Official agent skill

Azv Bicep Diagram Sync

by Azure in Azure/AZVerify

Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.

OfficialMITAuto-check passedDevOps & Cloud

Install Azv Bicep Diagram Sync

skills CLI
$ npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/AZVerify azv-bicep-diagram-sync --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azv-bicep-diagram-sync .claude/skills/azv-bicep-diagram-sync && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azv-bicep-diagram-sync
GitHub stars
101
Token cost
~2.9k tokens
SKILL.md length
952 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.

  • Works in 9 steps: Accept Inputs → Parse Diagram into Resource Model → Parse Bicep Templates into Resource Model → …
  • Tasks that involve Infrastructure as code
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Diagrams

What it does

Azv Bicep Diagram Sync is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence. Reports differences and offers resolution — update Bicep to match the diagram, update the diagram to match Bicep, or selectively resolve per resource.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code and Diagrams. It works with Bicep, draw.io, Microsoft Azure and Model Context Protocol. The licence is MIT.

When your agent uses it

  • Tasks that involve Infrastructure as code
  • Tasks that involve Diagrams

Example prompts

  • “/azv-bicep-diagram-sync”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Accept Inputs
  2. Parse Diagram into Resource Model
  3. Parse Bicep Templates into Resource Model
  4. Compare Resource Models
  5. Present Drift Report
  6. Offer Resolution Options
  7. Resolution: Update Bicep
  8. Resolution: Update Diagram
  9. Resolution: Selective

What it can do on your machine

Read from SKILL.md and the folder at commit d6a2b92. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azv Bicep Diagram Sync loads about 2.9k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 952 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/AZVerify at commit d6a2b92, republished under its MIT licence (© Azure). 952 words, ~2,851 tokens.

Download SKILL.mdSave it as .claude/skills/azv-bicep-diagram-sync/SKILL.md (or your agent's skills folder).
name
azv-bicep-diagram-sync
description
Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence. Reports differences and offers resolution — update Bicep to match the diagram, update the diagram to match Bicep, or selectively resolve per resource.
license
MIT
metadata.author
AzVerify
metadata.version
1.0
metadata.project
AzVerify

Compare Bicep templates in a solution folder against their source Draw.io diagram and resolve divergence.

Input: A solution folder containing Bicep templates (main.bicep, modules/*.bicep) and a Draw.io diagram file (.drawio or .drawio.xml). The user can specify the folder and diagram file, or the skill will auto-discover them.

Tools required: File system tools (read/write files), Draw.io MCP (mcp_drawio_create_diagram or mcp_draw_io_create_diagram), Bicep MCP server (for best-practice validation when regenerating Bicep)

Reference files:

  • .github/skills/shared/azure-resource-model.md — Shared resource metadata model definition
  • .github/skills/shared/azure-stencil-mapping.json — Azure resource type to Draw.io stencil mapping (used for reverse-lookup and diagram generation)
  • .github/skills/shared/azure-resource-configs.md — Per-resource-type configuration schemas with defaults
  • .github/skills/shared/azure-deployment-verification.md — Pre-deployment verification rules (MUST run before generating Bicep updates)

Shared procedures (MUST follow):

  • .github/skills/shared/procedures/diagram-parsing.md — Diagram-to-resource-model parsing procedure
  • .github/skills/shared/procedures/bicep-parsing.md — Bicep template parsing procedure
  • .github/skills/shared/procedures/resource-matching.md — Resource matching algorithm

Steps

1. Accept Inputs

Identify the solution folder, the Bicep templates, and the Draw.io diagram to compare.

1a. Identify the Solution Folder

If the user specifies a folder path:

  • Verify the folder exists
  • Use it as the solution folder

If no folder is specified:

  • Use the current workspace directory
  • Search for folders containing both a .drawio file and a main.bicep file
  • If exactly one such folder is found, use it (announce which folder)
  • If multiple are found, present the list and ask the user to select one
  • If none are found, ask the user to provide a solution folder
1b. Identify the Draw.io Diagram

If the user specifies a diagram file:

  • Verify the file exists and is a .drawio or .drawio.xml file
  • Read the file contents

If no diagram file is specified:

