Azure Draw.io MCP Diagrams
thomast1906/github-copilot-agent-skills
Creates and edits architecture diagrams through the Draw.io MCP tool, with guidance for rendering Azure icons correctly and laying out network diagrams.
Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.
$ npx skills add Azure/AZVerify --skill azv-azure-to-diagram -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/AZVerify azv-azure-to-diagram --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azv-azure-to-diagram .claude/skills/azv-azure-to-diagram && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azv-azure-to-diagram" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-azure-to-diagram into .claude/skills/azv-azure-to-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-azure-to-diagram", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-azure-to-diagramType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/AZVerify --skill azv-azure-to-diagram -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/AZVerify azv-azure-to-diagram --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/azv-azure-to-diagram .agents/skills/azv-azure-to-diagram && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azv-azure-to-diagram" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-azure-to-diagram into .agents/skills/azv-azure-to-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-azure-to-diagram", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AZVerify --skill azv-azure-to-diagram -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/AZVerify azv-azure-to-diagram --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/azv-azure-to-diagram .cursor/skills/azv-azure-to-diagram && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azv-azure-to-diagram" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-azure-to-diagram into .cursor/skills/azv-azure-to-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-azure-to-diagram", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/AZVerify.git --path .github/skills/azv-azure-to-diagram--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/AZVerify --skill azv-azure-to-diagram -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/AZVerify azv-azure-to-diagram --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/azv-azure-to-diagram .gemini/skills/azv-azure-to-diagram && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azv-azure-to-diagram" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-azure-to-diagram into .gemini/skills/azv-azure-to-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-azure-to-diagram", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/AZVerify azv-azure-to-diagramInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/AZVerify --skill azv-azure-to-diagram -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/azv-azure-to-diagram .github/skills/azv-azure-to-diagram && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azv-azure-to-diagram" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-azure-to-diagram into .github/skills/azv-azure-to-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-azure-to-diagram", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AZVerify --skill azv-azure-to-diagram -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/AZVerify azv-azure-to-diagram --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/azv-azure-to-diagram .opencode/skills/azv-azure-to-diagram && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azv-azure-to-diagram" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-azure-to-diagram into .opencode/skills/azv-azure-to-diagram/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-azure-to-diagram", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azv-azure-to-diagramReverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.
Azv Azure To Diagram is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions. Use when the user wants to visualize or document existing Azure infrastructure as a diagram.
Its SKILL.md is about 5.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires an authenticated Azure session (CLI, Az PowerShell, or Azure MCP).
It sits in Development, covering Diagrams. It works with Microsoft Azure, draw.io, Bicep and PowerShell. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d6a2b92. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
azpwshFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires an authenticated Azure session (CLI, Az PowerShell, or Azure MCP).
From compatibility in the SKILL.md frontmatter.
Azv Azure To Diagram loads about 5.7k tokens when it runs. Until then it costs about 71 tokens; SKILL.md has 2,894 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/AZVerify at commit d6a2b92, republished under its MIT licence (© Azure). 2,894 words, ~5,672 tokens.
.claude/skills/azv-azure-to-diagram/SKILL.md (or your agent's skills folder).Discover resources in a live Azure scope and generate a Draw.io architecture diagram with proper container hierarchy, verified icons, and inferred relationships.
Input: An Azure scope — a resource group name (primary) or a subscription ID with optional resource type filter. The user can specify the scope or the skill will prompt for it.
Tools required: File system tools (read/write files), Terminal (for running az CLI commands and PowerShell 7 / pwsh shared scripts), Azure MCP server tools (mcp_azure_group_resource_list, mcp_azure_compute, mcp_azure_storage, mcp_azure_subscription_list, etc.), Draw.io MCP (mcp_drawio_create_diagram or mcp_draw_io_create_diagram)
Before discovery, verify the capabilities used by this workflow:
azure-get_azure_bestpractices with get_azure_bestpractices_get for general code generation guidance.azure-bicepschema with bicepschema_get for every resource type whose API version or deployable schema is uncertain.azure-documentation search and fetch for current service guidance when a schema call does not answer the question.If a capability is unavailable, continue only when the matching shared reference plus Bicep CLI validation can provide the same check; report the fallback in the verification summary.
