azure-aigateway
Configure an Azure AI Gateway
AI teams need consistent controls for models, tools, and agents. This skill guides Azure API Management configuration for security, cost control, routing, and diagnostics.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "azure-aigateway" from https://skillstore.io/skills/microsoft-azure-aigateway.md and its manifest at https://skillstore.io/api/skills/microsoft-azure-aigateway/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "azure-aigateway". Configure cost controls for a shared Azure OpenAI gateway.
Expected outcome:
- Recommended controls: per-subscription token limits, semantic caching for non-streaming requests, and token metrics for chargeback.
- Authentication: managed identity with Cognitive Services User scoped to each backend resource.
- Validation: test quota responses, cache behavior, metric dimensions, and backend authorization before production.
Using "azure-aigateway". Troubleshoot repeated 401 responses from an Azure OpenAI backend.
Expected outcome:
The review checks APIM managed identity status, scoped RBAC assignments, the Cognitive Services token audience, propagation delays, and backend identifiers.
Security Audit
High RiskThe audit reviewed 80 static findings; 79 are documentation-related false positives. One finding is confirmed because an example imports an OpenAPI specification from a mutable branch. Semantic review also found caller-controlled rate-limit keys and commands that expose subscription keys.
Confirmed security concerns (2)
Capability review items (1)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (21)
๐ Env variables (14)
๐ Network access (21)
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/microsoft-azure-aigateway/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/microsoft-azure-aigateway?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/microsoft-azure-aigateway?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/microsoft-azure-aigateway/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/microsoft-azure-aigateway.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
microsoft. (2026). azure-aigateway security audit report (audit version 6) [Author version 0.0.0-placeholder]. Skillstore. https://skillstore.io/skills/microsoft-azure-aigateway/audits/6BibTeX citation
@techreport{microsoft-microsoft-azure-aigateway-2026,
author = {microsoft},
title = {azure-aigateway security audit report (audit version 6)},
institution = {Skillstore},
year = {2026},
number = {6},
url = {https://skillstore.io/skills/microsoft-azure-aigateway/audits/6},
note = {Author version 0.0.0-placeholder}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "azure-aigateway security audit report (audit version 6)"
version: "0.0.0-placeholder"
type: report
authors:
- name: "microsoft"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/microsoft-azure-aigateway/audits/6"
identifiers:
- type: other
value: "skillstore:microsoft-azure-aigateway:audit:6"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Govern Shared Model Access
Create centralized APIM controls for token budgets, caching, routing, and metrics across multiple AI applications.
Protect Agent Tools
Add authentication, content safety, and authenticated rate limits to APIs exposed as MCP tools.
Review Gateway Controls
Evaluate managed identity, RBAC, tenant isolation, content filtering, and operational diagnostics before production rollout.
Try These Prompts
Inspect APIM instance <name> in resource group <group>. Summarize AI backends and missing prerequisites without changing resources.
Prepare commands and policies to add Azure OpenAI resource <resource> to APIM <name>. Use managed identity and least-privilege RBAC.
Design an inbound APIM policy for <workload> with token limits, semantic caching, content safety, rate limiting, and token metrics. Explain policy order.
Design a multi-region, multi-tenant AI gateway for <requirements>. Include authenticated tenant keys, backend failover, cost controls, observability, and a verification plan.
Best Practices
- Use managed identities and narrow Azure RBAC scopes for all production backends.
- Validate resource names, subscriptions, regions, and policy availability before running commands.
- Use authenticated identities for rate-limit keys and keep credentials out of prompts, logs, and command output.
Avoid
- Do not use DefaultAzureCredential in production Azure workloads.
- Do not import mutable remote specifications without pinning and reviewing their contents.
- Do not trust caller-supplied headers for tenant isolation or rate limiting.
Frequently Asked Questions
Does this skill deploy Azure API Management?
Which AI backends are covered?
Does it support MCP tools?
Can these examples be used in production?
How does the skill authenticate to Azure services?
Which assistant tools are supported?
Developer Details
Author
microsoftLicense
MIT
Author version
v0.0.0-placeholder
Skillstore revision
r2
Repository
https://github.com/microsoft/github-copilot-for-azure/tree/main/plugin/skills/azure-aigateway/Ref
ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006
Maintenance freshness
7/25/2026
Usage
7 downloads ยท 143 views
File structure
๐ references/
๐ patterns.md
๐ policies.md
๐ sdk/
๐ azure-ai-contentsafety-py.md
๐ azure-ai-contentsafety-ts.md
๐ azure-mgmt-apimanagement-dotnet.md
๐ azure-mgmt-apimanagement-py.md
๐ troubleshooting.md
๐ SKILL.md
๐ version.json