  • Search the solution folder for .drawio files
  • If exactly one is found, use it (announce which file)
  • If multiple are found, present the list and ask the user to select one
  • If none are found, report an error:
## No Diagram Found

No `.drawio` files found in the solution folder `<folder-path>`.
This skill requires a Draw.io diagram to compare against the Bicep templates.
  • Stop execution
1c. Identify the Bicep Templates
  • Search the solution folder for main.bicep
  • If found, also scan for modules/*.bicep files
  • If main.bicep is not found, report an error:
## No Bicep Templates Found

No `main.bicep` file found in the solution folder `<folder-path>`.
This skill requires Bicep templates to compare against the diagram.
  • Stop execution
2. Parse Diagram into Resource Model

Follow the procedure in .github/skills/shared/procedures/diagram-parsing.md to parse the Draw.io XML into a structured resource model.

Display the parsed resource model as a table with columns: #, Resource, Type, Container.

3. Parse Bicep Templates into Resource Model

Follow the procedure in .github/skills/shared/procedures/bicep-parsing.md to parse all .bicep files in the solution folder.

Display the parsed Bicep resource model as a table with columns: #, Resource, Type, Source File, Notes.

4. Compare Resource Models

Follow the matching procedure in .github/skills/shared/procedures/resource-matching.md to compare the diagram resource model (Step 2) against the Bicep resource model (Step 3).

Additional classifications for this skill:

  • In Sync (name differs) — single-instance type match with name mismatch
  • Bicep Only — exists in Bicep templates but not in the diagram
  • Diagram Only — exists in the diagram but not in the Bicep templates

Bicep-specific rules:

  • Container resources: VNet containers in diagram should match Microsoft.Network/virtualNetworks in Bicep
  • Conditional resources: Resources with if conditions are classified normally but noted as "conditional"
5. Present Drift Report

Display a clear drift report summarizing all differences.

Report format:

## Bicep-Diagram Sync Report: <diagram-name>

### Summary
- **In Sync:** N resources
- **Bicep Only:** N resources (in Bicep, not in diagram)
- **Diagram Only:** N resources (in diagram, not in Bicep)

### Details

| Resource | Type | Status | Notes |
|----------|------|--------|-------|
| my-vnet | VNet | ✅ In Sync | |
| my-vm | Virtual Machine | ✅ In Sync | |
| redis-cache | Redis Cache | ⬜ Bicep Only | In modules/data.bicep |
| cosmos-db | Cosmos DB | 🔷 Diagram Only | Not in Bicep templates |
| my-subnet | Subnet | ✅ In Sync (name differs) | Diagram: "default", Bicep: "snet-default" |

If fully in sync:

## Bicep-Diagram Sync Report: <diagram-name>

✅ **Fully in sync!** All N resources in the diagram match the Bicep templates.

No action needed.

If drift is detected, proceed to Step 6.

6. Offer Resolution Options

When drift is detected, present resolution options to the user.

### Resolution Options

Drift detected — how would you like to resolve it?

1. **Update Bicep** — Add diagram-only resources to Bicep templates, remove Bicep-only resources
2. **Update Diagram** — Add Bicep-only resources to diagram, remove diagram-only resources
3. **Selective** — Choose per-resource which direction to resolve
4. **No action** — Keep the report for reference, don't change anything

Which option? (1/2/3/4)

Wait for the user's choice before proceeding.

Show full SKILL.md (422 more words)Show less
7. Resolution: Update Bicep

If the user chooses to update Bicep to match the diagram:

7a. Confirm changes

## Confirm Bicep Changes

The following changes will be made to the Bicep templates:

**Add to Bicep** (Diagram-only resources):
- cosmos-db (Microsoft.DocumentDB/databaseAccounts)

**Remove from Bicep** (Bicep-only resources):
- redis-cache (Microsoft.Cache/redis) — in modules/data.bicep

⚠️ Removing resources from Bicep templates means they will no longer be part of deployments.

Proceed? (yes/no)

Wait for explicit confirmation. If the user says no, return to Step 6.

