skills/microsoft/skills/azure-cost/Gen Agent Trust Hub

azure-cost

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [Azure Service Management]: The skill leverages the official Azure CLI and az rest commands to interface with the Cost Management APIs. While it contains logic for resource modification—such as rightsizing or deleting orphaned resources—these actions are fundamental to the skill's optimization purpose and include clear instructions to seek user approval before execution.
  • [Security-First Authentication]: It includes a dedicated guide on authentication best practices, correctly advising the use of Managed Identities and Azure RBAC over secrets or hardcoded credentials, which aligns with production security standards.
  • [Trusted Tool Integration]: The workflow integrates with established tools like azqr (Azure Quick Review) and kubectl to perform resource compliance scans and Kubernetes analysis. These are recognized utilities in the Azure and cloud-native landscape.
  • [Official Data Sourcing]: The skill retrieves current pricing and best practice guidelines from verified Microsoft domains (azure.microsoft.com, learn.microsoft.com) to ensure that optimization recommendations are based on authoritative information.
  • [Dynamic Intent Resolution]: By using the azure__extension_cli_generate MCP tool, the skill dynamically constructs CLI commands based on user requests, ensuring that generated operations are syntactically correct and aligned with the user's intended task.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 04:31 PM
Security Audit — agent-trust-hub — azure-cost