Provider Bug Review
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-arc --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-arc .claude/skills/azure-arc && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azure-arc" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-arc into .claude/skills/azure-arc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-arc", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-arcType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-arc --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/azure-arc .agents/skills/azure-arc && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azure-arc" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-arc into .agents/skills/azure-arc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-arc", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-arc --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/azure-arc .cursor/skills/azure-arc && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azure-arc" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-arc into .cursor/skills/azure-arc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-arc", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vinayaklatthe/microsoft-security-skills.git --path skills/azure-arc--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-arc --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/azure-arc .gemini/skills/azure-arc && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azure-arc" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-arc into .gemini/skills/azure-arc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-arc", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-arcInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/azure-arc .github/skills/azure-arc && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azure-arc" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-arc into .github/skills/azure-arc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-arc", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-arc --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/azure-arc .opencode/skills/azure-arc && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azure-arc" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-arc into .opencode/skills/azure-arc/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-arc", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azure-arcGuidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
Azure Arc is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management. Covers Arc-enabled servers onboarding, extending Defender for Cloud and Azure Policy to non-Azure machines, and Arc-enabled Kubernetes. WHEN: Azure Arc, manage on-prem servers from Azure, hybrid management, Arc-enabled servers, Arc Kubernetes, extend Defender for Cloud to on-prem, govern multicloud machines, Connected…
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Container orchestration. It works with Microsoft Azure, Kubernetes, Microsoft Defender and Amazon Web Services. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure Arc loads about 1.9k tokens when it runs. Until then it costs about 200 tokens; SKILL.md has 856 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 856 words, ~1,946 tokens.
.claude/skills/azure-arc/SKILL.md (or your agent's skills folder).Azure Arc projects on-premises, multicloud, and edge resources into Azure Resource Manager so they can be governed, secured, and managed with the same control plane as Azure-native resources, extending Azure Policy, Microsoft Defender for Cloud, and Azure Monitor to hybrid estates.
Bringing non-Azure servers, Kubernetes clusters, and data services under consistent Azure governance and security. Use this skill when you need one pane of glass and policy plane across hybrid / multicloud machines.
Do not use this skill for Azure-native VMs (use ARM directly), Intune-managed endpoints
(intune-device-mgmt), or Azure Stack HCI deployment.
| Resource type | Arc service | What you get |
|---|---|---|
| On-prem / AWS / GCP server | Arc-enabled servers | Defender for Cloud, Policy, Update Manager, Monitor, RBAC |
| Non-AKS Kubernetes (on-prem, EKS, GKE) | Arc-enabled Kubernetes | GitOps via Flux, Policy, Monitor, Defender for Containers |
| SQL Server on-prem / other cloud | Arc-enabled SQL Server | Inventory, best-practice assessment, Defender |
| PostgreSQL / SQL MI at edge | Arc-enabled data services | Managed PaaS-like experience at edge |
| Hybrid app platform (containerised) | Arc-enabled App Services / Functions | PaaS runtime on Arc-enabled K8s |
Rule of thumb: start with Arc-enabled servers for hybrid posture - it's the highest-value, lowest-friction step. The Connected Machine agent gives you Defender for Cloud and Azure Policy across the hybrid estate for the price of an outbound HTTPS connection.
Plan the onboarding scope and identity — Decide which subscriptions / resource groups
own the Arc resources. Define the target resource group per region / per business unit.
Pre-create service principals if onboarding at scale via script.
Verify: target RG exists with the Azure Connected Machine Onboarding role assigned to
the onboarding identity.
Plan network and proxy requirements — Connected Machine agent needs outbound HTTPS
(443) to a defined list of Microsoft endpoints. If servers are behind a corporate proxy,
configure the agent for proxy + auth. Some endpoints require firewall allowlisting.
Verify: a pilot server can reach *.his.arc.azure.com, *.guestconfiguration.azure.com,
*.dp.kubernetesconfiguration.azure.com (for K8s); agent install completes.
