Install the "azv-bicep-whatif" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-whatif into .claude/skills/azv-bicep-whatif/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-whatif", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add Azure/AZVerify --skill azv-bicep-whatif -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "azv-bicep-whatif" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-whatif into .agents/skills/azv-bicep-whatif/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-whatif", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Azure/AZVerify --skill azv-bicep-whatif -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "azv-bicep-whatif" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-whatif into .cursor/skills/azv-bicep-whatif/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-whatif", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add Azure/AZVerify --skill azv-bicep-whatif -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "azv-bicep-whatif" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-whatif into .gemini/skills/azv-bicep-whatif/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-whatif", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add Azure/AZVerify --skill azv-bicep-whatif -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "azv-bicep-whatif" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-whatif into .github/skills/azv-bicep-whatif/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-whatif", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add Azure/AZVerify --skill azv-bicep-whatif -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "azv-bicep-whatif" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-bicep-whatif into .opencode/skills/azv-bicep-whatif/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-bicep-whatif", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Facts
Skill name
azv-bicep-whatif
GitHub stars
101
Token cost
~3.5k tokens
SKILL.md length
1,496 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT
At a glance
Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.
Works in 7 steps: Check Azure Authentication → Accept Inputs → Parse Templates into Expected Resource… → …
Tasks that involve Infrastructure as code
Calls az
What it does
Azv Bicep Whatif is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template. Presents categorized change results (Create, Modify, Delete, No Change) without deploying anything. Does NOT use ARM what-if.
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Infrastructure as code. It works with Bicep, Microsoft Azure and GitHub. The licence is MIT.
When your agent uses it
Tasks that involve Infrastructure as code
Example prompts
“/azv-bicep-whatif”
Workflow steps
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d6a2b92. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Shell commands in SKILL.md call:
az
From the folder's file list and the shell code blocks in SKILL.md.
Network
No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Azv Bicep Whatif loads about 3.5k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 1,496 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~65
When it runs· the whole SKILL.md, loaded when a task matches
~3.5k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/azv-bicep-whatif/SKILL.md (or your agent's skills folder).
name
azv-bicep-whatif
description
Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template. Presents categorized change results (Create, Modify, Delete, No Change) without deploying anything. Does NOT use ARM what-if.
license
MIT
metadata.author
AzVerify
metadata.version
1.0
metadata.project
AzVerify
Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template. Reports resources that will be created, modified, deleted, or left unchanged — without using ARM what-if.
Approach: This skill does NOT use az deployment group what-if. Instead it:
Parses the Bicep template and parameter file to build an expected resource model
Queries Azure directly using az resource list and per-resource az <service> show commands to build an actual resource model
Compares both models to identify existence-level and property-level differences
Input: A solution folder containing Bicep templates (main.bicep) and a .bicepparam file, plus an Azure target scope (resource group name or subscription ID). The user can specify these, or the skill will auto-discover and prompt for missing inputs.
Tools required: File system tools (read files), Terminal (for running az CLI commands), Azure MCP server tools
Reference files:
.github/skills/shared/azure-resource-model.md — Shared resource metadata model definition
.github/skills/shared/azure-resource-configs.md — Per-resource-type configuration schemas (useful for interpreting property changes)
Follow the procedure in .github/skills/shared/procedures/azure-authentication.md. HARD GATE — stop if not authenticated.
2. Accept Inputs
Identify the solution folder, the Bicep template, the parameter file, and the target scope.
2a. Identify the Solution Folder
If the user specifies a folder path:
Verify the folder exists
Use it as the solution folder
If no folder is specified:
Search the workspace for folders containing a main.bicep file
If exactly one is found, use it (announce which folder)
If multiple are found, present the list and ask the user to select one
If none are found, ask the user to provide a solution folder
2b. Identify the Bicep Template
Verify main.bicep exists in the solution folder
If not found, report an error:
## No Bicep Template Found
No `main.bicep` file found in `<folder-path>`.
This skill requires a Bicep template to run the what-if analysis.
Stop execution
2c. Identify the Parameter File
If exactly one .bicepparam file exists in the solution folder:
Use it as the parameter file (announce which file)
If multiple .bicepparam files exist:
Present the list and ask the user to select one:
## Multiple Parameter Files Found
Found multiple `.bicepparam` files in `<folder-path>`:
1. `app-dev.bicepparam`
2. `app-prod.bicepparam`
Which parameter file should I use? (1/2)
Wait for user selection
If no .bicepparam file exists:
Warn the user:
⚠️ No `.bicepparam` file found in `<folder-path>`. Default parameter values from `azure-property-paths.json` will be used as expected values.
