Agent skill

Azure API Management Security Review

by thomast1906 in thomast1906/github-copilot-agent-skills

Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

MITAuto-check passedSecurity

Install Azure API Management Security Review

skills CLI
$ npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install thomast1906/github-copilot-agent-skills api-security-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/thomast1906/github-copilot-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/api-security-review .claude/skills/api-security-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
api-security-review
GitHub stars
202
Token cost
~3.1k tokens
SKILL.md length
1,000 words
Files
2 (incl. references)
Skills in repo
15
Repo updated
First seen
Licence
MIT

At a glance

Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity.

  • Works in 12 steps: OWASP API Security Top 10 (2023 RC) → Call Security Best Practices FIRST → Search Security Documentation → …
  • Security audit of an APIM instance before it goes live
  • SKILL.md covers When to Use This Skill, Security Review Framework, Security Controls Checklist and Important: MCP Tools (ALWAYS…, plus 5 more sections
  • Reaches login.microsoftonline.com

What it does

This skill has the agent review an Azure API Management instance for security gaps. It maps each of the ten OWASP API Security risks (2023 RC) to the APIM policy or network control that addresses it, such as validate-jwt for authentication and authorization checks, rate-limit-by-key for resource consumption, and VNet Internal mode with Private Link for SSRF.

A longer checklist in references/SECURITY_CONTROLS.md lists more than 60 controls across 9 categories, and a quick summary groups them into areas like network security, identity and access, and data protection. The review works from the configuration and policies you give it and fits pre-deployment checks, audits, post-incident reviews and compliance work against Azure Security Benchmark and CIS Azure.

When your agent uses it

  • Security audit of an APIM instance before it goes live
  • Confirming APIM runs in VNet Internal mode with Private Link to backends
  • Compliance review against the OWASP API Top 10 or Azure Security Benchmark
  • Reviewing API Management configuration after a security incident

Example prompts

  • “Review our APIM policies against the OWASP API Security Top 10 before the production release.”
  • “Confirm that our API Management instance really uses VNet Internal mode and Private Link.”
  • “We had an incident last week, so go through the APIM config and list the authentication gaps.”

Requirements

  • Access to the APIM configuration and policies to be reviewed

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. OWASP API Security Top 10 (2023 RC)
  2. Call Security Best Practices FIRST
  3. Search Security Documentation
  4. Query Existing Resources (If Reviewing Deployed Environment)
  5. VNet Internal Mode Validation
  6. Private Link Validation
  7. Authentication Configuration
  8. Rate Limiting Configuration
  9. TLS Configuration
  10. Secret Management
  11. CORS Configuration
  12. Error Response Validation

What it can do on your machine

Read from SKILL.md and the folder at commit 554ac0b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are xml and kql).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • login.microsoftonline.com

    Also links to:

    • learn.microsoft.com
    • owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure API Management Security Review loads about 3.1k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 79 tokens; SKILL.md has 1,000 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from thomast1906/github-copilot-agent-skills at commit 554ac0b, republished under its MIT licence (© thomast1906). 1,000 words, ~3,091 tokens.

Download SKILL.mdSave it as .claude/skills/api-security-review/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
api-security-review
description
Reviews Azure API Management configurations for security vulnerabilities, OWASP API Security Top 10 compliance, VNet Internal mode validation, Private Link verification, and Azure Security Benchmark alignment. Use when performing security audits, pre-deployment validation, or compliance reviews.
license
MIT
metadata.author
Thomas Thornton
metadata.version
1.0.0
metadata.last-updated
2026-05-19
metadata.azure-services
api-management, security-center
metadata.compliance-frameworks
owasp-api-top10,azure-security-benchmark,cis-azure

API Security Review Skill

Performs comprehensive security reviews of Azure API Management configurations, policies, and network architecture with focus on OWASP API Security Top 10 and Azure Security Benchmark.

