Azure Key Vault
Kilo-Org/kilo-marketplace
Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.
Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall…
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-network-security-design --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-network-security-design .claude/skills/azure-network-security-design && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azure-network-security-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-network-security-design into .claude/skills/azure-network-security-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-network-security-design", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-network-security-designType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-network-security-design --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/azure-network-security-design .agents/skills/azure-network-security-design && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azure-network-security-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-network-security-design into .agents/skills/azure-network-security-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-network-security-design", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-network-security-design --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/azure-network-security-design .cursor/skills/azure-network-security-design && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azure-network-security-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-network-security-design into .cursor/skills/azure-network-security-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-network-security-design", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vinayaklatthe/microsoft-security-skills.git --path skills/azure-network-security-design--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-network-security-design --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/azure-network-security-design .gemini/skills/azure-network-security-design && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azure-network-security-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-network-security-design into .gemini/skills/azure-network-security-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-network-security-design", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-network-security-designInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/azure-network-security-design .github/skills/azure-network-security-design && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azure-network-security-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-network-security-design into .github/skills/azure-network-security-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-network-security-design", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills azure-network-security-design --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/azure-network-security-design .opencode/skills/azure-network-security-design && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azure-network-security-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/azure-network-security-design into .opencode/skills/azure-network-security-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-network-security-design", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azure-network-security-designGuidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall…
Azure Network Security Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall, DDoS protection, WAF on Front Door/App Gateway, and centralised private DNS. Aligned to the Zero Trust network pillar. WHEN: Azure network security, hub spoke, Virtual WAN, network segmentation, NSG ASG design, private endpoint, Private Link, DDoS protection, secure virtual network, egress control, Zero Trust network…
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Network security. It works with Microsoft Azure, Azure Key Vault and Microsoft Defender. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure Network Security Design loads about 1.8k tokens when it runs. Until then it costs about 191 tokens; SKILL.md has 797 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 797 words, ~1,817 tokens.
.claude/skills/azure-network-security-design/SKILL.md (or your agent's skills folder).Secure Azure networking applies Zero Trust to the network pillar: segment, control traffic explicitly, prefer private connectivity, and inspect / filter egress, assuming the network is hostile. The output is a hub-spoke (or Virtual WAN) topology with NSG microsegmentation, private endpoints, and a single controlled egress path.
Designing the network topology and controls for an Azure landing zone or workload. Use this skill to pick topology, design segmentation, and place controls.
Do not use this skill for the firewall product itself (azure-firewall), VM hardening
(defender-for-cloud-hardening), or single-service networking (azure-key-vault).
| Estate shape | Topology | Notes |
|---|---|---|
| Single region, few subscriptions | Hub-spoke (single region) | Default for most |
| Multi-region with many spokes / branch sites | Virtual WAN | Microsoft-managed transit |
| Greenfield enterprise-scale | Azure Landing Zones (CAF) - VWAN or hub-spoke | Use CAF blueprints |
| Heavy on-prem + Azure | Hub-spoke + ExpressRoute / VPN gateway | Hub holds gateway + firewall |
| Small / single-workload | Single VNet, no hub | Don't over-engineer |
Rule of thumb: hub-spoke for most enterprises, Virtual WAN at multi-region branch scale. The hub holds shared services (firewall, gateway, DNS, Bastion); workloads sit in spokes. Don't put workloads in the hub.
Topology and address plan — Pick hub-spoke or Virtual WAN. Allocate non-overlapping RFC 1918 ranges per region / spoke; reserve gateway subnet, firewall subnet, Bastion subnet in the hub. Verify: address plan documented; no overlap with on-prem ranges; no overlap between regions.
Segmentation with NSGs and ASGs — NSG at subnet level (preferred over per-NIC). Group workloads with Application Security Groups (ASGs) instead of static IP lists - ASGs survive scale events. Microsegment by tier: web / app / data. Verify: NSG flow logs enabled to a Log Analytics workspace; default-deny rule present; ASGs used instead of IP-based source/dest for VM groups.
Private endpoints for PaaS — Use Private Endpoints / Private Link for sensitive
PaaS (Storage, SQL, Key Vault, Cosmos DB). Traffic stays on Microsoft backbone. Disable
public network access on the PaaS resource itself.
Verify: publicNetworkAccess = Disabled on the resource; private endpoint resolves to a
private IP via private DNS zone.
