Apex GitHub Operations
jonathan-vella/apex
WORKFLOW SKILL — Full GitHub contribution lifecycle: branches, conventional commits, issues, PRs, Actions, releases.
Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.
$ npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/AZVerify azv-bicep-diagram-sync --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azv-bicep-diagram-sync .claude/skills/azv-bicep-diagram-sync && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azv-bicep-diagram-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-diagram-sync into .claude/skills/azv-bicep-diagram-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-diagram-sync", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-diagram-syncType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/AZVerify azv-bicep-diagram-sync --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/azv-bicep-diagram-sync .agents/skills/azv-bicep-diagram-sync && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azv-bicep-diagram-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-diagram-sync into .agents/skills/azv-bicep-diagram-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-diagram-sync", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/AZVerify azv-bicep-diagram-sync --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/azv-bicep-diagram-sync .cursor/skills/azv-bicep-diagram-sync && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azv-bicep-diagram-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-diagram-sync into .cursor/skills/azv-bicep-diagram-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-diagram-sync", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/AZVerify.git --path .github/skills/azv-bicep-diagram-sync--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/AZVerify azv-bicep-diagram-sync --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/azv-bicep-diagram-sync .gemini/skills/azv-bicep-diagram-sync && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azv-bicep-diagram-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-diagram-sync into .gemini/skills/azv-bicep-diagram-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-diagram-sync", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/AZVerify azv-bicep-diagram-syncInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/azv-bicep-diagram-sync .github/skills/azv-bicep-diagram-sync && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azv-bicep-diagram-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-diagram-sync into .github/skills/azv-bicep-diagram-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-diagram-sync", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/AZVerify azv-bicep-diagram-sync --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/azv-bicep-diagram-sync .opencode/skills/azv-bicep-diagram-sync && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azv-bicep-diagram-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-diagram-sync into .opencode/skills/azv-bicep-diagram-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-diagram-sync", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azv-bicep-diagram-syncCompare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.
Azv Bicep Diagram Sync is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence. Reports differences and offers resolution — update Bicep to match the diagram, update the diagram to match Bicep, or selectively resolve per resource.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Infrastructure as code and Diagrams. It works with Bicep, draw.io, Microsoft Azure and Model Context Protocol. The licence is MIT.
9 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d6a2b92. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azv Bicep Diagram Sync loads about 2.9k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 952 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/AZVerify at commit d6a2b92, republished under its MIT licence (© Azure). 952 words, ~2,851 tokens.
.claude/skills/azv-bicep-diagram-sync/SKILL.md (or your agent's skills folder).Compare Bicep templates in a solution folder against their source Draw.io diagram and resolve divergence.
Input: A solution folder containing Bicep templates (main.bicep, modules/*.bicep) and a Draw.io diagram file (.drawio or .drawio.xml). The user can specify the folder and diagram file, or the skill will auto-discover them.
Tools required: File system tools (read/write files), Draw.io MCP (mcp_drawio_create_diagram or mcp_draw_io_create_diagram), Bicep MCP server (for best-practice validation when regenerating Bicep)
Reference files:
.github/skills/shared/azure-resource-model.md — Shared resource metadata model definition.github/skills/shared/azure-stencil-mapping.json — Azure resource type to Draw.io stencil mapping (used for reverse-lookup and diagram generation).github/skills/shared/azure-resource-configs.md — Per-resource-type configuration schemas with defaults.github/skills/shared/azure-deployment-verification.md — Pre-deployment verification rules (MUST run before generating Bicep updates)Shared procedures (MUST follow):
.github/skills/shared/procedures/diagram-parsing.md — Diagram-to-resource-model parsing procedure.github/skills/shared/procedures/bicep-parsing.md — Bicep template parsing procedure.github/skills/shared/procedures/resource-matching.md — Resource matching algorithmIdentify the solution folder, the Bicep templates, and the Draw.io diagram to compare.
If the user specifies a folder path:
If no folder is specified:
.drawio file and a main.bicep fileIf the user specifies a diagram file:
.drawio or .drawio.xml fileIf no diagram file is specified:
.drawio files## No Diagram Found
No `.drawio` files found in the solution folder `<folder-path>`.
This skill requires a Draw.io diagram to compare against the Bicep templates.main.bicepmodules/*.bicep filesmain.bicep is not found, report an error:## No Bicep Templates Found
No `main.bicep` file found in the solution folder `<folder-path>`.