When to Use This Skill

Activate this skill when users need:

  • Security audits: Comprehensive review of APIM configuration and policies
  • Pre-deployment validation: Security checklist before production deployment
  • Compliance reviews: OWASP API Top 10, Azure Security Benchmark, CIS Azure alignment
  • Vulnerability assessments: Identify security gaps in authentication, network, policies
  • Incident response: Review configuration after security incident
  • Architecture validation: Verify VNet Internal mode, Private Link, authentication setup

Security Review Framework

1. OWASP API Security Top 10 (2023 RC)
IDThreatAPIM Mitigation
API1Broken Object Level AuthorizationPolicy: validate-jwt + check user claims for resource ownership
API2Broken AuthenticationPolicy: OAuth 2.0 (validate-jwt), no plaintext credentials
API3Broken Object Property Level AuthorizationPolicy: Validate input/output schemas, mask sensitive fields
API4Unrestricted Resource ConsumptionPolicy: rate-limit-by-key (per user/subscription), quota enforcement
API5Broken Function Level AuthorizationPolicy: Validate JWT scopes/roles per operation
API6Unrestricted Access to Sensitive Business FlowsPolicy: Advanced rate limiting, CAPTCHA integration
API7Server Side Request Forgery (SSRF)Network: VNet Internal mode, Private Link to backends
API8Security MisconfigurationInfrastructure: TLS 1.3, disable weak ciphers, NSG rules
API9Improper Inventory ManagementGovernance: Azure API Center, version tracking, deprecation
API10Unsafe Consumption of APIsPolicy: Validate backend responses, timeout policies

Security Controls Checklist

See references/SECURITY_CONTROLS.md for complete 60+ control checklist across 9 categories

Quick Control Summary
  1. Network Security (NS-): VNet Internal, Private Link, NSG, no public IPs
  2. Identity & Access (IA-): OAuth 2.0, MFA, PIM, no service accounts
  3. Data Protection (DP-): TLS 1.3, Key Vault, no PII in logs
  4. Logging & Threat (LT-): App Insights, correlation IDs, SIEM integration
  5. Identity Management (IM-): Managed Identity, RBAC, least privilege
  6. Recovery (RA-): Backups, zone redundancy, DR plan
  7. Governance (GS-): API Center, policy enforcement, compliance
  8. Posture (PS-): Azure Policy, Defender for APIs, vulnerability scanning
  9. DevSecOps (DV-): APIOps, IaC security, secret scanning

Important: MCP Tools (ALWAYS Use)

1. Call Security Best Practices FIRST
Tool: mcp_azure_mcp_get_azure_bestpractices
Intent: "Azure API Management security best practices"
2. Search Security Documentation
Tool: mcp_azure_mcp_documentation search
Query: "APIM security best practices OWASP"
3. Query Existing Resources (If Reviewing Deployed Environment)
Tool: azure_resources-query_azure_resource_graph
Intent: "Get API Management instances with network configuration and SKU details"

Critical Security Validations

1. VNet Internal Mode Validation

Check: APIM instances deployed in VNet Internal mode (no public IP)

kql
// Azure Resource Graph Query
resources
| where type == 'microsoft.apimanagement/service'
| extend vnetType = properties.virtualNetworkType
| where vnetType != 'Internal'
| project name, resourceGroup, location, vnetType, sku=properties.sku.name

Expected: vnetType == 'Internal' for all production APIM instances

Risk if External: Gateway endpoint exposed to public internet, larger attack surface


Check: Azure Front Door connects to APIM via Private Link (not public origin)

Validation Steps:

  1. Front Door origin type = Private Link (not Custom or Public)
  2. Private Link target = APIM resource ID
  3. Private Link status = Approved (not Pending)
  4. APIM has no public DNS record resolving to public IP

Risk if Public: Traffic goes over public internet, no zero-trust architecture


3. Authentication Configuration

Check: APIs use OAuth 2.0 (validate-jwt policy) or subscription keys (not both for sensitive APIs)

Policy Review:

xml
<!-- GOOD: OAuth for sensitive APIs -->
<validate-jwt header-name="Authorization">
    <openid-config url="https://login.microsoftonline.com/{tenant}/..." />
    <required-claims>
        <claim name="scp" match="any">
            <value>api.read</value>
        </claim>
    </required-claims>
</validate-jwt>

