Apex GitHub Operations
jonathan-vella/apex
WORKFLOW SKILL — Full GitHub contribution lifecycle: branches, conventional commits, issues, PRs, Actions, releases.
Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.
$ npx skills add Azure/AZVerify --skill azv-bicep-policy-check -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/AZVerify azv-bicep-policy-check --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azv-bicep-policy-check .claude/skills/azv-bicep-policy-check && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azv-bicep-policy-check" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-policy-check into .claude/skills/azv-bicep-policy-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-policy-check", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-policy-checkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/AZVerify --skill azv-bicep-policy-check -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/AZVerify azv-bicep-policy-check --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/azv-bicep-policy-check .agents/skills/azv-bicep-policy-check && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azv-bicep-policy-check" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-policy-check into .agents/skills/azv-bicep-policy-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-policy-check", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AZVerify --skill azv-bicep-policy-check -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/AZVerify azv-bicep-policy-check --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/azv-bicep-policy-check .cursor/skills/azv-bicep-policy-check && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azv-bicep-policy-check" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-policy-check into .cursor/skills/azv-bicep-policy-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-policy-check", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/AZVerify.git --path .github/skills/azv-bicep-policy-check--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/AZVerify --skill azv-bicep-policy-check -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/AZVerify azv-bicep-policy-check --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/azv-bicep-policy-check .gemini/skills/azv-bicep-policy-check && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azv-bicep-policy-check" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-policy-check into .gemini/skills/azv-bicep-policy-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-policy-check", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/AZVerify azv-bicep-policy-checkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/AZVerify --skill azv-bicep-policy-check -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/azv-bicep-policy-check .github/skills/azv-bicep-policy-check && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azv-bicep-policy-check" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-policy-check into .github/skills/azv-bicep-policy-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-policy-check", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AZVerify --skill azv-bicep-policy-check -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/AZVerify azv-bicep-policy-check --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/azv-bicep-policy-check .opencode/skills/azv-bicep-policy-check && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azv-bicep-policy-check" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-policy-check into .opencode/skills/azv-bicep-policy-check/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-policy-check", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azv-bicep-policy-checkCheck a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.
Azv Bicep Policy Check is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment. Uses the checkPolicyRestrictions REST API for fast server-side evaluation, with a legacy CLI fallback. Produces a per-resource compliance report with remediation guidance.
Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Infrastructure as code, Backend development and REST APIs. It works with Bicep, Microsoft Azure and GitHub. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d6a2b92. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
azFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azv Bicep Policy Check loads about 4.3k tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 1,924 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/AZVerify at commit d6a2b92, republished under its MIT licence (© Azure). 1,924 words, ~4,326 tokens.
.claude/skills/azv-bicep-policy-check/SKILL.md (or your agent's skills folder).Check Bicep templates against the Azure Policy assignments active in the target environment. Reports whether each resource would be compliant, non-compliant, or requires manual evaluation — before any deployment occurs.
Input: A solution folder containing Bicep templates (main.bicep) and a .bicepparam file, plus an Azure target scope (resource group name, subscription ID). The user can specify these, or the skill will auto-discover and prompt for missing inputs.
Tools required: File system tools (read files), Terminal (for running az CLI commands)
Reference files:
.github/skills/shared/azure-resource-model.md — Shared resource metadata model definition.github/skills/shared/azure-resource-configs.md — Per-resource-type configuration schemas and auto-detection rules.github/skills/shared/data/azure-property-paths.json — Azure Property Retrieval Mapping (MCP tools, CLI fallbacks, ARM JSON paths)Shared procedures (MUST follow):
.github/skills/shared/procedures/azure-authentication.md — Azure session check procedure.github/skills/shared/procedures/bicep-parsing.md — Bicep template parsing procedureFollow the procedure in .github/skills/shared/procedures/azure-authentication.md. HARD GATE — stop if not authenticated.
Identify the solution folder, the Bicep template, the parameter file, and the target scope.
If the user specifies a folder path:
If no folder is specified:
main.bicep filemain.bicep exists in the solution folder## No Bicep Template Found
No `main.bicep` file found in `<folder-path>`.
