Azure Cost Mcp — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Azure Cost Mcp (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
An MCP server that gives Claude live access to Azure pricing and cost data — retail prices, VM comparisons, reservation analysis, architecture estimates, and actual subscription spend.
Nine tools across two API groups:
| Tool | Description | Auth required |
|---|---|---|
azure_search_prices | Search Azure retail prices with OData filters | No |
azure_compare_vm_prices | Compare VM SKUs across regions (monthly matrix) | No |
azure_find_cheapest_region | Find cheapest regions for a given SKU | No |
azure_compare_reservation_vs_payg | PAYG vs 1-yr / 3-yr reservation with break-even | No |
azure_estimate_architecture_cost | Estimate multi-component architecture monthly cost | No |
azure_query_costs | Query actual subscription spend (group by service, resource group, etc.) | Yes |
azure_query_costs_by_resource | Top-N resources by spend with % of total | Yes |
azure_get_cost_forecast | Cost forecast for a period | Yes |
azure_list_budgets | List budgets with CRITICAL / WARNING / OK status | Yes |
npm install
npm run buildCreate a service principal and assign the Cost Management Reader role:
# Create service principal
az ad sp create-for-rbac --name azure-cost-mcp --role "Cost Management Reader" \
--scopes /subscriptions/<SUBSCRIPTION_ID>
# Output includes appId (clientId), password (clientSecret), tenant (tenantId)Add to ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):
{
"mcpServers": {
"azure-cost": {
"command": "node",
"args": ["/absolute/path/to/azure-cost-mcp/dist/index.js"],
"env": {
"AZURE_TENANT_ID": "...",
"AZURE_CLIENT_ID": "...",
"AZURE_CLIENT_SECRET": "...",
"AZURE_SUBSCRIPTION_ID": "..."
}
}
}
}The retail tools work without credentials. Cost Management tools will return setup instructions if credentials are missing.
| Variable | Required | Description |
|---|---|---|
AZURE_TENANT_ID | For auth tools | Azure AD tenant ID |
AZURE_CLIENT_ID | For auth tools | Service principal application ID |
AZURE_CLIENT_SECRET | For auth tools | Service principal secret |
AZURE_SUBSCRIPTION_ID | For auth tools | Subscription to query |
AZURE_RETAIL_DEFAULT_CURRENCY | No | Default currency (default: USD) |
A Claude Code skill at ~/.claude/skills/azure-cost.md encodes tool routing rules, the reservation comparison rule, output conventions, and graceful degradation guidance. Install it by copying skills/azure-cost.md from this repository to ~/.claude/skills/.
npm test # run tests
npm run test:watch # watch mode
npm run lint # ESLint
npm run format # Prettier~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.