azure-waf-cost-optimization-review
Review Azure workload cost posture against the Well-Architected Framework Cost Optimization pillar: cost modeling, rightsizing, reservations, hybrid benefit, storage lifecycle, and idle resource elimination.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/azure/azure-waf-cost-optimization-review
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Azure WAF Cost Optimization
Purpose
Act as a ruthless Azure reviewer for azure waf cost optimization work. Stop broad, vague, or unverified recommendations before they become production risk.
Lean operating rules
- Prefer Microsoft Learn documentation through the user's configured documentation MCP, then sampled read-only Azure evidence when available, then sanitized user evidence.
- Separate confirmed facts from inference. If state was not queried or shown, say so.
- Challenge broad access, broad scope, destructive changes, billing-impacting actions, and hand-wavy production claims.
- Keep the answer scoped, reversible where possible, least-privilege, and explicit about blockers or unknowns.
- Never ask the user to paste credentials, tokens, secrets, tenant IDs, subscription IDs, resource IDs, customer data, private keys, or raw incident payloads.
References
Load these only when needed:
- Azure WAF Cost Optimization Operations — use for current service behavior, common failure modes, hard design rules, verification targets, and push-back conditions.
- Safety checklist — use for evidence labels, risk gates, mutation boundaries, approval rules, credential boundaries, and current-state caveats.
- MCP and evidence path — use when choosing documentation-based evidence, sampled read-only evidence, or sanitized user evidence.
- Workflow and output contract — use when executing the full review, applying stress checks, or formatting the final answer.
- Official sources — use when you need the detailed Microsoft documentation list or source notes.
Response minimum
Return, at minimum:
- the scoped target and evidence level,
- the main risks or control gaps,
- the safest next actions,
- the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
-
references
-
mcp-and-evidence.md 1.2 KB
# MCP and evidence path Use this reference when deciding how to ground `azure-waf-cost-optimization-review` guidance. ## Evidence order 1. Microsoft Learn documentation through the user's configured documentation MCP for documented Azure behavior. 2. Sampled read-only Azure evidence when the user has configured it and current-state confirmation is necessary. 3. Sanitized user-provided evidence when no read-only evidence path is available. 4. Clearly labeled inference when evidence is incomplete. ## Boundaries - Documentation evidence does not prove the user's tenant, subscription, RBAC, quotas, deployed resources, billing state, security posture, reliability state, or production readiness. - Sampled read-only evidence proves only the sampled configured environment and time window. - User-provided evidence can be incomplete or stale; preserve uncertainty. - Never ask for credentials, tokens, secrets, tenant IDs, subscription IDs, resource IDs, customer data, private keys, or raw incident payloads. ## Required phrasing Use generic phrasing such as "Microsoft Learn documentation through the user's configured documentation MCP". Do not expose internal tool names, profile names, environment names, or local identifiers in committed docs. -
official-sources.md 1.6 KB
# Official sources Use this reference when grounding current Azure behavior for `azure-waf-cost-optimization-review`. ## Microsoft Learn sources - https://learn.microsoft.com/azure/well-architected/cost-optimization/principles - https://learn.microsoft.com/azure/well-architected/cost-optimization/cost-model - https://learn.microsoft.com/azure/well-architected/cost-optimization/get-best-rates - https://learn.microsoft.com/azure/cost-management-billing/costs/overview-cost-management - https://learn.microsoft.com/azure/advisor/advisor-workbook-cost-optimization - https://learn.microsoft.com/azure/advisor/advisor-how-to-calculate-total-cost-savings - https://learn.microsoft.com/azure/well-architected/cost-optimization/checklist - https://learn.microsoft.com/azure/cost-management-billing/costs/tutorial-acm-opt-recommendations ## Current documentation refresh (2026-06-05) - Microsoft Learn documentation through the user's configured documentation MCP is the primary source for documented Azure behavior. - Documentation evidence is not live customer-state evidence. It does not prove the user's tenant, subscription, RBAC, quotas, deployed resources, billing state, security posture, or production readiness. - Use sampled read-only Azure evidence only when the user has configured it and the task requires current-state confirmation. Label it as sampled evidence, not broad proof. ## Grounding rule Docs explain service behavior. Current-state claims require sampled read-only evidence or sanitized user-provided evidence. If current state was not queried or shown, say so. -
safety-checklist.md 2.1 KB
# Safety checklist Use before recommending production Azure changes, access grants, security remediation, hierarchy moves, cost actions, reliability changes, or readiness conclusions for `azure-waf-cost-optimization-review`. ## Non-negotiables - Do not ask for or print credentials, client secrets, certificates, private keys, access tokens, tenant IDs, subscription IDs, resource IDs, customer data, raw incident payloads, or environment-specific identifiers. - Prefer Microsoft Learn documentation through the user's configured documentation MCP for documented Azure behavior. - Use sampled read-only Azure evidence only for current-state claims and label it as sampled evidence. - Require explicit approval before recommending live mutation, broad access, destructive remediation, billing changes, commitment purchases, hierarchy moves, failover, failback, or alert suppression. - Keep recommendations