Centralise egress through Azure Firewall — UDR on spokes: 0.0.0.0/0 next hop =
firewall private IP. All outbound goes through the firewall for FQDN filtering and
logging.
Verify: effective routes on a spoke NIC show next-hop = firewall; no spoke has its own
public IP egress.
DDoS + WAF for public-facing — Enable Azure DDoS Network Protection on VNets with public IPs. Place public web apps behind Front Door or Application Gateway with WAF in Prevention mode. Verify: DDoS plan associated; WAF rules in Prevention (not Detection) for prod.
Centralised DNS — Private DNS zones linked from the hub; spokes auto-resolve PaaS private endpoints via the zones. Don't let each spoke run its own DNS.
Block management plane on the internet — No direct RDP / SSH from internet to VMs. Use Azure Bastion (in the hub) or Defender for Cloud just-in-time VM access. Verify: NSGs block 3389 / 22 from internet on all VM subnets; Bastion deployed in hub.
Design a hub-and-spoke network with segmentation and private endpoints for an Azure landing zone.How do I apply Zero Trust principles to an Azure virtual network?Plan NSG and ASG rules plus DDoS protection for a secure VNet.Control egress traffic and private connectivity across spokes.Replace internet-exposed RDP with Bastion and just-in-time VM access.Should I use hub-spoke or Virtual WAN for our multi-region estate?© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/azure-network-security-design of vinayaklatthe/microsoft-security-skills.
Open the folder on GitHubat commit 15f16df
Azure Network Security Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure Network Security Design this skillvinayaklatthe/microsoft-security-skills | 175 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Azure Key VaultKilo-Org/kilo-marketplace | 190 | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Azure Information ProtectionMicrosoftDocs/Agent-Skills | 776 | — | ~1.3k | Automated safety check: Pass | CC-BY-4.0 | |
| Implementing Cloud Security Posture Managementmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | |
| Azure Compliancemicrosoft/GitHub-Copilot-for-Azure | 255 | 2 repos | ~997 | Automated safety check: Pass | MIT | |
| Detecting Compromised Cloud Credentialsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 |
Kilo-Org/kilo-marketplace
Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.
MicrosoftDocs/Agent-Skills
Expert knowledge for Azure Information Protection development including best practices, decision making, configuration, and deployment.
mukul975/Anthropic-Cybersecurity-Skills
Continuously monitor multi-cloud environments (AWS, Azure, GCP) for misconfigurations, compliance violations, and security risks using Prowler, ScoutSuite, AWS Security Hub, Microsoft Defender for…
microsoft/GitHub-Copilot-for-Azure
Run Azure compliance and security audits with azqr plus Key Vault expiration checks.
mukul975/Anthropic-Cybersecurity-Skills
Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible-travel patterns, and credential-stuffing indicators using GuardDuty, Microsoft…
mukul975/Anthropic-Cybersecurity-Skills
Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage…
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
vinayaklatthe/microsoft-security-skills
Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…
vinayaklatthe/microsoft-security-skills
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).
vinayaklatthe/microsoft-security-skills
Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.
Categories
Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall…. Azure Network Security Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing secure Azure network architecture — hub-spoke topology (or Virtual WAN), segmentation with NSGs/ASGs, private endpoints / Private Link for PaaS, egress through Azure Firewall, DDoS protection, WAF on Front Door/App Gateway, and centralised private DNS.
Azure Network Security Design fits situations like: the firewall itself (use azure-firewall); VM-level hardening (use defender-for-cloud-hardening); key Vault networking only (use azure-key-vault).
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a claude-code`. Or copy the skill folder (skills/azure-network-security-design in vinayaklatthe/microsoft-security-skills) into .claude/skills/azure-network-security-design in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a codex`. Or copy the skill folder (skills/azure-network-security-design in vinayaklatthe/microsoft-security-skills) into .agents/skills/azure-network-security-design in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-network-security-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-network-security-design, .gemini/skills/azure-network-security-design, .github/skills/azure-network-security-design and .opencode/skills/azure-network-security-design in your project.
SKILL.md names no scripts, command-line tools or credentials: Azure Network Security Design is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azure Network Security Design is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Azure Network Security Design: Azure Key Vault (Kilo-Org/kilo-marketplace, 190 stars), Azure Information Protection (MicrosoftDocs/Agent-Skills, 776 stars), Implementing Cloud Security Posture Management (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Azure Compliance (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.
Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.