Follow .github/skills/shared/procedures/output-budget.md strictly — this skill frequently handles 20-40+ resources and can hit the LLM response length limit. In addition to the shared rules:
.drawio file via the Draw.io MCP tool. Do NOT echo full Draw.io XML content in the response — show only the file path and a summary of what was generated.resource-model.json, extract-*.json, and any other temporary resource model JSON) are never deliverables. Keep them available until Step 9c has written original-request.md (it needs the resource counts and relationship tables), then delete them all in Step 9d. Never leave the resource model JSON behind after the skill completes.If pwsh/powershell.exe or a shared script cannot be executed, use the fallback that matches the step you are on, then continue the workflow normally:
| Step | Fallback source |
|---|---|
| 1 — Auth check | MCP auth probe fallback in .github/skills/shared/procedures/azure-authentication.md |
| 3 — Discovery | "Script/pwsh Unavailable — MCP Fallback" in .github/skills/shared/azure-resource-configs.md (see Step 3e) |
| 4 — Filtering | Inline fallback in .github/skills/shared/procedures/resource-filtering.md |
| 6a — Property extraction | "Script/pwsh Unavailable — MCP Fallback" in .github/skills/shared/azure-resource-configs.md |
| 6b — Read-only stripping and secrets | Manual strip rules listed in Step 6b, using .github/skills/shared/data/arm-readonly-properties.json |
| 7a — Relationships | "Manual Relationship Inference — Script Unavailable Fallback" in .github/skills/shared/azure-resource-model.md |
Stop only if Azure MCP is also unavailable, using the prerequisite message in .github/skills/shared/azure-resource-configs.md.
Run pwsh .github/skills/shared/scripts/Test-AzureAuth.ps1 — see .github/skills/shared/procedures/azure-authentication.md for the script contract. The script writes a JSON status object to stdout and exits non-zero when no Azure session is found. A non-zero exit code is a HARD GATE: present the authentication instructions from the contract doc and stop. (If pwsh or the script is unavailable, see "Fallback: pwsh Unavailable".)
Identify the Azure scope to discover resources from.
If the user specifies a resource group name:
az group show --name <name> (or, if az is unavailable, Get-AzResourceGroup -Name <name> via Az PowerShell, or mcp_azure_group_list/mcp_azure_group_resource_list via Azure MCP) — if all available methods fail, report an error and stopIf the user specifies a subscription ID:
If no scope is specified:
Which Azure resource group should I generate a diagram from?
If you want subscription-level discovery, provide a subscription ID instead.Resource type filters: If the user provides a resource type filter (e.g., "only compute and networking resources"):
Microsoft.Compute/*, Microsoft.Network/*)Resource exclusions: If the user wants to exclude specific resources or types from the diagram:
Enumerate all resources in the specified Azure scope.
3a. Create Solution Folder
Create the solution folder now, before any intermediate files are written.
MyAppRG → folder my-app-rg/my-app-rg-2/, my-app-rg-3/, …). If more than 5 collisions are detected, ask the user to confirm the output folder name.3b. Resource group scope
Run the shared discovery script and write the resource model to a temporary JSON file in the output folder:
pwsh .github/skills/shared/scripts/Get-AzureResourceModel.ps1 -ResourceGroup <rg-name> -OutFile <output-folder>/resource-model.jsonThe script emits the shared resource model contract (id, name, type, location, tags, sku) documented in .github/skills/shared/azure-resource-model.md. Treat the emitted JSON as the source of truth for Steps 4-7. Do not print the model contents.
If the script exits non-zero or produces unparseable output, use "Script/pwsh unavailable — MCP fallback" (Step 3e) instead of stopping. Only stop if Azure MCP is also unavailable, per "Fallback: pwsh Unavailable" above. If the result count is zero and the resource group was confirmed to exist in Step 2a, warn the user that the authenticated identity may lack Reader permissions.
Display a single progress line:
Found **N resources** in `<rg-name>` — now filtering and enriching.3c. Subscription scope
Run the same script with -SubscriptionId <sub-id> instead of -ResourceGroup. Do not apply user-specified exclusions here — those are applied exactly once, in Step 4, alongside the standard exclusion rules, to avoid filtering the same resource list twice. Resource type inclusion filters (Step 2b) are applied uniformly for both scopes in Step 3d below.
If the script exits non-zero or produces unparseable output, use "Script/pwsh unavailable — MCP fallback" (Step 3e) instead of stopping. Only stop if Azure MCP is also unavailable, per "Fallback: pwsh Unavailable" above. If the result count is zero, warn the user that the authenticated identity may lack Reader permissions on this subscription.
