Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 7d3136f2853e436a… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Prepare — Architecture Planning & Cost Estimation
Quick Reference
| Property | Value |
|---|---|
| Best for | Mapping app components to Azure services with cost estimation and quota validation |
| Inputs | prereq-output.json + context.json from .copilot-azure/sessions/{id}/ |
| Outputs | prepare-plan.json written to session directory |
| Parent | azure-app-onboard |
When to Use This Skill
Invoked by the azure-app-onboard orchestrator at Phase 2 when prereq-output.json exists. Not directly user-routable.
Return to orchestrator: When complete, return control to
azure-app-onboard. Do NOT directly invoke scaffold or deploy.
When NOT to Use
| Scenario | Use Instead |
|---|---|
| Code readiness or prereq scanning | azure-app-onboard Step 3 (prereq) |
| IaC generation from a completed plan | azure-app-onboard Step 7 (scaffold) |
| Deploying resources to Azure | azure-app-onboard Step 9 (deploy) |
| Optimizing existing Azure spend | cost-optimization from the optional azure-cost plugin |
| Estimating VM-specific costs | azure-compute |
| Enterprise landing zone architecture | azure-enterprise-infra-planner |
If cost-optimization is unavailable, explain that it is provided by the
optional azure-cost plugin and direct the user to their client's supported
plugin installation flow; do not imply the handoff completed.
MCP Tools
| Tool | Purpose |
|---|---|
mcp_azure_mcp_pricing / azure-pricing (router → command: pricing_get) | Cost estimation (inline — see Step 6). Fallback: dispatch subagent-pricing.md |
mcp_azure_mcp_policy | Subscription policy constraints |
az rest | Quota validation (via sub-agent — see Step 5) |
mcp_azure_mcp_cloudarchitect → cloudarchitect_design | WAF-aligned architecture design |
mcp_azure_mcp_wellarchitectedframework | Per-service WAF guidance |
mcp_azure_mcp_advisor → advisor_recommendation_list | Optimization recommendations |
Workflow
| # | Step | Action | Reference |
|---|---|---|---|
| 1 | Read session state | Load prereq-output.json + context.json. Resolve subscription | Cross-ref subscription-resolution.md if needed |
| 2 | Query policy constraints | Inline MCP: fetch policy + advisor recommendations | mcp_azure_mcp_policy + mcp_azure_mcp_advisor |
| 3 | Map components to services | Per-component Azure service selection, Dockerfile routing, deploy-as-is | ⛔ You MUST read service-mapping.md and deploy-strategy.md |
| 4 | Select SKUs + WAF analysis | Budget-aware SKU selection, inline WAF service guidance | ⛔ You MUST read sku-matrix.md |
| 5 | Validate quotas + region capacity | ⛔ Read subagent-quota.md → dispatch as task (NEXT action MUST be task, ⛔ agent_type: "task" — NEVER "general-purpose"). Copy the COMPLETE and UNMODIFIED template text into the task prompt between <<<TEMPLATE_START>>> / <<<TEMPLATE_END>>> delimiters — do NOT summarize. Append the caller-provided inputs listed in subagent-quota.md's Input table AFTER the template block. ⛔ After dispatching, proceed to Step 6 (cost estimation) while the subagent runs. Do NOT run quota checks yourself — the subagent handles it. Collect subagent results before Step 9 (write plan). | ⛔ You MUST read subagent-quota.md |
| 6 | Estimate costs | ⛔ You MUST read pricing-guide.md for methodology, then pricing-guide-services.md for per-service filters. Call the pricing router (mcp_azure_mcp_pricing/azure-pricing) with command: "pricing_get" + a parameters{} object inline per paid service. If MCP unavailable or fails → ⛔ Read subagent-pricing.md → dispatch as task (NEXT action MUST be task, ⛔ agent_type: "task" — NEVER "general-purpose"). Copy the COMPLETE and UNMODIFIED template text into the task prompt between <<<TEMPLATE_START>>> / <<<TEMPLATE_END>>> delimiters — do NOT summarize. Append data (services[], region, budget tier) AFTER the template block. Write results to prepare-plan.json.costEstimate. | pricing-guide.md |
| 7 | Generate naming | Centralized naming: suffix, prefix, all resource names | ⛔ You MUST read naming-patterns.md |
| 8 | Determine IaC format | Existing non-Azure .tf → ask_user Bicep vs TF, write to overrides[].iacFormat. No .tf → default Bicep. | (inline) |
| 9 | Write prepare-plan.json | Per PreparePlan schema. Include postDeployRecommendations, deploymentVariables | ⛔ You MUST read prepare-schemas.ts for PreparePlan schema |
| 10 | Return summary | Structured summary for orchestrator approval gate | (inline — 1 line) |
| 11 | Validate plan | 4-dimension check: Goal Alignment, WAF Alignment, Dependency Completeness, Deployment Viability. Fix inline on failure, document tradeoffs in assumptions[]. | All must pass before writing |
Step 5 — Post-Quota Validation
⛔ NEVER present a region without checking quota first. Skipping quota validation causes cascading deploy failures and extended healing loops. ⛔ If plan includes PostgreSQL/MySQL, verify
offerRestrictionsVerified: true— if false/missing, region is blocked. Do NOT proceed to scaffold with unchecked DB services. ⛔ Free ≠ unlimited. Every compute SKU — including F1, Consumption, and Serverless tiers — has a per-subscription, per-region quota. Do NOT skip quota checks because a SKU is free. ⛔ After region fallback, update ALLservices[].regioninprepare-plan.json. Do not leave stale values.
