Azure Key Vault
Kilo-Org/kilo-marketplace
Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.
Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills pki-design --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/pki-design .claude/skills/pki-design && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pki-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/pki-design into .claude/skills/pki-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pki-design", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/pki-designType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills pki-design --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/pki-design .agents/skills/pki-design && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pki-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/pki-design into .agents/skills/pki-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pki-design", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills pki-design --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/pki-design .cursor/skills/pki-design && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pki-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/pki-design into .cursor/skills/pki-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pki-design", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/vinayaklatthe/microsoft-security-skills.git --path skills/pki-design--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills pki-design --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/pki-design .gemini/skills/pki-design && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pki-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/pki-design into .gemini/skills/pki-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pki-design", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install vinayaklatthe/microsoft-security-skills pki-designInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/pki-design .github/skills/pki-design && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pki-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/pki-design into .github/skills/pki-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pki-design", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install vinayaklatthe/microsoft-security-skills pki-design --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/pki-design .opencode/skills/pki-design && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pki-design" agent skill from https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills/pki-design into .opencode/skills/pki-design/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pki-design", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pki-designGuidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.
Pki Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. Covers CA strategy (offline root + issuing CAs, AD CS vs managed/third-party vs public CA), Azure Key Vault certificates, HSM key protection, Entra certificate-based authentication (CBA), certificate lifecycle (issuance, renewal, rotation, revocation), and Intune SCEP/PKCS distribution. WHEN: PKI design, certificate authority, root CA offline, issuing CA, certificate management, Key Vault…
Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Security, covering Cryptography, Secrets management and App store release. It works with Microsoft Entra ID, Azure Key Vault and Microsoft Azure. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pki Design loads about 2.1k tokens when it runs. Until then it costs about 211 tokens; SKILL.md has 936 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 936 words, ~2,086 tokens.
.claude/skills/pki-design/SKILL.md (or your agent's skills folder).Public Key Infrastructure (PKI) issues and manages the digital certificates that underpin authentication, encryption, and signing. In Azure-centric and hybrid environments this means combining a trusted CA hierarchy, Key Vault storage, automated lifecycle, and certificate-based authentication.
Designing certificate issuance, distribution, and lifecycle for: Entra phishing-resistant CBA, TLS / mTLS for services, device identity (Wi-Fi 802.1x, VPN), code signing, and S/MIME. Use this skill when the question is "where do certificates come from and how do they renew", not "how do I store one secret".
Do not use this skill for Key Vault secrets/keys (azure-key-vault) or Entra ID model
(entra-id).
| If the use case is... | CA choice | Notes |
|---|---|---|
| Internet-facing TLS (websites, APIs) | Public CA (DigiCert, GlobalSign, Let's Encrypt) | Always; private CAs aren't trusted by browsers |
| Internal app TLS, mTLS, service-to-service | Internal issuing CA (AD CS or managed) | Private CA chain trusted internally |
| Entra certificate-based authentication | Internal CA published to Entra trust store | Pair with strong binding policy |
| Device identity (Wi-Fi 802.1x, VPN) | AD CS or third-party PKI + Intune SCEP/PKCS | Auto-enrollment essential |
| Code signing | EV code signing cert from a public CA | Hardware token; protect aggressively |
| S/MIME email signing/encryption | Third-party public CA (DigiCert, Sectigo) | Internal CAs not trusted by external recipients |
| Short-lived workload certs (Kubernetes) | cert-manager with ACME or internal issuer | Minutes-to-hours TTL |
Rule of thumb: never use a private CA for internet-facing services and never use a public CA for internal certificates at scale (cost + agility). Two distinct chains.
Design the CA hierarchy — Offline root CA + one or more online issuing CAs. Root signs issuing CA certs (long validity, e.g. 10-20 years), issuing CAs sign end-entity certs (1-2 year validity). Verify: root CA host is powered off or air-gapped except for CRL signing and issuing CA renewal.
Protect the keys with HSM — Root CA private key in an HSM (FIPS 140-2 Level 2+).
Azure Managed HSM for cloud-native; on-prem HSM for AD CS. Never an unprotected
filesystem.
Verify: certutil -getreg ca\CSP\Provider shows the HSM provider, not "Microsoft Software
Key Storage Provider".