Display a single progress line:
Found **N resources** in subscription `<sub-id>` — now filtering and enriching.3d. Apply Resource Type Inclusion Filters
Get-AzureResourceModel.ps1 has no -ResourceTypeFilter parameter — it never narrows results by type on its own, regardless of scope. If the user specified a resource type inclusion filter in Step 2b (e.g., "only show networking resources" → Microsoft.Network/*), apply it now, before the resource model is treated as the source of truth for the remaining steps:
<output-folder>/resource-model.json).type matches one of the mapped inclusion prefixes from Step 2b (case-insensitive, wildcard * match). Discard the rest.<output-folder>/resource-model.json with the filtered result, preserving the same JSON shape (id, name, type, location, tags, sku, relationships).If the user did not specify an inclusion filter in Step 2b, skip this step — the model from Step 3b/3c passes through unchanged.
3e. Script/pwsh unavailable — MCP fallback
If pwsh/powershell.exe or the script cannot be executed, build the same resource model through Azure MCP as described in "Fallback: pwsh Unavailable" (list resources with mcp_azure_group_resource_list, then assemble the model shape by hand, applying the same inclusion-filter logic from Step 3d before treating the result as final).
3f. Handle empty results
If no resources are found (or none remain after filtering):
## No Resources Found
No resources were found in `<scope-name>`.
If you expected resources here, verify:
- The resource group name is spelled correctly
- You're connected to the correct subscription (`az account show` or `Get-AzContext`)
- Resources have been deployed to this scopeRun pwsh .github/skills/shared/scripts/Select-AzureResources.ps1 -InputFile <resource-model.json> -Mode diagram — see .github/skills/shared/procedures/resource-filtering.md for the script contract. The script applies the shared exclusion rules using the "Exclude for Diagrams" column, writes the filtered resource model JSON to stdout, and should be treated as the source of truth for the remaining steps. (If pwsh or the script is unavailable, see "Fallback: pwsh Unavailable".)
If the script exits non-zero or produces unparseable output, report the error message to the user and stop. Do not proceed with an empty or partial resource list.
Also apply any user-specified exclusion filters from Step 2b now — this is the only place exclusions are applied (inclusion filters, if any, were already applied in Step 3d).
If all resources are filtered out, report "No Diagram-Worthy Resources" and stop execution.
Display the filtered resource list:
Write the temporary resource model JSON to the solution folder created in Step 3a. It is an intermediate artifact only and must be deleted before the skill finishes.
If the filtered resource count exceeds 20, warn and offer:
Re-filter if the user selects option 1, then continue.
If the user's response does not map to option 1 or option 2, re-present the two options with the instruction: "Please reply with 1 to filter by type or 2 to generate the full diagram." If after two re-prompts no valid choice is received, default to option 2 and note this in the completion summary.
Use resource-type-specific Azure MCP tools to retrieve detailed properties for relationship inference.
Enrichment targets (by resource type): look up each in-scope resource's resourceTypes[] entry in .github/skills/shared/data/azure-property-paths.json for the MCP tool (or CLI fallback) and the ARM JSON paths to extract. That mapping is the authoritative source — see "Property Mapping Source of Truth" in .github/skills/shared/azure-resource-configs.md for how to consume it. Do not duplicate the mapping table here.
Enrichment process:
Prefer batch CLI enrichment over per-resource MCP calls to reduce output volume:
az resource list --resource-group <rg> -o json with --query to get all resources with their full properties in one call (or, if az is unavailable, Get-AzResource -ResourceGroupName <rg> -ExpandProperties via Az PowerShell). Parse the output to extract relationship-relevant properties. As each resource is enriched this way, record its enrichment source (batch) in a local tracking variable (e.g., a map of resource ID → batch/targeted/failed)..github/skills/shared/data/azure-property-paths.json).az webapp config appsettings list for App Service app settings). Update the tracking variable to targeted for each resource enriched this way, or failed if the call errors or is unavailable.Output discipline during enrichment:
Enriched N resources (K via batch query, J via targeted API calls, W warnings).Graceful fallback: If a resource-type-specific MCP tool fails or is unavailable:
The discovery script (Step 3b/3c) already populates a baseline relationships array on each resource — parent/child contains links plus any relationship it detects by matching ARM resource IDs inside properties (see .github/skills/shared/azure-resource-model.md). That baseline was computed before enrichment, so it only saw the often-sparse az resource list property bags — it can miss direct ARM ID references (NIC subnet IDs, private-endpoint targets, App Service Plan IDs, etc.) that only appear once Step 6 enrichment fills in the fuller properties. Before layering on the patterns below, re-run the generic ID-matching detection (the patterns in the "Manual Relationship Inference" table of .github/skills/shared/azure-resource-model.md) against the enriched properties and merge any newly-found relationships into the baseline array, de-duplicating against relationships already present. Then use the patterns below to add diagram-specific edge styles and detect relationships the generic ID matching cannot see (connection strings, Key Vault reference syntax, RBAC scope strings, co-location).