This skill requires a Bicep template to check policy compliance.If exactly one .bicepparam file exists in the solution folder:
If multiple .bicepparam files exist:
If no .bicepparam file exists:
⚠️ No `.bicepparam` file found in `<folder-path>`. Default parameter values will be used when evaluating policy compliance.If the user specifies a resource group name:
az group show --name <name> and capture the subscription ID from the resultIf the user specifies a subscription ID:
If no scope is specified, try to infer it:
.bicepparam file: look for comments or using declarations indicating a target resource groupThe `.bicepparam` file references resource group `<name>`. Use this as the target scope? (yes/no)Which Azure resource group are you targeting for this deployment?Read the Bicep template and parameter file to build an expected resource model — what the templates declare should exist.
.bicepparam fileRead the .bicepparam file and extract all parameter values. For each param <name> = <value> line, record the name and resolved value.
main.bicep and all module filesRead main.bicep and every Bicep module it references in modules/. For each resource block, extract:
Microsoft.Web/sites)name property — resolve parameter references using the values from Step 3a where possibleStore this as the expected resource model: a list of resources, each with their type, name, and full declared properties.
If a property value references a parameter that cannot be resolved (e.g., it depends on deployment-time input), record it as <unresolved: paramName>.
Many policies (e.g., required tags) target the resource group itself (Microsoft.Resources/subscriptions/resourceGroups), not the resources inside it. The skill must check the resource group as a separate resource.
If the resource group already exists:
az group show --name <rgName> -o json to get its current tags and locationIf the resource group does not exist yet (new deployment):
name — the target resource group namelocation — the location parameter from the .bicepparam filetags — look for a resourceGroupTags or similar parameter in the .bicepparam file. If none exists, use {}Add this as the first entry in the expected resource model:
Resource: <rgName>
Type: Microsoft.Resources/subscriptions/resourceGroups
API version: 2024-03-01
Properties: { location, tags }This adds only one extra API call (~1–3 seconds) to the check, keeping total execution fast.
Use the Azure checkPolicyRestrictions REST API to evaluate each resource against all active policies in a single call per resource. This replaces sequential CLI fetches of initiatives and definitions.
Performance goal: 1 REST call per resource (typically 2–5 calls total). No initiative expansion, no definition fetching, no local rule evaluation needed — Azure does all policy evaluation server-side.
For each resource in the expected resource model (Step 3), including the resource group from Step 3c, build a resourceContent JSON object matching what would be deployed. Include:
For the resource group entry (from Step 3c):
type — Microsoft.Resources/subscriptions/resourceGroupslocation — resolved from parametersname — the target resource group nametags — resolved from parameters, or {} if none specifiedThe resource group check uses subscription-level scope (even if the RG exists), since RG creation happens at subscription level. Use:
/subscriptions/$subscriptionId/providers/Microsoft.PolicyInsights/checkPolicyRestrictions?api-version=2022-03-01
For all other resources:
type — the full resource type (e.g., Microsoft.DevCenter/devcenters)location — resolved from parametersname — resolved from parameterstags — resolved from parameters (use {} if empty/unresolved)sku — if applicablekind — if applicableproperties — the full properties bag, resolved from parameters where possibleFor properties that reference unresolved parameters, use a reasonable placeholder value and flag the resource for manual review on those properties.
CRITICAL: All resource checks MUST be executed in a single terminal command. Do NOT run separate terminal commands per resource.
Build a single PowerShell script that:
isRG = $true)az rest --method POST against the checkPolicyRestrictions endpointAPI endpoint pattern: /subscriptions/$subscriptionId[/resourceGroups/$rgName]/providers/Microsoft.PolicyInsights/checkPolicyRestrictions?api-version=2022-03-01
Each resource payload: @{ resourceDetails = @{ resourceContent = <content>; apiVersion = <version> } }
Performance: Completes in one terminal invocation taking ~5–15 seconds total (1–3 seconds per API call).
