AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Azure Backup Readiness

skill-aiappsgbb-awesome-gbb-azure-backup-readiness · by aiappsgbb

>

No reviews yet
0 installs
16 views
0.0% view→install

Install

$ agentstack add skill-aiappsgbb-awesome-gbb-azure-backup-readiness

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-aiappsgbb-awesome-gbb-azure-backup-readiness)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Azure Backup Readiness? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

azure-backup-readiness

Audits Azure backup coverage at a resource group scope. Vault-type aware.

When to use

  • threadlight v0.5.4 needs to flip BAK-401 from kind: manual to

kind: sibling-skill — this skill's probe() is the sibling.

  • Pre-pilot review: confirm a candidate Foundry RG has at least one

vault with protected items before a customer pilot.

  • Spoke landing-zone check: detect RGs that have an RSV / Backup Vault

resource but no policies attached.

Probing an RG

from azure_backup_readiness.probe import probe

result = probe(
    subscription_id="",
    resource_group="",
    # protected_item_types=["VM", "SQLDataBase"],  # optional REL-007 filter
)
# result["vaults"]                         → list of {kind, name, id, protected_item_count}
# result["summary"]["total_vaults"]        → int
# result["summary"]["rsv_count"]           → int  (RSV count)
# result["summary"]["bv_count"]            → int  (BackupVault count)
# result["summary"]["total_protected_items"] → int  (sum across vaults, after type filter)
# result["summary"]["protected_item_types_filter"] → list[str] | None (echo of applied filter)
# result["summary"]["confidence"]          → 0.0..1.0
# result["summary"]["probe_error"]         → str | None
# result["findings"]                       → list of typed findings
# result["manifest_path"]                  → path to JSON manifest on disk

protected_item_types (the REL-007 sibling-contract input) is an optional list of workload/datasource type tokens. When provided, only protected items whose type matches one of the tokens (case-insensitive substring) count toward total_protected_items / per-vault protected_item_count. When omitted (default), every protected item counts. The applied filter is echoed back in summary.protected_item_types_filter.

The probe never raises. If one vault API denies (e.g. RSV is forbidden but Backup Vault works), the probe still completes and returns confidence: 0.5. If both deny, returns confidence: 0.0 and probe_error populated.

> MUST: Copy verbatim from > [references/python/probe.py](references/python/probe.py). > Do NOT redefine inline — the validator enforces single-source-of-truth.

Vault-type awareness (decision)

Per spec §4.4 Q-D1 (locked decision), this skill probes both Recovery Services Vaults and Backup Vaults. These are two distinct Azure backup surfaces:

| Vault kind | SDK | When to use | |------------|-----|-------------| | Recovery Services Vault | azure-mgmt-recoveryservices | Classic VM / SQL / file backup | | Backup Vault (DataProtection) | azure-mgmt-dataprotection | Modern Blob / Disk / PostgreSQL backup |

A Foundry RG may have neither, one, or both. The probe doesn't prefer either — both are reported in result["vaults"] with their kind field set accordingly.

CLI

python -m azure_backup_readiness --sub  --rg 
# optional REL-007 type filter:
python -m azure_backup_readiness --sub  --rg  --protected-item-types VM SQLDataBase

Outputs JSON to stdout AND writes the same content to out/.json. Override via AZURE_BACKUP_READINESS_OUT=.

Auth

Uses DefaultAzureCredential. Caller needs at minimum Backup Reader at the RG scope (built-in role). Without it, the probe returns a shape with probe_error populated rather than raising.

See also

  • azure-resource-diagnostics — peer skill for diagnostic settings audit.
  • foundry-rbac-audit — peer skill for RBAC posture audit.
  • azure-monitor-alert-baseline — peer skill for alert coverage audit.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.