<!-- BAD: No authentication -->
<policies>
    <inbound>
        <base />
        <!-- No validate-jwt or check-header -->
    </inbound>
</policies>

Risk if Missing: Unauthenticated access to sensitive data, API abuse


4. Rate Limiting Configuration

Check: All APIs have rate limiting (rate-limit-by-key or quota-by-key)

Policy Review:

xml
<!-- GOOD: Per-user rate limiting -->
<rate-limit-by-key calls="1000" renewal-period="3600" 
                   counter-key="@((string)context.Variables['userId'])" />

<!-- BAD: No rate limiting -->
<policies>
    <inbound>
        <base />
        <!-- No rate-limit-by-key -->
    </inbound>
</policies>

Risk if Missing: API4 Unrestricted Resource Consumption, DDoS vulnerability


5. TLS Configuration

Check: TLS 1.2+ only, no SSL 3.0/TLS 1.0/TLS 1.1

Azure Portal Validation:

  • APIM → Security → Protocols → TLS 1.0 Disabled
  • APIM → Security → Protocols → TLS 1.1 Disabled
  • APIM → Security → Protocols → SSL 3.0 Disabled
  • APIM → Security → Ciphers → Weak ciphers Disabled

Risk if Enabled: Vulnerable to BEAST, POODLE, CRIME attacks


6. Secret Management

Check: All secrets/certificates stored in Azure Key Vault (not in policies or code)

Policy Review:

xml
<!-- GOOD: Secret from Key Vault -->
<set-header name="X-API-Key">
    <value>{{api-backend-key}}</value> <!-- Named value linked to Key Vault -->
</set-header>

<!-- BAD: Hardcoded secret -->
<set-header name="X-API-Key">
    <value>sk-abc123xyz789</value>
</set-header>

Risk if Hardcoded: Secret exposure in logs, code repositories, APIM exports


7. CORS Configuration

Check: CORS policies have specific origins (not * wildcard for production)

xml
<!-- GOOD: Specific origins -->
<cors allow-credentials="true">
    <allowed-origins>
        <origin>https://app.example.com</origin>
    </allowed-origins>
</cors>

<!-- Warning: ACCEPTABLE FOR DEV: Wildcard -->
<cors allow-credentials="false">
    <allowed-origins>
        <origin>*</origin>
    </allowed-origins>
</cors>

<!-- BAD: Wildcard with credentials -->
<cors allow-credentials="true">
    <allowed-origins>
        <origin>*</origin> <!-- Security risk! -->
    </allowed-origins>
</cors>

Risk: CSRF attacks, credential theft if misconfigured


Show full SKILL.md (391 more words)Show less
8. Error Response Validation

Check: Error responses don't leak sensitive information (stack traces, internal IPs)

Policy Review:

xml
<!-- GOOD: Generic error -->
<on-error>
    <set-body>@{
        return new JObject(
            new JProperty("error", "Internal server error"),
            new JProperty("correlationId", context.Variables["correlationId"])
        ).ToString();
    }</set-body>
</on-error>

<!-- BAD: Detailed error -->
<on-error>
    <set-body>@{
        return context.LastError.Message; // Might contain stack trace, DB connection strings
    }</set-body>
</on-error>

Risk: Information disclosure (API3, API8)


Security Review Output Format

When performing security review, structure findings as:

Finding: [Title]
  • Severity: Critical | High | Medium | Low
  • OWASP Mapping: API1, API4, API8, etc.
  • Azure Security Benchmark: NS-1, DP-2, IA-3, etc.
  • Current State: What was found
  • Risk: Impact if not fixed
  • Remediation: Step-by-step fix with code examples
  • Microsoft Docs: Link to official guidance
  • Priority: Immediate | Before Production | Post-Launch

Example:

Finding: VNet External Mode Detected
  • Severity: Critical
  • OWASP Mapping: API7 (SSRF), API8 (Security Misconfiguration)
  • Azure Security Benchmark: NS-1 (Network Segmentation)
  • Current State: APIM instance apim-api-marketplace-prod-uks deployed in VNet External mode with gateway endpoint 10.2.1.4 exposed via public IP
  • Risk: Gateway endpoint accessible from public internet, no network isolation, vulnerable to DDoS bypassing Front Door
  • Remediation:
    1. Redeploy APIM in VNet Internal mode:
      bash
      az apim update --name apim-api-marketplace-prod-uks --resource-group rg-apim-prod-uks \
        --virtual-network-type Internal
    2. Update Front Door origin to use Private Link (not public IP)
    3. Verify no public DNS resolution: nslookup apim-api-marketplace-prod-uks.azure-api.net should return internal IP only
  • Microsoft Docs: APIM VNet Internal Mode
  • Priority: Immediate (block production deployment)

Azure Security Benchmark Quick Reference

Control IDCategoryRequirementAPIM Implementation
NS-1Network SegmentationIsolate workloadsVNet Internal mode
NS-2Private ConnectivityPrivate Link/EndpointsFront Door → APIM Private Link
NS-4DDoS ProtectionEnable DDoS Standard or ingress with DDoSFront Door Premium (DDoS included)
IA-2Secure AuthenticationOAuth/MFAvalidate-jwt with Entra ID
IA-5MFA EnforcementRequire MFAEntra ID Conditional Access
DP-1Data at Rest EncryptionEncrypt sensitive dataAzure Managed Disks encryption
DP-3Data in Transit EncryptionTLS 1.2+APIM TLS 1.3, disable weak protocols
DP-4Encryption Key ManagementAzure Key VaultAll secrets in Key Vault
LT-1Centralized LoggingLog all security eventsApp Insights, Azure Monitor
LT-4Audit LoggingTamper-proof audit trailAzure Activity Log, diagnostic logs
IM-1Managed IdentitiesAvoid service accountsAPIM Managed Identity
IM-3Least PrivilegeRBACCustom roles per environment
GS-1Policy EnforcementAzure PolicyRequire VNet Internal, TLS 1.2+

  • apim-policy-authoring - Review policies created by this skill for security
  • azure-apim-architecture - Understand architecture security decisions
  • apiops-deployment - Integrate security checks into CI/CD pipeline

Microsoft Documentation


Skill Version: 1.0
Last Updated: 29 January 2026
Primary Knowledge: SECURITY_CONTROLS_CHECKLIST.md, references/SECURITY_CONTROLS.md

© thomast1906, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in .github/skills/api-security-review of thomast1906/github-copilot-agent-skills.

  • SKILL.md
  • references/SECURITY_CONTROLS.md

Open the folder on GitHubat commit 554ac0b

Compare with similar skills

Azure API Management Security Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure API Management Security Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure API Management Security Review this skillthomast1906/github-copilot-agent-skills202—~3.1kAutomated safety check: PassMIT
Security ReviewerAratKruglik/claude-laravel1551 repos~1.1kAutomated safety check: NotesNone
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Security Analyzeraiskillstore/marketplace430—~1.2kAutomated safety check: NotesNone
Security Auditoraiskillstore/marketplace4306 repos~2.6kAutomated safety check: PassNone
Security Reviewjewbetcha/opentrace11618 repos~3.1kAutomated safety check: NotesMIT

Similar skills

  • Security Reviewer

    AratKruglik/claude-laravel

    A skill your agent uses when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security.

    155 GitHub starsUsed in 1 repo~1.1k tokens
    SecurityAuto-check: notes
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Security Analyzer

    aiskillstore/marketplace

    Comprehensive security vulnerability analysis for codebases and infrastructure.

    430 GitHub stars~1.2k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Auditor

    aiskillstore/marketplace

    Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

    430 GitHub starsUsed in 6 repos~2.6k tokens
    SecurityAuto-check passed
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 18 repos~3.1k tokens
    SecurityAuto-check: notes
  • Runs and interprets Psalm security (taint) analysis on a Laravel project.

