Official agent skill

Azqr Developer

by Azure in Azure/azqr

Expert guidance for developing and contributing to Azure Quick Review (azqr) - A Go-based CLI tool for Azure resource compliance analysis

OfficialMITAuto-check passedDevelopment

Install Azqr Developer

skills CLI
$ npx skills add Azure/azqr --skill azqr-developer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/azqr azqr-developer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/azqr.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/azqr-developer .claude/skills/azqr-developer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azqr-developer
GitHub stars
794
Token cost
~3k tokens
SKILL.md length
971 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Expert guidance for developing and contributing to Azure Quick Review (azqr) - A Go-based CLI tool for Azure resource compliance analysis

  • Works in 3 steps: Adding Support for New Azure Services → Testing Requirements → Building and Distribution
  • Development work in your project
  • SKILL.md covers Project Overview, Quick Start, Project Structure and Code Style and Standards, plus 6 more sections
  • Calls make and az; needs AZURE_CLIENT_SECRET and AZURE_TOKEN_CREDENTIALS

What it does

Azqr Developer is an agent skill from Azure/azqr, published by the product's own GitHub organization. Expert guidance for developing and contributing to Azure Quick Review (azqr) - A Go-based CLI tool for Azure resource compliance analysis

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `knowledge/go-idioms.md`).

It sits in Development. It works with Microsoft Azure. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/azqr-developer”

Requirements

  • Docker
  • A credential in AZURE_CLIENT_SECRET

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Adding Support for New Azure Services
  2. Testing Requirements
  3. Building and Distribution

What it can do on your machine

Read from SKILL.md and the folder at commit 3cf9f0a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • go.dev
    • aka.ms
    • azure.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AZURE_CLIENT_SECRET
    • AZURE_TOKEN_CREDENTIALS

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azqr Developer loads about 3k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 971 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/azqr at commit 3cf9f0a, republished under its MIT licence (© Azure). 971 words, ~3,043 tokens.

Download SKILL.mdSave it as .claude/skills/azqr-developer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
azqr-developer
description
Expert guidance for developing and contributing to Azure Quick Review (azqr) - A Go-based CLI tool for Azure resource compliance analysis

Azure Quick Review (azqr) Development Skill

Expert guidance for autonomous agents and developers contributing to the Azure Quick Review (azqr) project.

Project Overview

Azure Quick Review (azqr) is a CLI tool written in Go that analyzes Azure resources for compliance with Azure's best practices and recommendations. The tool scans Azure resources using:

  • Azure Resource Graph (ARG) queries from the Azure Proactive Resiliency Library v2 (APRL)
  • Azure Resource Manager (ARM) rules built with the Azure Golang SDK

Quick Start

Prerequisites
  • Go 1.23.3 or higher
  • Valid Azure authentication (Service Principal, Managed Identity, or Azure CLI)
Essential Commands
bash
# Build the project
make build

# Run all tests (REQUIRED before submitting pull requests)
make test

# Clean build artifacts
make clean

# View all available targets
make help

Project Structure

azqr/
├── cmd/azqr/               # Main CLI application entry point
│   ├── main.go            # Application entry point
│   └── commands/          # CLI command implementations (one file per Azure service)
├── cmd/server/            # Server mode implementation
├── internal/              # Internal packages
│   ├── scanner.go         # Main scanning logic
│   ├── models/            # Data models and filters
│   ├── renderers/         # Output formatters (Excel, CSV, JSON)
│   ├── scanners/          # Service-specific scanners (one per Azure service)
│   ├── graph/             # Azure Resource Graph queries
│   └── aigov/             # AI Governance utilities
├── data/                  # Static data files
│   └── recommendations.json # Generated recommendations data
├── examples/              # Example configurations and CI/CD pipelines
├── docs/                  # Documentation website (Hugo-based)
└── Makefile              # Build automation

Code Style and Standards

Naming Conventions
  • Variables: Use camelCase for all variable names
  • Functions: Use MixedCaps for exported functions, mixedCaps for unexported
  • Packages: Use lowercase, single-word package names (avoid underscores)
  • Interfaces: Name with -er suffix when possible (e.g., Scanner, Renderer)
Documentation
  • Always add code comments using godoc style for exported functions
  • Document why, not what, unless the what is complex
  • Start comments with the name of the thing being described
  • Write comments in complete sentences
Authentication

All code must support multiple authentication methods:

