AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Azure Resource Diagnostics

skill-aiappsgbb-awesome-gbb-azure-resource-diagnostics · by aiappsgbb

>

No reviews yet
0 installs
16 views
0.0% view→install

Install

$ agentstack add skill-aiappsgbb-awesome-gbb-azure-resource-diagnostics

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-aiappsgbb-awesome-gbb-azure-resource-diagnostics)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Azure Resource Diagnostics? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

azure-resource-diagnostics

Audits Azure diagnostic-settings coverage at a resource group scope.

When to use

  • threadlight v0.5.x needs to flip OBS-106 from kind: manual to

kind: sibling-skill — this skill's probe() is the sibling.

  • Pre-pilot review: confirm a candidate Foundry RG routes its resource

logs somewhere (Log Analytics / Event Hubs / Storage) before a customer pilot.

  • Spoke landing-zone check: detect resources that have no diagnostic

settings configured at all.

Probing an RG

from azure_resource_diagnostics.probe import probe

result = probe(
    subscription_id="",
    resource_group="",
    # target_resource_types=["storage_account", "key_vault"],  # optional OBS-106 filter
)
# result["resources"]                          → list of {id, name, type, configured, destinations, setting_count}
# result["summary"]["total_resources"]         → int (after type filter)
# result["summary"]["configured_count"]        → int (≥1 destination set)
# result["summary"]["unconfigured_count"]      → int (no destination)
# result["summary"]["target_resource_types_filter"] → list[str] | None (echo of applied filter)
# result["summary"]["confidence"]              → 0.0..1.0
# result["summary"]["probe_error"]             → str | None
# result["findings"]                           → list of no-diagnostic-settings findings
# result["manifest_path"]                      → path to JSON manifest on disk

target_resource_types (the OBS-106 sibling-contract input) is an optional list of resource-type tokens. Matching is robust: each token is normalized (lowercased, non-alphanumerics stripped) and matched as a substring of the normalized ARM type, so both raw ARM types (Microsoft.Storage/storageAccounts) and snake_case logical kinds (storage_account) select the same resources. When omitted (default), every resource in the RG is probed. The applied filter is echoed back in summary.target_resource_types_filter.

The probe never raises. If the RG resource listing is denied (RBAC missing), the probe still returns a shape with probe_error populated and confidence: 0.0. Resource types that don't support diagnostic settings (Monitor returns 404) are treated as having no destinations, not as a denial.

> MUST: Copy verbatim from > [references/python/probe.py](references/python/probe.py). > Do NOT redefine inline — the validator enforces single-source-of-truth.

"Any destination counts" (decision)

Per spec §4.4 Q-D2 (locked decision), a resource is configured if it has any diagnostic setting routing to any destination:

| Destination | Setting attribute | Meaning | |-------------|-------------------|---------| | Log Analytics | workspace_id | Logs → LAW workspace | | Event Hubs | event_hub_authorization_rule_id | Logs → Event Hubs | | Storage | storage_account_id | Logs → Storage account |

A diagnostic setting that exists but routes nowhere counts as unconfigured. Each unconfigured resource produces a no-diagnostic-settings finding.

CLI

python -m azure_resource_diagnostics --sub  --rg 
# optional OBS-106 type filter (ARM types or logical kinds):
python -m azure_resource_diagnostics --sub  --rg  --target-resource-types storage_account key_vault

Outputs JSON to stdout AND writes the same content to out/.json. Override via AZURE_RESOURCE_DIAGNOSTICS_OUT=.

Auth

Uses DefaultAzureCredential. Caller needs at minimum Monitoring Reader at the RG scope (built-in role) plus Reader to list resources. Without it, the probe returns a shape with probe_error populated rather than raising.

See also

  • azure-backup-readiness — peer skill for backup-coverage audit.
  • azure-monitor-alert-baseline — peer skill for alert coverage audit.
  • foundry-rbac-audit — peer skill for RBAC posture audit.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.