Error Handling
| Error | Remediation |
|---|---|
| Pricing API 400 | Verify --sku included. Free tiers: skip API |
| MCP pricing unavailable | Dispatch subagent-pricing.md as task fallback (uses direct HTTP to prices.azure.com) |
| Prereq output missing | Trigger prereq backfill |
| Quota check fails | Fall back to best-effort estimate + disclaimer |
| Override conflicts | Re-run from Step 3 with new constraints |
Files
13- SKILL.md
aec53f71f66.4 KB - references/deploy-strategy.md
d7187f4c836.8 KB - references/mcp-tools.md
0ba0aacded5.6 KB - references/naming-patterns.md
df747fb9d34.6 KB - references/prepare-schemas.ts
903e00912e7.0 KB - references/pricing-guide-services.md
1a4a4594b98.4 KB - references/pricing-guide.md
1000c4d89e4.0 KB - references/service-mapping.md
e100b7e8fb8.5 KB - references/sku-matrix.md
6c6f3d8c073.2 KB - references/sku-quota-validation.md
13e46947139.0 KB - references/subagent-pricing.md
26ade5773c2.5 KB - references/subagent-quota.md
cb1a9f14713.5 KB - references/validation-rubric.md
9f36164b9a2.3 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from microsoft/skills8
Build Azure AI Foundry agents using the Microsoft Agent Framework Python SDK (agent-framework-azure-ai). Use when creating persistent agents with AzureAIAgentsProvider, using hosted tools (code interpreter, file search, web search), integrating MCP servers, managing conversation threads, or implemen
Set up AI Runway on AKS — from bare cluster to running model. Covers cluster verification, controller install, GPU assessment, provider setup, and first deployment. WHEN: \"setup AI Runway\", \"onboard AKS cluster\", \"install AI Runway\", \"airunway setup\", \"deploy model to AKS\", \"GPU inference
Diagnose Day-2 AKS GPU and KAITO incidents using profile-aware, read-only evidence. WHEN: 'Insufficient nvidia.com/gpu', GPU pod Pending, model-load OOM, DCGM/VRAM, KAITO Workspace not ready, or GPU autoscaling. DO NOT USE FOR: setup (airunway-aks-setup), non-GPU incidents (aks-troubleshooting), sta
Lookup documented AKS fixes only when the prompt includes an exact catalog signature and all of its qualifiers: VMCannotFitEphemeralOSDisk; NodePoolMcVersionIncompatible; 'NodeImageVersion is not accepted'; AKS SkuNotAvailable with size, location, and zone; ZonalAllocationFailed with insufficient zo
Collects bounded packet captures from AKS nodes and Azure network configuration for wire-level evidence. WHEN: \"capture packets on an AKS node\", \"take a pcap\", \"run tcpdump on AKS\", \"prove where packets drop\". Use for explicit packet-capture intent after read-only diagnostics, not general AK
Debug live Azure Kubernetes Service (AKS) incidents with a read-only, evidence-first investigation. WHEN: pod crashes or Pending, CrashLoopBackOff, OOMKilled, ImagePullBackOff, node NotReady, DNS or ingress failure, connectivity timeout, network policy, SNAT exhaustion, node-pool scaling blocked by
Guidance for instrumenting webapps with Azure Application Insights. Provides telemetry patterns, SDK setup, and configuration references. WHEN: how to instrument app, App Insights SDK, telemetry patterns, what is App Insights, Application Insights guidance, instrumentation examples, APM best practic
Instrument browser/web apps with the Application Insights JavaScript SDK (@microsoft/applicationinsights-web). Use for Real User Monitoring (RUM) — page views, clicks, AJAX/fetch dependencies, exceptions, custom events, and browser-side GenAI agent traces correlated to backend OpenTelemetry traces.
Related devops skillsscan passed
Build monitoring dashboards that answer real operator questions for Grafana, SigNoz, and similar platforms. Use when turning metrics into a working dashboard instead of a vanity board.
Configure deployment settings for /land-and-deploy.
Build or maintain Cloudflare Sandbox apps on @cloudflare/sandbox@next (SDK 1.0 preview). Use sandbox-migrate-to-next when porting a stable app.
Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea
Automates CI/CD pipeline setup. Use when setting up or modifying build and deployment pipelines. Use when you need to automate quality gates, configure test runners in CI, or establish deployment strategies.
Deploys and manages full-stack web applications (Next.js, Angular) with Server-Side Rendering (SSR) using Firebase App Hosting. Use when deploying Next.js/Angular apps, configuring apphosting.yaml or firebase.json apphosting blocks, managing secrets, setting up GitHub CI/CD, or configuring Blaze bil