Microsoft.PolicyInsights/checkPolicyRestrictions/read permission. Fall back to the legacy approach (Step 4-fallback below).The checkPolicyRestrictions response contains two key sections:
fieldRestrictions[] — per-field value restrictions with field, restrictions[].result, restrictions[].values, policy IDs, and policyEffectcontentEvaluationResult.policyEvaluations[] — full evaluation results with evaluationResult ("NonCompliant"/"Compliant"), effectDetails.effect, and policy display namesIf the checkPolicyRestrictions API is not available (403, unsupported region, or older API version), fall back to this approach:
az policy assignment list --scope "/subscriptions/$subscriptionId" -o jsonThis fallback is slower (2–5+ minutes for environments with many assignments) but does not require the Microsoft.PolicyInsights RP.
Map the checkPolicyRestrictions API response to compliance status for each resource.
For each entry in contentEvaluationResult.policyEvaluations:
evaluationResult: "NonCompliant" + effect: "deny" → Resource would be Non-Compliant (deployment blocked)evaluationResult: "NonCompliant" + effect: "audit" → Resource would be Non-Compliant (deployment allowed but flagged)evaluationResult: "NonCompliant" + effect: "auditIfNotExists" → Needs manual review (depends on related resource existence in Azure)evaluationResult: "NonCompliant" + effect: "modify" → Modify policy active — Azure will auto-remediate post-deployment, but the value CAN be set proactively in the Bicep template. Report what the modify policy will change.evaluationResult: "NonCompliant" + effect: "deployIfNotExists" → Auto-remediated after deployment (separate resource created by policy; cannot be pre-set in Bicep)If policyEvaluations is empty or all results are compliant, the resource is Compliant.
For each entry in fieldRestrictions:
values list → Compliant for this restrictiondeny → Non-Compliant (deployment blocked)audit → Non-Compliant (flagged)<unresolved: paramName>) → Needs manual reviewCombine contentEvaluationResult and fieldRestrictions classifications. The worst status wins:
Aggregate the per-resource, per-policy evaluations into a summary compliance report.
Present a top-level summary table:
## Policy Compliance Check — <folder-name>
| # | Resource | Type | Status |
|---|----------|------|--------|
| 1 | <rgName> | Resource Group | ❌ Non-Compliant (deny) |
| 2 | <name> | <type> | ✅ Compliant |
| 3 | <name> | <type> | ⚠️ Non-Compliant (audit) |
| 4 | <name> | <type> | 🔧 Modify policy active |
| 5 | <name> | <type> | 🔄 Auto-remediated (DINE) |
| 6 | <name> | <type> | ❓ Needs manual review |
**Scope**: <resourceGroupName> (Subscription: <subscriptionName>)
**Policies evaluated**: <count> policy assignments (<count> definitions)
**Result**: <X> compliant, <Y> non-compliant (deny), <Z> non-compliant (audit), <M> modify policies active, <W> need reviewNote: The resource group itself is always checked as the first resource. Policies that target
Microsoft.Resources/subscriptions/resourceGroups(e.g., required tags on resource groups) are evaluated here. This catches tag requirements, naming conventions, and other RG-level policies that would otherwise be missed.
For each non-compliant resource, show: Policy name, Assignment, Effect, Reason, Expected vs Actual values, and Remediation guidance.
Show: Policy name, Reason (unresolvable property or condition involving related resources), and recommend az policy state list --resource <resourceId> after deployment.
Show: Policy name, Assignment, Effect (modify), what it does, fields modified (table: Field, Policy action, Value source), current Bicep value, and proactive fix suggestion (set tags/properties in .bicepparam file).
Show: Policy name, Effect (deployIfNotExists), note that no Bicep changes are required — the remediation creates a separate resource post-deployment.
