Skip to main content

keyvault-secret-reader

Read a named secret from Azure Key Vault using the caller's (agent's) managed identity, without ever placing the secret value in a prompt or tool argument. Use when an agent needs a credential, API key, connection string, or `sig` held in Key Vault — including from inside a managed harness or sandbox where DefaultAzureCredential resolves to the agent identity. Requires the identity to hold the 'Key Vault Secrets User' role on the vault.

Jump to install

Source facts

Repository
microsoft-foundry/foundry-samples
Last source activity
July 27, 2026 at 07:18
Detected SKILL.md language
English
Stars
431
Forks
472

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.