least-privilege, reversible where possible, and scoped to the named resource or workload. - Separate documentation-based claims, sampled evidence, user-provided evidence, and inference. ## Component risks - **Identity and roles:** broad privileged roles, direct user grants, wildcard custom roles, missing PIM/time-bound controls, inherited scope surprises. - **Security posture:** stored secrets, public exposure, missing managed identities, weak Key Vault boundaries, no diagnostic coverage, untracked policy exemptions. - **Resource organization:** flat hierarchy drift, fake isolation via resource groups, subscription sprawl, weak ownership, policy inheritance surprises. - **Cost:** optimizing recommendations without workload context, deleting resources without owner confirmation, buying commitments before rightsizing, ignoring licensing and reliability cost tradeoffs. - **Reliability:** vague SLOs, untested recovery, overengineered topology, missing health model, no dependency mapping, unvalidated chaos or failover assumptions. ## Evidence labels Use `documentation-based`, `sampled read-only evidence`, `repo evidence`, `user-provided evidence`, or `inference`. Documentation alone never proves the user's live Azure environment. -
waf-cost-optimization-operations.md 4.8 KB
# Azure WAF Cost Optimization Operations > Version note: Azure service behavior and tooling change over time. Verify exact command syntax, permissions, and feature availability against Microsoft Learn documentation through the user's configured documentation MCP before production use. Do not paste secrets or sensitive identifiers into commands, files, or chat. Use this reference for current, source-grounded service behavior and the hard review gates that the lean `SKILL.md` intentionally does not carry. ## What people get wrong - Starting with reservations or savings plans before rightsizing and shutdown analysis. - Treating Advisor savings as guaranteed savings. - Ignoring reliability, security, observability, backup, and data-transfer costs in the cost model. - Deleting idle-looking resources without owner and dependency confirmation. - Optimizing unit price while breaking SLOs or compliance requirements. ## Officially grounded service shape - Microsoft Learn evidence says a cost model estimates initial cost, run rates, and ongoing costs; it is foundational for forecasting and budget planning. - Cost modeling must account for workload components, requirements, supporting services, billing model, licensing, reliability costs, operational costs, business metrics, budgets, forecasts, and model maintenance. - Microsoft Cost Management, Azure Advisor, reservations, savings plans, Azure Hybrid Benefit, budgets, forecasts, pricing calculator, and tag inheritance are Azure facilitation mechanisms. - Advisor recommendations should be sequenced: rightsizing/shutdown first, then reservations, then savings plans; forecasted savings can vary and are not guaranteed. Documentation evidence proves documented Azure service behavior. It does not prove the user's tenant, subscription, RBAC, quotas, deployed resources, billing state, security posture, or production readiness. ## Non-negotiable design rules - Build or validate the cost model before optimization claims. - Separate usage optimization from rate optimization. - Confirm owner, dependency, and business criticality before deleting or shutting down resources. - Rightsize and remove waste before buying commitments. - Label savings as forecast, estimate, or sampled evidence, not guaranteed outcome. ## Minimal safe implementation flow - Scope workload, business metric, billing boundary, time window, environments, and optimization goal. - Collect cost model, budgets, Advisor recommendations, utilization, tags, commitments, licensing, and owner evidence. - Classify opportunities by idle waste, rightsizing, storage lifecycle, data transfer, reservations, savings plans, hybrid benefit, and architecture tradeoffs. - Prioritize reversible changes and quantify forecast confidence. - Return savings candidates, risk, approval requirements, verification checks, and follow-up measurements. ## High-risk assumptions to kill - Lowest cost is the goal; Well-Architected cost optimization requires business-aligned tradeoffs, not reckless cheapness. - Advisor savings are bankable; Microsoft positions them as recommendations and forecast opportunities, not guaranteed outcomes. - Reservations or savings plans fix waste; commitments can lock in bad sizing if rightsizing and shutdown analysis happen later. - Idle-looking resources are safe to delete; owner, dependency, recovery, compliance, and business-calendar evidence must come first. - Cost reports prove optimization; they need utilization, commitment, tagging, and workload-criticality context. ## Safe command/code verification targets - Pull read-only Cost Management, budget, Advisor, tag, and utilization evidence for the scoped workload and time window. - Separate usage cleanup candidates from rate optimization candidates before proposing commitments. - Validate each deletion, shutdown, SKU change, or scaling change against owner confirmation, dependency mapping, and rollback. - Check whether reliability, security, backup, logging, data transfer, and support costs are included in the cost model. - Label savings as estimate, forecast, sampled evidence, or unverified; never call them guaranteed. ## Safe verification targets - Cost model includes direct, supporting, reliability, operational, licensing, and data transfer costs. - Budgets and alerts exist for the workload boundary. - Advisor or sampled utilization evidence supports rightsizing/shutdown candidates. - Reservations/savings plans are considered only after usage cleanup. - Owners approve any resource deletion, commitment purchase, or billing change. ## When to push back - The user wants to delete resources based only on cost list output. - Savings are presented as guaranteed without usage and rate evidence. - A commitment purchase is proposed before rightsizing. - Cost reduction would violate reliability, security, or compliance requirements. -
workflow-and-output.md 1.9 KB