Onboard servers at scale — Pilot 5-10 servers manually (one Windows, one Linux).
Then script the rollout: GPO / Ansible / Configuration Manager for Windows; cloud-init /
Ansible for Linux. The agent script accepts service principal + tags.
Verify: Arc resource appears in the target RG; Connected status; tags applied.
Govern with Azure Policy + machine configuration — Assign Azure Policy initiatives (e.g. Azure Security Benchmark) at the RG / subscription scope. Machine configuration (formerly guest configuration) audits in-OS settings on Arc machines just like Azure VMs. Verify: ASB initiative shows compliance state for Arc machines; in-OS audit returns results (e.g. password complexity).
Extend Defender for Cloud — Enable Defender for Servers Plan 2 on the subscription that contains the Arc resources. Defender deploys MDE, file integrity monitoring, and adaptive controls to the Arc machines. Verify: Defender for Servers shows Arc machines as protected; MDE shows them onboarded.
Unify monitoring + updates — Send Arc machines' logs to Log Analytics via Azure Monitor Agent (extension). Use Azure Update Manager to assess and deploy updates from Azure across the hybrid fleet.
Grant access via Azure RBAC — Arc machines are ARM resources. Use Azure RBAC + PIM for who can manage them. The Arc agent also enables a managed identity on the machine for outbound calls to Azure services.
Onboard on-premises servers to Azure with Arc and extend Defender for Cloud to them.How do I govern multicloud machines from Azure using Azure Arc?Deploy the Azure Arc agent at scale via service principal and apply security policy.Bring Arc-enabled Kubernetes clusters under central governance with Flux GitOps.Apply the Azure Security Benchmark initiative to Arc-enabled servers.Plan network and proxy requirements before broad Arc onboarding.© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/azure-arc of vinayaklatthe/microsoft-security-skills.
Open the folder on GitHubat commit 15f16df
Azure Arc next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure Arc this skillvinayaklatthe/microsoft-security-skills | 175 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Provider Bug Reviewmondoohq/mql | 412 | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Kcli Cluster Deploymentkarmab/kcli | 653 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Extend Discovery Typerunwhen-contrib/runwhen-local | 163 | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Kclikarmab/kcli | 653 | — | ~2.6k | Automated safety check: Warn | Apache-2.0 | |
| Provider API Call Dedupmondoohq/mql | 412 | — | ~7.7k | Automated safety check: Pass | Custom licence |
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
runwhen-contrib/runwhen-local
Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes).
karmab/kcli
Comprehensive guide for kcli usage. An agent skill from karmab/kcli.
mondoohq/mql
A skill your agent uses when a provider scan is slow, times out, or trips rate limits (429, throttling, Retry-After), when the same request URL appears many times in a debug log, when an asset's…
davila7/claude-code-templates
Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
vinayaklatthe/microsoft-security-skills
Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).
vinayaklatthe/microsoft-security-skills
Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control.
Categories
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management. Azure Arc is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
Azure Arc fits situations like: azure-native VMs only (use Azure Resource Manager directly); intune-managed endpoints (use intune-device-mgmt); azure Stack HCI specifically (separate product).
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a claude-code`. Or copy the skill folder (skills/azure-arc in vinayaklatthe/microsoft-security-skills) into .claude/skills/azure-arc in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a codex`. Or copy the skill folder (skills/azure-arc in vinayaklatthe/microsoft-security-skills) into .agents/skills/azure-arc in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-arc -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-arc, .gemini/skills/azure-arc, .github/skills/azure-arc and .opencode/skills/azure-arc in your project.
SKILL.md names no scripts, command-line tools or credentials: Azure Arc is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azure Arc is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Azure Arc: Provider Bug Review (mondoohq/mql, 412 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars), Extend Discovery Type (runwhen-contrib/runwhen-local, 163 stars) and Kcli (karmab/kcli, 653 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.
Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.