This skill requires Bicep templates to compare against the diagram.Follow the procedure in .github/skills/shared/procedures/diagram-parsing.md to parse the Draw.io XML into a structured resource model.
Display the parsed resource model as a table with columns: #, Resource, Type, Container.
Follow the procedure in .github/skills/shared/procedures/bicep-parsing.md to parse all .bicep files in the solution folder.
Display the parsed Bicep resource model as a table with columns: #, Resource, Type, Source File, Notes.
Follow the matching procedure in .github/skills/shared/procedures/resource-matching.md to compare the diagram resource model (Step 2) against the Bicep resource model (Step 3).
Additional classifications for this skill:
Bicep-specific rules:
Microsoft.Network/virtualNetworks in Bicepif conditions are classified normally but noted as "conditional"Display a clear drift report summarizing all differences.
Report format:
## Bicep-Diagram Sync Report: <diagram-name>
### Summary
- **In Sync:** N resources
- **Bicep Only:** N resources (in Bicep, not in diagram)
- **Diagram Only:** N resources (in diagram, not in Bicep)
### Details
| Resource | Type | Status | Notes |
|----------|------|--------|-------|
| my-vnet | VNet | ✅ In Sync | |
| my-vm | Virtual Machine | ✅ In Sync | |
| redis-cache | Redis Cache | ⬜ Bicep Only | In modules/data.bicep |
| cosmos-db | Cosmos DB | 🔷 Diagram Only | Not in Bicep templates |
| my-subnet | Subnet | ✅ In Sync (name differs) | Diagram: "default", Bicep: "snet-default" |If fully in sync:
## Bicep-Diagram Sync Report: <diagram-name>
✅ **Fully in sync!** All N resources in the diagram match the Bicep templates.
No action needed.If drift is detected, proceed to Step 6.
When drift is detected, present resolution options to the user.
### Resolution Options
Drift detected — how would you like to resolve it?
1. **Update Bicep** — Add diagram-only resources to Bicep templates, remove Bicep-only resources
2. **Update Diagram** — Add Bicep-only resources to diagram, remove diagram-only resources
3. **Selective** — Choose per-resource which direction to resolve
4. **No action** — Keep the report for reference, don't change anything
Which option? (1/2/3/4)Wait for the user's choice before proceeding.
If the user chooses to update Bicep to match the diagram:
7a. Confirm changes
## Confirm Bicep Changes
The following changes will be made to the Bicep templates:
**Add to Bicep** (Diagram-only resources):
- cosmos-db (Microsoft.DocumentDB/databaseAccounts)
**Remove from Bicep** (Bicep-only resources):
- redis-cache (Microsoft.Cache/redis) — in modules/data.bicep
⚠️ Removing resources from Bicep templates means they will no longer be part of deployments.
Proceed? (yes/no)Wait for explicit confirmation. If the user says no, return to Step 6.
7b. Run deployment verification
Before generating Bicep, read and run the verification rules from .github/skills/shared/azure-deployment-verification.md:
@secure() decorators7c. Apply Bicep changes
For Diagram-only resources (add to Bicep):
modules/networking.bicepmodules/compute.bicepmodules/data.bicep.github/skills/shared/bicep-best-practices.md.github/skills/shared/azure-resource-configs.mdmain.bicep and the .bicepparam file with descriptive commentsparent: for child resources, @secure(), @description(), symbolic referencesFor Bicep-only resources (remove from Bicep):
resource block from the module filemain.bicep and the .bicepparam filemain.bicep if the module file is now empty7d. Present result
## Bicep Updated ✓
**Added:** 1 resource (cosmos-db)
**Removed:** 1 resource (redis-cache)
The Bicep templates now match the diagram.
| File | Changes |
|------|---------|
| main.bicep | Added cosmos-db module reference; removed redis-cache reference |
| modules/data.bicep | Added Cosmos DB resource; removed Redis Cache resource |
| <name>.bicepparam | Added cosmos-db parameters; removed redis-cache parameters |
⚠️ Review the updated `.bicepparam` file — new parameters use defaults that you may want to customize.If the user chooses to update the diagram to match Bicep:
8a. Confirm changes
## Confirm Diagram Changes
The following changes will be made to the diagram:
**Add to diagram** (Bicep-only resources):
- redis-cache (Redis Cache)
**Remove from diagram** (Diagram-only resources):
- cosmos-db (Cosmos DB)
⚠️ Removing resources from the diagram is irreversible unless you have a backup.