Analyze enriched resource properties to discover the remaining relationships the baseline cannot see — none of these are direct ARM ID references, so generic ID matching misses them. (Edge styling for the resulting relationship types is defined once in drawio-diagram-conventions.md §5 — do not re-specify colors here.)
| Pattern | Detection | Relationship |
|---|---|---|
| Key Vault References | Config contains @Microsoft.KeyVault(SecretUri=...) | secures |
| App Insights | App settings contain APPLICATIONINSIGHTS_CONNECTION_STRING matching AI resource | connects |
| Connection Strings | App settings contain SQL/Cosmos/Storage/Redis server names matching discovered resources | connects |
| Named Connection Strings | az webapp config connection-string list entries reference database or storage resources in the same RG | connects |
| RBAC Role Assignment | Managed identity has role assignments whose scope matches a discovered resource's ARM ID | secures |
Co-located Resource Inference
After completing explicit relationship detection using the table above, check for implicit co-location connections using this numbered checklist:
connects edge and label it (inferred) in the relationship output so the user can verify.Resources with no relationships are placed directly inside their resource group container.
Output (concise): Follow Output Budget Rules for display format. Example count summary:
Inferred **N relationships** (saved to a temporary resource model file). Key: 3 subnet placements, 2 PEs, 4 data connections.Build the Draw.io diagram XML from the resource model and inferred relationships following the shared conventions in .github/skills/shared/drawio-diagram-conventions.md.
Follow all diagram construction rules: canvas format, stencil mapping lookup, resource shapes and icon paths, container hierarchy (Resource Group → VNet → Subnet), edge rules, VNet Integration special case, and layout patterns (left-to-right flow, 2×2 zone grid, hub-and-spoke, semantic proximity, sizing).
If a resource type has no entry in azure-stencil-mapping.json, use the generic Azure resource stencil mxgraph.azure2.general and append a warning to the completion summary listing unmapped types so the user can update the mapping file.
Multi-page diagrams: When the resource group includes networking subnets or monitoring resources that survived filtering, generate additional pages alongside "Architecture Overview":
.github/skills/shared/drawio-diagram-conventions.md section 7e. Use a 3-column × N-row subnet grid grouped by function tier. Place resources inside subnets only when a confirmed VNet Integration or subnet delegation exists (e.g., a Managed Identity or WAF with an actual subnet association); ASPs and other resources without VNet Integration should be placed in a separate swimlane outside the VNet container — never in a scattered row at the bottom of the VNet. Add per-subnet route table icons instead of radiating edges from a central icon. Target pageWidth="1800" pageHeight="1600" — the page MUST NOT require horizontal scrolling on a 1920px display.pageWidth="1800" is sufficient.8f. Generate the diagram
Use the Draw.io MCP tool (mcp_drawio_create_diagram or mcp_draw_io_create_diagram) to create the .drawio file with the assembled XML.
Output discipline for diagram generation:
Diagram created with N resource cells and M edges.If the Draw.io MCP tool is unavailable or returns an error, write the assembled XML string to <folder-name>.drawio directly using the file system tool and note in the completion summary that the file was written without MCP validation. If both the Draw.io MCP tool and the file system tool are unavailable, report the failure to the user and stop without outputting the raw XML.
Create a solution folder containing the generated diagram and metadata.
9a. Confirm the solution folder
The solution folder was created in Step 3a. Save the diagram file here now (see Step 9b).
9b. Save the diagram
.drawio file inside the solution folder<folder-name>.drawio9c. Create original-request.md
Document the discovery in original-request.md with: source scope, subscription, discovery date, resource counts, full resource table (Resource, Type, Location), full relationship table (Source, Relationship, Target), and notes pointing to related skills (azv-bicep-diagram-sync, azv-diagram-to-bicep). Full tables go here, not in the chat response. Do not transcribe raw enrichment JSON properties — only the structured resource and relationship tables are required.