7b. Run deployment verification

Before generating Bicep, read and run the verification rules from .github/skills/shared/azure-deployment-verification.md:

  1. SKU dependency rules — verify companion resources exist
  2. Resource compatibility rules — verify backend protocols, DNS zones
  3. Networking rules — verify subnet sizing, no overlaps
  4. Security rules — verify TLS 1.2+, HTTPS, @secure() decorators
  5. Version currency rules — verify runtime stacks and API versions are current

7c. Apply Bicep changes

For Diagram-only resources (add to Bicep):

  1. Determine the appropriate module file based on resource type:
    • Networking resources → modules/networking.bicep
    • Compute resources → modules/compute.bicep
    • Data/storage resources → modules/data.bicep
    • If no matching module exists, create one
  2. Generate the resource block following the rules in .github/skills/shared/bicep-best-practices.md
  3. Use configuration defaults from .github/skills/shared/azure-resource-configs.md
  4. Add parameters to main.bicep and the .bicepparam file with descriptive comments
  5. Follow Bicep best practices: parent: for child resources, @secure(), @description(), symbolic references

For Bicep-only resources (remove from Bicep):

  1. Remove the resource block from the module file
  2. Remove associated parameters from main.bicep and the .bicepparam file
  3. Remove module references in main.bicep if the module file is now empty
  4. Remove empty module files

7d. Present result

## Bicep Updated ✓

**Added:** 1 resource (cosmos-db)
**Removed:** 1 resource (redis-cache)

The Bicep templates now match the diagram.

| File | Changes |
|------|---------|
| main.bicep | Added cosmos-db module reference; removed redis-cache reference |
| modules/data.bicep | Added Cosmos DB resource; removed Redis Cache resource |
| <name>.bicepparam | Added cosmos-db parameters; removed redis-cache parameters |

⚠️ Review the updated `.bicepparam` file — new parameters use defaults that you may want to customize.
8. Resolution: Update Diagram

If the user chooses to update the diagram to match Bicep:

8a. Confirm changes

## Confirm Diagram Changes

The following changes will be made to the diagram:

**Add to diagram** (Bicep-only resources):
- redis-cache (Redis Cache)

**Remove from diagram** (Diagram-only resources):
- cosmos-db (Cosmos DB)

⚠️ Removing resources from the diagram is irreversible unless you have a backup.

Proceed? (yes/no)

Wait for explicit confirmation. If the user says no, return to Step 6.

8b. Generate updated diagram

  1. Load the existing diagram XML
  2. For Bicep-only resources (add to diagram):
    • Look up each resource type in .github/skills/shared/azure-stencil-mapping.json for the correct icon and style
    • Add new mxCell elements with proper Azure icons
    • Place new resources in the correct container based on their module file and any parent relationships in Bicep
    • For container resources (VNets, Subnets), create both the container cell and its icon child cell using the dual icon pattern
  3. For Diagram-only resources (remove from diagram):
    • Remove the corresponding mxCell elements from the XML
    • Also remove any associated icon cells (cells with id ending in -icon)
    • Remove any edges connected to removed cells
  4. Re-layout the diagram to accommodate changes (adjust container sizes, reposition as needed)
  5. Save the updated diagram via the Draw.io MCP tool

8c. Present result

## Diagram Updated ✓

**Added:** 1 resource (redis-cache)
**Removed:** 1 resource (cosmos-db)

The diagram now matches the Bicep templates.
Saved to `<diagram-path>`.
9. Resolution: Selective

If the user chooses selective resolution:

For each drifted resource, present the options:

### Resource: cosmos-db (Cosmos DB) — Diagram Only

This resource exists in the diagram but not in the Bicep templates.

1. **Add to Bicep** — Generate a Cosmos DB resource block in modules/data.bicep
2. **Remove from Diagram** — Remove this resource from the diagram
3. **Skip** — Leave this resource unresolved

Choice? (1/2/3)

Apply the user's choice for each resource following the same logic as Steps 7 and 8.

After all resources are resolved, present a summary:

## Selective Resolution Complete ✓

| Resource | Type | Action |
|----------|------|--------|
| cosmos-db | Cosmos DB | Added to Bicep |
| redis-cache | Redis Cache | Removed from Bicep |
| old-function | Function App | Skipped |

Remaining drift: 1 resource (old-function)

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/azv-bicep-diagram-sync of Azure/AZVerify.

