Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/agenticpawan/fullstack-pilot/azure-keyvault-appconfignpx skills add AgenticPawan/FullStack-Pilot --skill azure-keyvault-appconfiggit clone --depth 1 https://github.com/AgenticPawan/FullStack-PilotWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/agenticpawan/fullstack-pilot/azure-keyvault-appconfig)<a href="https://agentmods.dev/skills/agenticpawan/fullstack-pilot/azure-keyvault-appconfig"><img src="https://agentmods.dev/badge/skills/agenticpawan/fullstack-pilot/azure-keyvault-appconfig.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00094 | $0.01762 |
| Opus 5 | $0.00047 | $0.00881 |
| Sonnet 5 | $0.00019 | $0.00352 |
| Haiku 4.5 | $0.00009 | $0.00176 |
Grade A, and why
azure-keyvault-appconfig scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 175 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Standard IDs
| ID | Severity | What it checks |
|---|---|---|
| KVA-001 | P0 | Secret value defined inline (Bicep param/App Setting) instead of a Key Vault reference |
| KVA-002 | P0 | App Configuration / Key Vault accessed by connection string or access key, not managed identity |
| KVA-003 | P1 | Key Vault missing enableSoftDelete + enablePurgeProtection |
| KVA-004 | P1 | Feature flags stored in App Settings/env instead of the App Configuration flag store |
| KVA-005 | P1 | Key Vault / App Configuration publicNetworkAccess enabled with no private endpoint |
dotnet-secrets-rotation, dotnet-dynamic-configuration, and dotnet-feature-flags govern
how the application reads secrets, refreshes config, and evaluates flags — all of which
assume a backing store exists and is reachable by identity. This skill governs the Azure
resources that provide it: Key Vault and App Configuration, provisioned in Bicep, accessed by
managed identity (never a key), so the consumer-side skills have something safe to consume.
Complements azure-security-baseline ASB-IM-2 (Key Vault for secrets) with the concrete
Bicep wiring.
Check A — No inline secrets; use Key Vault references (KVA-001)
Detection
Scan Bicep and app-settings for secret-looking values assigned literally — a connection
string with a password, an API key, a client secret — where the value should be a Key Vault
reference resolved at runtime by identity. A secret in a Bicep param or an App Service
appSettings entry lands in deployment history and the portal in cleartext.
BAD — client secret handed to the app as a literal setting
resource site 'Microsoft.Web/sites@2023-12-01' = {
properties: {
siteConfig: {
appSettings: [
{ name: 'Db__Password', value: dbPassword } // KVA-001: literal secret in config
]
}
}
}
GOOD — App Setting is a Key Vault reference, resolved by the site's managed identity
appSettings: [
{
name: 'Db__Password'
value: '@Microsoft.KeyVault(SecretUri=${kv.properties.vaultUri}secrets/db-password/)'
}
]
// The app's system-assigned identity has 'Key Vault Secrets User' on the vault (Check B).
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 5d ago First seen · 175 lines · 94 tokens per session scan A d2dbe3c6b811
azure-keyvault-appconfig is a skill published in the GitHub repository AgenticPawan/FullStack-Pilot (2 stars, last pushed 1mo ago), licensed MIT. It adds 94 tokens to every session and 1,762 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
azure-mgmt-applicationinsights-dotnet
Azure Application Insights SDK for .NET. Application performance monitoring and observability resource management. Use for creating Application Insights components, web tests, workbooks, analytics items, and API keys. Triggers: "Application Insights", "ApplicationInsights", "App Insights", "APM", "application…
azure-resource-manager-durabletask-dotnet
Azure Resource Manager SDK for Durable Task Scheduler in .NET. Use for MANAGEMENT PLANE operations: creating/managing Durable Task Schedulers, Task Hubs, and retention policies via Azure Resource Manager. Triggers: "Durable Task Scheduler", "create scheduler", "task hub", "DurableTaskSchedulerResource", "provision…
azure-resource-manager-mysql-dotnet
Azure MySQL Flexible Server SDK for .NET. Database management for MySQL Flexible Server deployments. Use for creating servers, databases, firewall rules, configurations, backups, and high availability. Triggers: "MySQL", "MySqlFlexibleServer", "MySQL Flexible Server", "Azure Database for MySQL", "MySQL database…
azure-eventhub-dotnet
Azure Event Hubs SDK for .NET. Use for high-throughput event streaming: sending events (EventHubProducerClient, EventHubBufferedProducerClient), receiving events (EventProcessorClient with checkpointing), partition management, and real-time data ingestion. Triggers: "Event Hubs", "event streaming"…
azure-mgmt-botservice-dotnet
Azure Resource Manager SDK for Bot Service in .NET. Management plane operations for creating and managing Azure Bot resources, channels (Teams, DirectLine, Slack), and connection settings. Triggers: "Bot Service", "BotResource", "Azure Bot", "DirectLine channel", "Teams channel", "bot management .NET", "create bot".
azure-mgmt-fabric-dotnet
Azure Resource Manager SDK for Fabric in .NET. Use for MANAGEMENT PLANE operations: provisioning, scaling, suspending/resuming Microsoft Fabric capacities, checking name availability, and listing SKUs via Azure Resource Manager. Triggers: "Fabric capacity", "create capacity", "suspend capacity", "resume capacity"…