9d. Clean up intermediate files
Delete all intermediate files from the solution folder before you finish — only final deliverables should remain. This includes resource-model.json (written in Step 3b/3c), any filtered copy written in Step 4, and any extract-*.json files written during enrichment. The raw JSON properties from enrichment do not need to be transcribed to original-request.md; only the structured tables from Step 9c are required there.
9e. Present completion (concise)
Show: folder path, diagram file with resource count, original-request.md, resource/relationship/excluded counts, and next steps pointing to azv-diagram-to-bicep and azv-diagram-azure-sync.
© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/azv-azure-to-diagram of Azure/AZVerify.
Open the folder on GitHubat commit d6a2b92
Azv Azure To Diagram next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azv Azure To Diagram this skillAzure/AZVerify | 101 | — | ~5.7k | Automated safety check: Pass | MIT | |
| Azure Draw.io MCP Diagramsthomast1906/github-copilot-agent-skills | 202 | — | ~3.1k | Automated safety check: Pass | None | |
| Drawio MCP Diagrammingthomast1906/github-copilot-agent-skills | 202 | — | ~6.6k | Automated safety check: Pass | None | |
| Drawio Azuresparklabx/drawio-ai-kit | 655 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| Drawio Diagram BuilderWill-hxw/drawio-diagram-builder | 413 | — | ~5.9k | Automated safety check: Pass | MIT |
thomast1906/github-copilot-agent-skills
Creates and edits architecture diagrams through the Draw.io MCP tool, with guidance for rendering Azure icons correctly and laying out network diagrams.
thomast1906/github-copilot-agent-skills
Create and edit diagrams using the Draw.io MCP server — any shape, any vendor.
sparklabx/drawio-ai-kit
A skill your agent uses when the user asks for an Azure architecture diagram — VNet/networking, App Service, AKS, landing zone, multi-region, or any diagram built with Azure service icons.
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
Will-hxw/drawio-diagram-builder
Create, edit, replicate, and iteratively refine editable research and technical diagrams in diagrams.net/draw.io (.drawio XML) from prompts, papers, repositories, screenshots, or existing diagrams.
bahayonghang/drawio-skills
Create, edit, replicate, import, and export draw.io diagrams with an offline YAML-first workflow: architecture, network topologies, flowcharts, UML/ER, org charts, Mermaid/CSV conversion, existing…
Azure/AZVerify
Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.
Azure/AZVerify
Reverse-engineer a live Azure scope (resource group or filtered subscription) into deployment-ready, modular Bicep templates with parameter files.
Azure/AZVerify
Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.
Azure/AZVerify
Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.
Azure/AZVerify
Compare a Draw.io Azure architecture diagram against a live Azure environment to detect drift.
Azure/AZVerify
Deep-compare a Draw.io Azure architecture diagram against a live Azure environment — checks both resource existence AND every tracked configuration property (SKU, size, settings, etc.) against…
Categories
Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions. Azv Azure To Diagram is an agent skill from Azure/AZVerify, published by the product's own GitHub organization.io architecture diagram following established AzVerify conventions.
Azv Azure To Diagram fits situations like: the user wants to visualize; document existing Azure infrastructure as a diagram.
Run `npx skills add Azure/AZVerify --skill azv-azure-to-diagram -a claude-code`. Or copy the skill folder (.github/skills/azv-azure-to-diagram in Azure/AZVerify) into .claude/skills/azv-azure-to-diagram in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/AZVerify --skill azv-azure-to-diagram -a codex`. Or copy the skill folder (.github/skills/azv-azure-to-diagram in Azure/AZVerify) into .agents/skills/azv-azure-to-diagram in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/AZVerify --skill azv-azure-to-diagram -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azv-azure-to-diagram, .gemini/skills/azv-azure-to-diagram, .github/skills/azv-azure-to-diagram and .opencode/skills/azv-azure-to-diagram in your project.
Going by SKILL.md and its folder, Azv Azure To Diagram needs the command-line tools its instructions call (az and pwsh). Compatibility (from SKILL.md): Requires an authenticated Azure session (CLI, Az PowerShell, or Azure MCP)..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azv Azure To Diagram is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.7k tokens (SKILL.md is roughly 23k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Azv Azure To Diagram: Azure Draw.io MCP Diagrams (thomast1906/github-copilot-agent-skills, 202 stars), Drawio MCP Diagramming (thomast1906/github-copilot-agent-skills, 202 stars), Drawio Azure (sparklabx/drawio-ai-kit, 655 stars) and Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/AZVerify, which has 101 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 27, 2026.
Source: Azure/AZVerify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.