  • Service Principal (environment variables: AZURE_CLIENT_ID, AZURE_CLIENT_SECRET, AZURE_TENANT_ID)
  • Azure Managed Identity
  • Azure CLI authentication
Error Handling
  • Follow Go idiomatic error handling patterns
  • Check errors immediately after the function call
  • Wrap errors with context using fmt.Errorf with %w verb
  • Keep error messages lowercase and don't end with punctuation
  • Name error variables err

Development Workflow

1. Adding Support for New Azure Services

When adding a new Azure service, follow this systematic approach:

  1. Create scanner in internal/scanners/<service>/

    • Implement the scanner interface
    • Support both ARM-based and ARG-based recommendations
    • Include appropriate error handling and logging
  2. Add command in cmd/azqr/commands/<service>.go

    • Follow the existing command pattern
    • Use appropriate service abbreviation (see README.md)
  3. Update models in internal/models/

    • Add service-specific models if needed
    • Ensure models support JSON serialization
  4. Add comprehensive tests

    • Include unit tests for scanner logic
    • Test both success and error cases
    • Use table-driven tests for multiple scenarios
  5. Update documentation

    • Add service to supported services list in README.md
    • Document any service-specific requirements
2. Testing Requirements

CRITICAL: Always run make test before submitting pull requests. This is non-negotiable.

The test command includes:

  • Linting (golangci-lint) - Code quality checks
  • Go vet checks - Static analysis
  • Module tidiness verification - Dependency management
  • Unit tests with race condition detection
  • Coverage reporting
bash
# Run the full test suite (ALWAYS run before PR)
make test

# Individual test components
make lint    # Run linter
make vet     # Run go vet
make tidy    # Check module tidiness
3. Building and Distribution
bash
# Build for current platform
make build

# Build for specific OS/architecture
GOOS=linux GOARCH=amd64 make build
GOOS=windows GOARCH=amd64 make build

# Build Docker image
make build-image

# Build with version information
PRODUCT_VERSION=1.0.0 make build

# Update recommendations.json after adding rules
make json

Common Development Tasks

Adding a New Recommendation Rule
  1. Identify the target Azure service
  2. Locate the appropriate scanner in internal/scanners/<service>/
  3. Add the rule logic following existing patterns:
    • Use consistent naming conventions
    • Include clear comments explaining the rule
    • Reference official Azure documentation
  4. Update tests to cover the new rule
  5. Run make json to update recommendations.json
  6. Verify with make test
Fixing Bugs
  1. Reproduce the issue with a minimal test case
  2. Add regression test if missing
  3. Implement fix following project patterns
  4. Verify fix with make test
  5. Update documentation if the bug revealed unclear behavior
Performance Optimization
  1. Use the throttling utilities in internal/throttling/ for rate limiting
  2. Implement concurrent scanning where appropriate (use goroutines wisely)
  3. Cache expensive operations when possible
  4. Profile using Go's built-in tools before optimizing
  5. Focus on algorithmic improvements first

Scanner Implementation Patterns

Scanner Interface
go
// internal/scanners/<service>/<service>.go
package <service>

import (
    "context"
    "github.com/Azure/azqr/internal/models"
)

// Scanner implements the service scanner interface
type Scanner struct {
    // Scanner fields (config, client, etc.)
}

// Scan performs the compliance scan for the service
func (s *Scanner) Scan(ctx context.Context) ([]models.Recommendation, error) {
    // Implementation
    // 1. Fetch resources
    // 2. Apply recommendation rules
    // 3. Return findings
}
Command Implementation
go
// cmd/azqr/commands/<service>.go
package commands

import (
    "github.com/spf13/cobra"
)

func init() {
    // Register command with root command
}

var <service>Cmd = &cobra.Command{
    Use:   "<service>",
    Short: "Scan <Service Name>",
    Long:  "Detailed description of what this scanner does",
    Run:   <service>Run,
}

func <service>Run(cmd *cobra.Command, args []string) {
    // Command implementation
    // 1. Parse flags
    // 2. Initialize scanner
    // 3. Run scan
    // 4. Output results
}

Testing Patterns

Table-Driven Tests
go
func TestScanner_Scan(t *testing.T) {
    tests := []struct {
        name    string
        setup   func() // setup test environment
        want    int    // expected number of recommendations
        wantErr bool
    }{
        {
            name:    "success case",
            setup:   func() { /* setup */ },
            want:    5,
            wantErr: false,
        },
        {
            name:    "error case",
            setup:   func() { /* setup */ },
            want:    0,
            wantErr: true,
        },
    }
    
    for _, tt := range tests {
        t.Run(tt.name, func(t *testing.T) {
            tt.setup()
            // test implementation
        })
    }
}