Offer the user:
fix — Update Bicep templates to resolve non-compliant settings AND proactively set modify-policy valuessave report — Save compliance report as policy-compliance-report.md in the solution folderFor deny/audit non-compliant resources with deterministic fixes:
For modify policies (proactive fix):
.bicepparam with placeholder valuesFor resource group-level policies (e.g., RequireTag deny):
Report that RG creation must include required tags
If targetScope = 'subscription', add tags to the RG resource in Bicep
For non-compliant resources where the required change is not deterministic (e.g., involves unresolved parameters or complex conditions):
After all updates, present the list of changes made and suggest running azv-bicep-policy-check again to confirm
If the user replies save report (or equivalent):
policy-compliance-report.md in the solution folderSaved compliance report to `<folder>/policy-compliance-report.md`.checkPolicyRestrictions REST API (2022-03-01) for server-side evaluation (5–15 seconds for 3–5 resources). Falls back to legacy assignment-expansion approach (2–5+ min) if API returns 403.Microsoft.PolicyInsights/checkPolicyRestrictions/read permission. Most Reader/Contributor roles include this.auditIfNotExists) are marked Needs manual review. Same for unresolvable deployment-time parameters.deny (blocks deployment) > audit (flags) > modify (auto-remediates, actionable in Bicep) > deployIfNotExists (informational).azv-diagram-to-bicep run.© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/azv-bicep-policy-check of Azure/AZVerify.
Open the folder on GitHubat commit d6a2b92
Azv Bicep Policy Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azv Bicep Policy Check this skillAzure/AZVerify | 101 | — | ~4.3k | Automated safety check: Pass | MIT | |
| Apex GitHub Operationsjonathan-vella/apex | 217 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Azure Well Architected Reviewgithub/awesome-copilot | 40k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Azure Validatemicrosoft/GitHub-Copilot-for-Azure | 255 | 1 repos | ~880 | Automated safety check: Pass | MIT | |
| Azure Architecture Autopilotgithub/awesome-copilot | 40k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Azure Bicep Skilltimothywarner-org/claude-code | 224 | — | ~2.9k | Automated safety check: Pass | MIT |
jonathan-vella/apex
WORKFLOW SKILL — Full GitHub contribution lifecycle: branches, conventional commits, issues, PRs, Actions, releases.
github/awesome-copilot
Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.
microsoft/GitHub-Copilot-for-Azure
Pre-deployment validation for Azure readiness. An agent skill from microsoft/GitHub-Copilot-for-Azure.
github/awesome-copilot
Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.
timothywarner-org/claude-code
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
PSBicep/PSBicep
Update placeholders in PSBicep help markdown files. An agent skill from PSBicep/PSBicep.
Azure/AZVerify
Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.
Azure/AZVerify
Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.
Azure/AZVerify
Reverse-engineer a live Azure scope (resource group or filtered subscription) into deployment-ready, modular Bicep templates with parameter files.
Azure/AZVerify
Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.
Azure/AZVerify
Compare a Draw.io Azure architecture diagram against a live Azure environment to detect drift.
Azure/AZVerify
Deep-compare a Draw.io Azure architecture diagram against a live Azure environment — checks both resource existence AND every tracked configuration property (SKU, size, settings, etc.) against…
Works with
Categories
Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment. Azv Bicep Policy Check is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.
Azv Bicep Policy Check fits situations like: tasks that involve Infrastructure as code; tasks that involve Backend development; tasks that involve REST APIs.
Run `npx skills add Azure/AZVerify --skill azv-bicep-policy-check -a claude-code`. Or copy the skill folder (.github/skills/azv-bicep-policy-check in Azure/AZVerify) into .claude/skills/azv-bicep-policy-check in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/AZVerify --skill azv-bicep-policy-check -a codex`. Or copy the skill folder (.github/skills/azv-bicep-policy-check in Azure/AZVerify) into .agents/skills/azv-bicep-policy-check in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/AZVerify --skill azv-bicep-policy-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azv-bicep-policy-check, .gemini/skills/azv-bicep-policy-check, .github/skills/azv-bicep-policy-check and .opencode/skills/azv-bicep-policy-check in your project.
Going by SKILL.md and its folder, Azv Bicep Policy Check needs the command-line tools its instructions call (az).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azv Bicep Policy Check is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Azv Bicep Policy Check: Apex GitHub Operations (jonathan-vella/apex, 217 stars), Azure Well Architected Review (github/awesome-copilot, 40k stars), Azure Validate (microsoft/GitHub-Copilot-for-Azure, 255 stars) and Azure Architecture Autopilot (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/AZVerify, which has 101 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 27, 2026.
Source: Azure/AZVerify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.