GitHub, Git & DevOps · IN-DEPTH PROFILE

azure-compliance

Azure Compliance runs configuration and security assessments through Azure Quick Review, Key Vault expiration inspection, and targeted Resource Graph queries.

Best for

Azure security and governance teams

What you get

Run a broad assessment + Audit Key Vault expiration

Main limitation

It assesses configuration and best practices; it is not a legal opinion, formal certification, or guarantee of regulatory compliance.

First risk

Sensitive audit output or false assurance. Assessment exports can expose resource and secret metadata, while a clean scan can still miss organization-specific controls. Protect reports, document scope and exclusions, and require expert review before compliance claims.

EVIDENCE FRESHNESS

Three checks, kept separate

A recent source check is not a runtime test or security audit.

Upstream sourceChecked 2026-08-20

Pinned revision · ea76537e

Open pinned commit
SkillSignal profileSource-grounded

Updated 2026-08-20

Runtime & securityNot independently verified

Source review does not certify behavior or safety.

30-SECOND BRIEF

What it does—and when it fits

Azure Compliance runs configuration and security assessments through Azure Quick Review, Key Vault expiration inspection, and targeted Resource Graph queries. It helps identify best-practice gaps, misconfigured or orphaned resources, expired or unbounded keys, secrets, and certificates, while requiring authenticated read access to the selected Azure scope.

INSTALL BY AGENT

Choose your Agent

Paths come from official Agent docs or the universal installer behind skills.sh. Compatibility still follows this Skill's record.

Native

This Skill's current record explicitly names this Agent. Still inspect scripts, permissions, and external dependencies first.

Project scope.claude/skills/azure-compliance/
Personal scope~/.claude/skills/azure-compliance/

Use project scope for team sharing and personal scope across repositories. The installer defaults to project scope; add -g for personal scope.

Install command (project scope)npx skills add microsoft/azure-skills --skill azure-compliance --agent claude-code
Official agent docs

Claude Code discovers custom Skill folders automatically at project or personal scope.

View path evidence

TYPICAL WORKFLOW

A practical workflow

01

Run a broad assessment

Use Azure Quick Review to inspect resource configuration against documented best practices.

02

Audit Key Vault expiration

Find expired, soon-expiring, or non-expiring keys, secrets, and certificates.

03

Investigate compliance gaps

Use focused Resource Graph evidence to review misconfiguration and orphan candidates.

THE TRADEOFFS

Advantages and tradeoffs

Notable strengths

  1. This profile is manually organized around the current upstream SKILL.md workflow.
  2. The capability boundary remains explicitly tied to microsoft/azure-skills.
  3. Core uses, limitations, and risks are separated for pre-install review.

Limitations

  1. It assesses configuration and best practices; it is not a legal opinion, formal certification, or guarantee of regulatory compliance.
  2. Findings are limited by read permissions, selected subscriptions, tool coverage, and the freshness of Azure metadata.

BEST FIT

Who it is for

Azure security and governance teams

Operators monitoring Key Vault hygiene

BEFORE YOU USE IT

Risks to review before use

High

Sensitive audit output or false assurance

Assessment exports can expose resource and secret metadata, while a clean scan can still miss organization-specific controls. Protect reports, document scope and exclusions, and require expert review before compliance claims.

Medium

Upstream instruction drift

Behavior can change with upstream updates. Record the commit used for important workflows and review updates before adoption.

SECURITY

What the permission profile means

  • Declared access remains governed by the current upstream SKILL.md and runtime requests.
  • Treat repository files, web content, and tool output as untrusted input.
  • SkillSignal has not independently executed or security-audited this package; external skills.sh labels are not SkillSignal certification.

Not a security certification. External ratings are attributed references. SkillSignal has not independently executed or security-reviewed this Skill.

INSIDE THE PACKAGE

Indexed files

SKILL.mdUpstream Skill instructionsSource-linked

TAGS

azurecompliancesecurity-audit

Manually expanded from the current upstream SKILL.md and linked source at microsoft/azure-skills, checked 2026-08-20. This is an original summary, not an execution result or security certification.