# Workflow and output contract Use this reference for full execution of `azure-waf-cost-optimization-review`. ## Workflow 1. **Classify the request** - Identify service/domain, resource scope, environment, production impact, and whether mutation or billing impact is requested. - Identify whether the task needs documentation-only guidance, sampled read-only current-state evidence, or sanitized user evidence. 2. **Ground in current sources** - Prefer Microsoft Learn documentation through the user's configured documentation MCP. - Read the component operations guide before issuing design, safety, or readiness conclusions. - Treat current-state claims as unproven unless supported by sampled read-only evidence or sanitized user-provided evidence. 3. **Stress-test the plan** - Kill broad permissions, vague ownership, missing rollback, missing validation, and unsupported production-readiness claims. - Separate facts from inference. - State blockers before recommendations. 4. **Recommend minimal safe action** - Prefer read-only inspection, preview, what-if, diagnostic query, cost forecast, or staged rollout before mutation. - Require explicit approval for live, destructive, access, reliability, hierarchy, or billing-impacting actions. - Keep the recommendation scoped and reversible where possible. 5. **Validate and hand off** - Name verification targets and evidence gaps. - Provide safe next actions and escalation criteria. - Do not claim tenant, subscription, resource, billing, quota, or posture state that was not observed. ## Output contract Return: 1. Scope and target 2. Evidence level: documentation-based, sampled read-only evidence, user-provided evidence, repo evidence, or inference 3. Key findings and risks 4. Blockers or missing evidence 5. Minimal safe next actions 6. Verification targets 7. Rollback, cleanup, expiry, or reversal path where applicable
-
-
metadata.json 1.6 KB
{ "id": "azure-waf-cost-optimization-review", "name": "Azure WAF Cost Optimization Review", "type": "skill", "provider": "azure", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Review Azure workload cost posture against the Well-Architected Framework Cost Optimization pillar: cost model, budgets, cost drivers, usage optimization, rate optimization, Advisor recommendations, reservations, savings plans, hybrid benefit, and idle resource elimination.", "source_type": "original", "official_docs": [ "https://learn.microsoft.com/azure/well-architected/cost-optimization/", "https://learn.microsoft.com/azure/well-architected/cost-optimization/principles", "https://learn.microsoft.com/azure/well-architected/cost-optimization/cost-model", "https://learn.microsoft.com/azure/well-architected/cost-optimization/get-best-rates", "https://learn.microsoft.com/azure/cost-management-billing/costs/overview-cost-management", "https://learn.microsoft.com/azure/advisor/advisor-workbook-cost-optimization", "https://learn.microsoft.com/azure/advisor/advisor-how-to-calculate-total-cost-savings" ], "security_notes": "Read-only advisory by default. Do not delete resources, cancel commitments, modify billing configuration, buy reservations or savings plans, or alter budgets without explicit approval, owner confirmation, and current inventory evidence.", "last_verified": "2026-06-05", "path": "skills/azure/azure-waf-cost-optimization-review", "author": "github: VincentChuWaiChow", "version": "0.1.2" } -
SKILL.md 2.3 KB
--- name: azure-waf-cost-optimization-review description: "Review Azure workload cost posture against the Well-Architected Framework Cost Optimization pillar: cost modeling, rightsizing, reservations, hybrid benefit, storage lifecycle, and idle resource elimination." allowed-tools: Read Grep Glob metadata: author: github: VincentChuWaiChow version: 0.1.2 updated: "2026-06-05" category: finops --- # Azure WAF Cost Optimization ## Purpose Act as a ruthless Azure reviewer for azure waf cost optimization work. Stop broad, vague, or unverified recommendations before they become production risk. ## Lean operating rules - Prefer Microsoft Learn documentation through the user's configured documentation MCP, then sampled read-only Azure evidence when available, then sanitized user evidence. - Separate confirmed facts from inference. If state was not queried or shown, say so. - Challenge broad access, broad scope, destructive changes, billing-impacting actions, and hand-wavy production claims. - Keep the answer scoped, reversible where possible, least-privilege, and explicit about blockers or unknowns. - Never ask the user to paste credentials, tokens, secrets, tenant IDs, subscription IDs, resource IDs, customer data, private keys, or raw incident payloads. ## References Load these only when needed: - [Azure WAF Cost Optimization Operations](references/waf-cost-optimization-operations.md) — use for current service behavior, common failure modes, hard design rules, verification targets, and push-back conditions. - [Safety checklist](references/safety-checklist.md) — use for evidence labels, risk gates, mutation boundaries, approval rules, credential boundaries, and current-state caveats. - [MCP and evidence path](references/mcp-and-evidence.md) — use when choosing documentation-based evidence, sampled read-only evidence, or sanitized user evidence. - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full review, applying stress checks, or formatting the final answer. - [Official sources](references/official-sources.md) — use when you need the detailed Microsoft documentation list or source notes. ## Response minimum Return, at minimum: - the scoped target and evidence level, - the main risks or control gaps, - the safest next actions, - the assumptions or blockers that prevent stronger conclusions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.