    230 GitHub stars~4.7k tokensUpdated 3 days ago
    SecurityAuto-check passed

More from thomast1906/github-copilot-agent-skills

All 15 skills in this repo
  • Copilot Skill Creator

    thomast1906/github-copilot-agent-skills

    Guides creating, updating, reviewing and validating GitHub Copilot agent skills, from deciding whether a skill is the right tool to structuring bundled resources.

    202 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Azure APIM Policy Authoring

    thomast1906/github-copilot-agent-skills

    Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.

    202 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check passed
  • Azure Draw.io MCP Diagrams

    thomast1906/github-copilot-agent-skills

    Creates and edits architecture diagrams through the Draw.io MCP tool, with guidance for rendering Azure icons correctly and laying out network diagrams.

    202 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • Azure Pricing Lookup

    thomast1906/github-copilot-agent-skills

    Looks up live Azure retail prices by SKU, service or region through the Azure MCP pricing tool, estimates template costs and compares regions, price types and savings plans.

    202 GitHub stars~4.9k tokensUpdated yesterday
    Auto-check passed
  • Excalidraw MCP Diagramming

    thomast1906/github-copilot-agent-skills

    Create and edit diagrams on a live Excalidraw canvas using the Excalidraw MCP server.

    202 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed

Questions about Azure API Management Security Review

What does Azure API Management Security Review do?

Audits an Azure API Management setup against the OWASP API Security Top 10 and Azure Security Benchmark, covering policies, network layout and identity. This skill has the agent review an Azure API Management instance for security gaps. It maps each of the ten OWASP API Security risks (2023 RC) to the APIM policy or network control that addresses it, such as validate-jwt for authentication and authorization checks, rate-limit-by-key for resource consumption, and VNet Internal mode with Private Link for SSRF.

When should I use Azure API Management Security Review?

Azure API Management Security Review fits situations like: security audit of an APIM instance before it goes live; confirming APIM runs in VNet Internal mode with Private Link to backends; compliance review against the OWASP API Top 10 or Azure Security Benchmark; reviewing API Management configuration after a security incident.

How do I install Azure API Management Security Review in Claude Code?

Run `npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a claude-code`. Or copy the skill folder (.github/skills/api-security-review in thomast1906/github-copilot-agent-skills) into .claude/skills/api-security-review in your project. Claude Code loads it when a task matches its description.

How do I install Azure API Management Security Review in Codex?

Run `npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a codex`. Or copy the skill folder (.github/skills/api-security-review in thomast1906/github-copilot-agent-skills) into .agents/skills/api-security-review in your project. Codex loads it when a task matches its description.

Can I use Azure API Management Security Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add thomast1906/github-copilot-agent-skills --skill api-security-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/api-security-review, .gemini/skills/api-security-review, .github/skills/api-security-review and .opencode/skills/api-security-review in your project.

What does Azure API Management Security Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure API Management Security Review is instructions for the agent only. Our summary lists: Access to the APIM configuration and policies to be reviewed.

Does Azure API Management Security Review access the network?

SKILL.md names 3 domains. In commands or code: login.microsoftonline.com; the agent is likely to contact it when it follows the instructions. As links in the text: learn.microsoft.com and owasp.org. This is read from the text; nothing was executed.

Is Azure API Management Security Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure API Management Security Review use?

Azure API Management Security Review is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure API Management Security Review use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 700 tokens, read only when the agent opens those files.

What are the alternatives to Azure API Management Security Review?

Skills that share tags, products or a category with Azure API Management Security Review: Security Reviewer (AratKruglik/claude-laravel, 155 stars), API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Security Analyzer (aiskillstore/marketplace, 430 stars) and Security Auditor (aiskillstore/marketplace, 430 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure API Management Security Review?

thomast1906 (a GitHub user) maintains it in thomast1906/github-copilot-agent-skills, which has 202 GitHub stars. The repository holds 15 skills in this directory. The repository was last updated on October 7, 2026.

Source: thomast1906/github-copilot-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.