Open the folder on GitHubat commit d6a2b92

Compare with similar skills

Azv Bicep Diagram Sync next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azv Bicep Diagram Sync compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azv Bicep Diagram Sync this skillAzure/AZVerify101—~2.9kAutomated safety check: PassMIT
Apex GitHub Operationsjonathan-vella/apex217—~1.5kAutomated safety check: PassMIT
Azure Well Architected Reviewgithub/awesome-copilot40k—~2.5kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT
Azsdk Common Live And Recorded TestsAzure/azure-sdk-tools134—~1.5kAutomated safety check: NotesMIT

Similar skills

  • Apex GitHub Operations

    jonathan-vella/apex

    WORKFLOW SKILL — Full GitHub contribution lifecycle: branches, conventional commits, issues, PRs, Actions, releases.

    217 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure Well Architected Review

    github/awesome-copilot

    Official

    Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

    40k GitHub stars~2.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Official

    Deploy test resources and run Azure SDK tests in live, record, or playback mode.

    134 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Apex Azure Bicep Patterns

    jonathan-vella/apex

    UTILITY SKILL — Reusable Azure Bicep patterns: hub-spoke, private endpoints, diagnostics, AVM composition.

    217 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from Azure/AZVerify

All 9 skills in this repo
  • Azv Azure To Diagram

    Azure/AZVerify

    Official

    Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.

    101 GitHub stars~5.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Azv Azure To Bicep

    Azure/AZVerify

    Official

    Reverse-engineer a live Azure scope (resource group or filtered subscription) into deployment-ready, modular Bicep templates with parameter files.

    101 GitHub stars~5.4k tokensUpdated 1 mo ago
    Auto-check: warnings
  • Official

    Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.

    101 GitHub stars~4.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Azv Bicep Whatif

    Azure/AZVerify

    Official

    Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.

    101 GitHub stars~3.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Official

    Compare a Draw.io Azure architecture diagram against a live Azure environment to detect drift.

    101 GitHub stars~3.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Official

    Deep-compare a Draw.io Azure architecture diagram against a live Azure environment — checks both resource existence AND every tracked configuration property (SKU, size, settings, etc.) against…

    101 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Azv Bicep Diagram Sync

What does Azv Bicep Diagram Sync do?

Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence. Azv Bicep Diagram Sync is an agent skill from Azure/AZVerify, published by the product's own GitHub organization.io Azure architecture diagram to detect resource-level divergence.

When should I use Azv Bicep Diagram Sync?

Azv Bicep Diagram Sync fits situations like: tasks that involve Infrastructure as code; tasks that involve Diagrams.

How do I install Azv Bicep Diagram Sync in Claude Code?

Run `npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a claude-code`. Or copy the skill folder (.github/skills/azv-bicep-diagram-sync in Azure/AZVerify) into .claude/skills/azv-bicep-diagram-sync in your project. Claude Code loads it when a task matches its description.

How do I install Azv Bicep Diagram Sync in Codex?

Run `npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a codex`. Or copy the skill folder (.github/skills/azv-bicep-diagram-sync in Azure/AZVerify) into .agents/skills/azv-bicep-diagram-sync in your project. Codex loads it when a task matches its description.

Can I use Azv Bicep Diagram Sync in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azv-bicep-diagram-sync, .gemini/skills/azv-bicep-diagram-sync, .github/skills/azv-bicep-diagram-sync and .opencode/skills/azv-bicep-diagram-sync in your project.

What does Azv Bicep Diagram Sync need to run?

SKILL.md names no scripts, command-line tools or credentials: Azv Bicep Diagram Sync is instructions for the agent only.

Does Azv Bicep Diagram Sync access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Azv Bicep Diagram Sync safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azv Bicep Diagram Sync use?

Azv Bicep Diagram Sync is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azv Bicep Diagram Sync use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azv Bicep Diagram Sync?

Skills that share tags, products or a category with Azv Bicep Diagram Sync: Apex GitHub Operations (jonathan-vella/apex, 217 stars), Azure Well Architected Review (github/awesome-copilot, 40k stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars) and Azure Architecture Autopilot (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azv Bicep Diagram Sync?

Azure (a GitHub organization, an official publisher) maintains it in Azure/AZVerify, which has 101 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 27, 2026.

Source: Azure/AZVerify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.