Runtime Debugging and Troubleshooting

Enable Debug Mode
bash
# Set environment variable for detailed logging
export AZURE_SDK_GO_LOGGING=all

# Run with debug flag
./azqr scan --debug
Show full SKILL.md (427 more words)Show less
Common Issues and Solutions
  1. Authentication Failures

    • Verify Azure credentials are set correctly
    • Check permissions (requires Reader on Subscription/Management Group)
    • Test with az account show if using Azure CLI auth
  2. Rate Limiting

    • Use appropriate throttling settings
    • Implement exponential backoff for retries
    • Consider batching requests when possible
  3. Memory Usage

    • Monitor for large subscriptions with many resources
    • Use streaming or pagination for large datasets
    • Profile memory usage with pprof
  4. Network Connectivity

    • Ensure access to Azure APIs
    • Check firewall and proxy settings
    • Verify DNS resolution

Environment Variables

Authentication
bash
# Service Principal
AZURE_CLIENT_ID="<service-principal-id>"
AZURE_CLIENT_SECRET="<service-principal-secret>"  
AZURE_TENANT_ID="<tenant-id>"

# Credential Chain Configuration
AZURE_TOKEN_CREDENTIALS="dev"   # Use Azure CLI/Azure Developer CLI
AZURE_TOKEN_CREDENTIALS="prod"  # Use env vars/workload identity/managed identity
Debugging
bash
AZURE_SDK_GO_LOGGING="all"      # Enable detailed SDK logging

Contributing Guidelines

Pull Request Requirements
  1. Testing: Run make test and ensure all tests pass (100% required)
  2. Code Quality: Follow the existing code style and patterns
  3. Documentation: Update relevant documentation (README, code comments)
  4. Commit Messages: Use clear, descriptive commit messages
  5. Dependencies: Minimize new dependencies; justify if necessary
Supported Azure Services

The project currently supports 50+ Azure services including:

  • Compute: VMs, AKS, Azure Functions, App Service, etc.
  • Storage: Storage Accounts, Disks, NetApp Files, etc.
  • Networking: Virtual Networks, Load Balancers, Application Gateway, etc.
  • Databases: SQL, Cosmos DB, PostgreSQL, MySQL, etc.
  • And many more...

When adding new services:

  1. Use appropriate abbreviations (see README.md for existing conventions)
  2. Implement both ARM-based and ARG-based recommendations where applicable
  3. Follow the scanner interface pattern
  4. Include appropriate error handling and logging
Output Formats

azqr generates reports in multiple formats:

  • Excel (default): Multi-sheet workbook with recommendations, impacted resources, inventory, etc.
  • CSV: Same data as Excel but in CSV format (use --csv flag)
  • JSON: Machine-readable format for automation

Key Resources and References

Support and Community

  • Issues: Use GitHub Issues for bug reports and feature requests
  • Discussions: Use GitHub Discussions for questions and support
  • Security: Report security issues following the SECURITY.md guidelines
  • Code of Conduct: Follow the Microsoft Open Source Code of Conduct

Critical Reminders

  1. Always run make test before submitting a pull request - This is the most important rule
  2. Use camelCase for variable names
  3. Add godoc-style comments to all exported functions
  4. Support all authentication methods (Service Principal, Managed Identity, Azure CLI)
  5. Follow Go idiomatic error handling
  6. Keep code simple and readable
  7. Update recommendations.json with make json after adding rules
  8. Reference APRL documentation when implementing ARG-based rules
  9. Test both success and error paths
  10. Keep scanner implementations consistent with existing patterns

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/azqr-developer of Azure/azqr.

  • SKILL.md
  • knowledge/go-idioms.md

Open the folder on GitHubat commit 3cf9f0a

Compare with similar skills

Azqr Developer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azqr Developer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azqr Developer this skillAzure/azqr794—~3kAutomated safety check: PassMIT
Drawio Azuresparklabx/drawio-ai-kit652—~1.6kAutomated safety check: PassMIT
Azsdk Common Generate SDK LocallyAzure/azure-sdk-for-android121—~1.5kAutomated safety check: PassMIT
Kouchou AI Developmentdigitaldemocracy2030/kouchou-ai171—~540Automated safety check: NotesAGPL-3.0
New Resourcemondoohq/mql411—~5.6kAutomated safety check: PassCustom licence
Azv Azure To DiagramAzure/AZVerify101—~5.7kAutomated safety check: PassMIT

Similar skills

  • Drawio Azure

    sparklabx/drawio-ai-kit

    A skill your agent uses when the user asks for an Azure architecture diagram — VNet/networking, App Service, AKS, landing zone, multi-region, or any diagram built with Azure service icons.