Proceed? (yes/no)Wait for explicit confirmation. If the user says no, return to Step 6.
8b. Generate updated diagram
.github/skills/shared/azure-stencil-mapping.json for the correct icon and stylemxCell elements with proper Azure iconsmxCell elements from the XMLid ending in -icon)8c. Present result
## Diagram Updated ✓
**Added:** 1 resource (redis-cache)
**Removed:** 1 resource (cosmos-db)
The diagram now matches the Bicep templates.
Saved to `<diagram-path>`.If the user chooses selective resolution:
For each drifted resource, present the options:
### Resource: cosmos-db (Cosmos DB) — Diagram Only
This resource exists in the diagram but not in the Bicep templates.
1. **Add to Bicep** — Generate a Cosmos DB resource block in modules/data.bicep
2. **Remove from Diagram** — Remove this resource from the diagram
3. **Skip** — Leave this resource unresolved
Choice? (1/2/3)Apply the user's choice for each resource following the same logic as Steps 7 and 8.
After all resources are resolved, present a summary:
## Selective Resolution Complete ✓
| Resource | Type | Action |
|----------|------|--------|
| cosmos-db | Cosmos DB | Added to Bicep |
| redis-cache | Redis Cache | Removed from Bicep |
| old-function | Function App | Skipped |
Remaining drift: 1 resource (old-function)© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/azv-bicep-diagram-sync of Azure/AZVerify.
Open the folder on GitHubat commit d6a2b92
Azv Bicep Diagram Sync next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azv Bicep Diagram Sync this skillAzure/AZVerify | 101 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Apex GitHub Operationsjonathan-vella/apex | 217 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Azure Well Architected Reviewgithub/awesome-copilot | 40k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| Azure Architecture Autopilotgithub/awesome-copilot | 40k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Azsdk Common Live And Recorded TestsAzure/azure-sdk-tools | 134 | — | ~1.5k | Automated safety check: Notes | MIT |
jonathan-vella/apex
WORKFLOW SKILL — Full GitHub contribution lifecycle: branches, conventional commits, issues, PRs, Actions, releases.
github/awesome-copilot
Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
github/awesome-copilot
Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.
Azure/azure-sdk-tools
Deploy test resources and run Azure SDK tests in live, record, or playback mode.
jonathan-vella/apex
UTILITY SKILL — Reusable Azure Bicep patterns: hub-spoke, private endpoints, diagnostics, AVM composition.
Azure/AZVerify
Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.
Azure/AZVerify
Reverse-engineer a live Azure scope (resource group or filtered subscription) into deployment-ready, modular Bicep templates with parameter files.
Azure/AZVerify
Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.
Azure/AZVerify
Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.
Azure/AZVerify
Compare a Draw.io Azure architecture diagram against a live Azure environment to detect drift.
Azure/AZVerify
Deep-compare a Draw.io Azure architecture diagram against a live Azure environment — checks both resource existence AND every tracked configuration property (SKU, size, settings, etc.) against…
Categories
Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence. Azv Bicep Diagram Sync is an agent skill from Azure/AZVerify, published by the product's own GitHub organization.io Azure architecture diagram to detect resource-level divergence.
Azv Bicep Diagram Sync fits situations like: tasks that involve Infrastructure as code; tasks that involve Diagrams.
Run `npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a claude-code`. Or copy the skill folder (.github/skills/azv-bicep-diagram-sync in Azure/AZVerify) into .claude/skills/azv-bicep-diagram-sync in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a codex`. Or copy the skill folder (.github/skills/azv-bicep-diagram-sync in Azure/AZVerify) into .agents/skills/azv-bicep-diagram-sync in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/AZVerify --skill azv-bicep-diagram-sync -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azv-bicep-diagram-sync, .gemini/skills/azv-bicep-diagram-sync, .github/skills/azv-bicep-diagram-sync and .opencode/skills/azv-bicep-diagram-sync in your project.
SKILL.md names no scripts, command-line tools or credentials: Azv Bicep Diagram Sync is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azv Bicep Diagram Sync is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Azv Bicep Diagram Sync: Apex GitHub Operations (jonathan-vella/apex, 217 stars), Azure Well Architected Review (github/awesome-copilot, 40k stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars) and Azure Architecture Autopilot (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/AZVerify, which has 101 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 27, 2026.
Source: Azure/AZVerify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.