Storage and lifecycle in Key Vault — Use Azure Key Vault certificates for all
service certificates. Integrate with supported issuer CAs (DigiCert, GlobalSign, internal
via Key Vault Acmebot or partner connector) for automatic renewal.
Verify: cert objects have lifetime_actions configured for auto-renewal at 75% of
lifetime; manual touch required only for new issuance.
Auto-enrollment for device and user certs — AD CS auto-enrollment via GPO for domain members; Intune SCEP or PKCS connector for cloud-managed devices. Never email a PFX file. Verify: Intune cert profile reports > 95% deployment success; user/device cert visible in personal store.
Plan revocation — CRL (Certificate Revocation List) published to HTTP endpoint; OCSP responder for real-time. Both must be highly available - if CRL is unreachable, modern clients fail closed for high-assurance certs. Use a CDN for the CRL HTTP endpoint. Verify: CRL endpoint reachable from public internet (if external certs) and from all internal clients; OCSP responder uptime > 99.9%.
Monitor expiry — Key Vault sends events for upcoming expiry. Stream to a dashboard.
For AD CS, use a script (certutil -view) on a schedule. Track 90/60/30/7 days out.
Verify: no cert in production expires unmonitored; alerts fire 60 days before expiry.
Rotation discipline — Plan rotation before issuance, not when expiry approaches. Service teams own renewal automation; PKI team owns CA + alerting infrastructure.
Design a PKI hierarchy with offline root + two issuing CAs and HSM key protection.Issue and auto-rotate certificates from Azure Key Vault for our App Service workloads.Set up Entra certificate-based authentication with our internal CA and strong binding.Plan SCEP/PKCS certificate deployment via Intune for Wi-Fi 802.1x.Configure CRL and OCSP for our internal CA with a CDN-backed CRL endpoint.Monitor and auto-alert on certificate expiry across Key Vault and AD CS.© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/pki-design of vinayaklatthe/microsoft-security-skills.
Open the folder on GitHubat commit 15f16df
Pki Design next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pki Design this skillvinayaklatthe/microsoft-security-skills | 175 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Azure Key VaultKilo-Org/kilo-marketplace | 190 | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Azure Keyvault Pymicrosoft/skills | 3.1k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Azure Compliancemicrosoft/GitHub-Copilot-for-Azure | 255 | 2 repos | ~997 | Automated safety check: Pass | MIT | |
| Entra App Registrationmicrosoft/GitHub-Copilot-for-Azure | 255 | 2 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Apex Azure Compliancejonathan-vella/apex | 217 | — | ~1.6k | Automated safety check: Pass | MIT |
Kilo-Org/kilo-marketplace
Guidance for Azure Key Vault — securely storing and managing secrets, keys, and certificates with RBAC, network isolation, managed identity access, soft delete / purge protection, and rotation.
microsoft/skills
Azure Key Vault SDK for Python. An agent skill from microsoft/skills.
microsoft/GitHub-Copilot-for-Azure
Run Azure compliance and security audits with azqr plus Key Vault expiration checks.
microsoft/GitHub-Copilot-for-Azure
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.
jonathan-vella/apex
ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation.
bitwarden/ai-plugins
Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
vinayaklatthe/microsoft-security-skills
Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…
vinayaklatthe/microsoft-security-skills
Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
vinayaklatthe/microsoft-security-skills
Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).
vinayaklatthe/microsoft-security-skills
Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.
Categories
Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments. Pki Design is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for designing public key infrastructure (PKI) and certificate management on Azure and hybrid environments.
Pki Design fits situations like: entra ID identity model (use entra-id); key Vault secrets/keys only (use azure-key-vault).
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a claude-code`. Or copy the skill folder (skills/pki-design in vinayaklatthe/microsoft-security-skills) into .claude/skills/pki-design in your project. Claude Code loads it when a task matches its description.
Run `npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a codex`. Or copy the skill folder (skills/pki-design in vinayaklatthe/microsoft-security-skills) into .agents/skills/pki-design in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill pki-design -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pki-design, .gemini/skills/pki-design, .github/skills/pki-design and .opencode/skills/pki-design in your project.
SKILL.md names no scripts, command-line tools or credentials: Pki Design is instructions for the agent only.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Pki Design is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.1k tokens (SKILL.md is roughly 8.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pki Design: Azure Key Vault (Kilo-Org/kilo-marketplace, 190 stars), Azure Keyvault Py (microsoft/skills, 3.1k stars), Azure Compliance (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Entra App Registration (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.
Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.