    652 GitHub stars~1.6k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Azsdk Common Generate SDK Locally

    Azure/azure-sdk-for-android

    Official

    Generate, build, and test Azure SDKs locally from TypeSpec with automatic customization.

    121 GitHub stars~1.5k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Kouchou AI Development

    digitaldemocracy2030/kouchou-ai

    Local development setup, build and lint commands, environment configuration, and deployment helpers for the kouchou-ai repo.

    171 GitHub stars~540 tokensUpdated yesterday
    DevelopmentAuto-check: notes
  • New Resource

    mondoohq/mql

    Add or change a resource in an existing mql provider — schema, codegen, implementation, tests, and verification against a real target.

    411 GitHub stars~5.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Azv Azure To Diagram

    Azure/AZVerify

    Official

    Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.

    101 GitHub stars~5.7k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Azure Draw.io MCP Diagrams

    thomast1906/github-copilot-agent-skills

    Creates and edits architecture diagrams through the Draw.io MCP tool, with guidance for rendering Azure icons correctly and laying out network diagrams.

    202 GitHub stars~3.1k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from Azure/azqr

  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    794 GitHub starsUsed in 89 repos~8.2k tokens
    Auto-check passed
  • Kql Validator

    Azure/azqr

    Official

    Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.

    794 GitHub stars~703 tokensUpdated 2 days ago
    Auto-check passed
  • Review Areas

    Azure/azqr

    Official

    In-depth code review that fans out parallel subagents across review areas — CRITICAL after non-trivial development.

    794 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Code Simplifier

    Azure/azqr

    Official

    Analyzes recently modified code and creates pull requests with simplifications that improve clarity, consistency, and maintainability while preserving functionality

    794 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Azqr Developer

What does Azqr Developer do?

Expert guidance for developing and contributing to Azure Quick Review (azqr) - A Go-based CLI tool for Azure resource compliance analysis. Azqr Developer is an agent skill from Azure/azqr, published by the product's own GitHub organization.

When should I use Azqr Developer?

Azqr Developer fits situations like: development work in your project.

How do I install Azqr Developer in Claude Code?

Run `npx skills add Azure/azqr --skill azqr-developer -a claude-code`. Or copy the skill folder (.agents/skills/azqr-developer in Azure/azqr) into .claude/skills/azqr-developer in your project. Claude Code loads it when a task matches its description.

How do I install Azqr Developer in Codex?

Run `npx skills add Azure/azqr --skill azqr-developer -a codex`. Or copy the skill folder (.agents/skills/azqr-developer in Azure/azqr) into .agents/skills/azqr-developer in your project. Codex loads it when a task matches its description.

Can I use Azqr Developer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/azqr --skill azqr-developer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azqr-developer, .gemini/skills/azqr-developer, .github/skills/azqr-developer and .opencode/skills/azqr-developer in your project.

What does Azqr Developer need to run?

Going by SKILL.md and its folder, Azqr Developer needs the command-line tools its instructions call (make and az) and credentials named AZURE_CLIENT_SECRET and AZURE_TOKEN_CREDENTIALS. Our summary lists: Docker; A credential in AZURE_CLIENT_SECRET.

Does Azqr Developer access the network?

SKILL.md names 4 domains. As links in the text: github.com, go.dev, aka.ms and azure.github.io. This is read from the text; nothing was executed.

Is Azqr Developer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azqr Developer use?

Azqr Developer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azqr Developer use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azqr Developer?

Skills that share tags, products or a category with Azqr Developer: Drawio Azure (sparklabx/drawio-ai-kit, 652 stars), Azsdk Common Generate SDK Locally (Azure/azure-sdk-for-android, 121 stars), Kouchou AI Development (digitaldemocracy2030/kouchou-ai, 171 stars) and New Resource (mondoohq/mql, 411 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azqr Developer?

Azure (a GitHub organization, an official publisher) maintains it in Azure/azqr, which has 794 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 5, 2026.

Source: Azure/azqr on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.