources (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Confidential Computing?

MicrosoftDocs (a GitHub organization, an official publisher) maintains it in MicrosoftDocs/Agent-Skills, which has 775 GitHub stars. The repository holds 149 skills in this directory. The repository was last updated on October 5, 2026.

Source: MicrosoftDocs/Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.