Proceed without a parameter file
2d. Identify the Target Scope
If the user specifies a resource group name:
Use it as the target scope
Verify the resource group exists: run az group show --name <name> — if this fails, report an error and stop
If the user specifies a subscription ID:
Use it as the target scope for a subscription-level comparison
If no scope is specified, try to infer it:
From the .bicepparam file: Look for a using declaration or comments indicating the target resource group
If a resource group name is found, propose it:
The `.bicepparam` file references resource group `<name>`. Use this as the target scope? (yes/no)
If no scope can be inferred, ask the user:
Which Azure resource group should I compare the templates against?
Wait for user input
3. Parse Templates into Expected Resource Model
Read the Bicep template and parameter file to build an expected resource model — what the templates declare should exist.
3a. Read and parse the .bicepparam file
Read the .bicepparam file and extract all parameter values. These are the user-specified values that override defaults. For each param <name> = <value> line, record the name and resolved value.
3b. Read and parse main.bicep and all module files
Read main.bicep and every Bicep module it references in modules/. For each resource block that is either declared inline or inside a module, extract:
Resource type (e.g., Microsoft.Web/sites)
Resource name — resolve from parameter values in the .bicepparam file if the name is a parameter reference (e.g., name: appServiceName → resolve appServiceName to its value)
Key properties — extract any properties that map to tracked properties in .github/skills/shared/data/azure-property-paths.json for this resource type (e.g., sku.name, properties.siteConfig.linuxFxVersion, properties.httpsOnly)
Relationships — note explicit references between resources (e.g., App Service → App Service Plan via serverFarmId)
For properties that reference parameters (e.g., linuxFxVersion: appServiceRuntimeStack), resolve them using the .bicepparam values. If the parameter has no value in .bicepparam, use the default from azure-property-paths.json.
3c. Build the expected resource model
Produce a structured model (as defined in .github/skills/shared/azure-resource-model.md) with all declared resources and their resolved property values. This is the "desired state" from the templates.
Before querying Azure, verify that all resource providers required by the Bicep template are registered in the active subscription. Unregistered providers will cause deployment failures.
4a. Extract required provider namespaces
From the expected resource model (Step 3), extract a unique list of top-level resource provider namespaces. Derive the namespace from each resource type by taking the first segment (e.g., Microsoft.Compute/virtualMachines → Microsoft.Compute, Microsoft.Network/virtualNetworks → Microsoft.Network).
4b. Query registered providers
Run:
bash
az provider list --query "[?registrationState=='Registered'].namespace" -o json
This returns all currently registered provider namespaces in the subscription.
4c. Compare and report
Compare the required namespaces (4a) against the registered namespaces (4b) using case-insensitive matching.
If all providers are registered:
Continue to Step 5 (no message needed)
If one or more providers are NOT registered:
Display a warning with registration commands:
## ⚠️ Unregistered Resource Providers
The following resource providers are **required by the Bicep template** but are **not registered** in subscription `<sub-name>` (`<sub-id>`). Deployment will fail unless they are registered first.
| # | Provider Namespace | Required By |
|---|-------------------|-------------|
| 1 | Microsoft.App | my-container-app (Microsoft.App/containerApps) |
| 2 | Microsoft.Cache | my-redis (Microsoft.Cache/redis) |
**To register the missing providers, run:**
```bash
az provider register --namespace Microsoft.App
az provider register --namespace Microsoft.Cache
Note: Provider registration can take a few minutes. Check status with:
bash
az provider show --namespace <namespace> --query registrationState -o tsv
- **Continue execution** — this is a warning, not a hard gate. The what-if comparison is still valuable for planning.
### 5. Query Azure for Actual Resource Model
Query the target resource group to build an **actual resource model** — what is currently deployed in Azure.
**5a. List all resources in the target scope**
Run:
```bash
az resource list --resource-group <rg-name> -o json
This returns all resources currently in the resource group. Build an initial resource model from the results.
Exclude infrastructure-only resources that are auto-created by Azure and not declared in Bicep templates:
Microsoft.Compute/disks that are OS disks (managed by VMs)
Microsoft.Network/networkInterfaces that are PE-managed NICs (where managedBy is set to a Private Endpoint)
Microsoft.Network/networkWatchers — auto-created by Azure
For each resource, retrieve full properties using the most specific CLI command available:
Use resource-specific commands where available: az vm show, az webapp show, az appservice plan show, az network vnet show, az network vnet subnet show, az network nic show, az network private-endpoint show, az network private-dns zone show, az storage account show, az keyvault show, az redis show, az cosmosdb show, az sql server show, az acr show, az containerapp show
Fall back to az resource show --ids <resourceId> -o json for child resources or types without specific CLI commands
All commands use --ids <resourceId> -o json
Show progress: Querying Azure resources (1/N): vnet-01...
5c. Extract tracked properties from query results
For each resource, extract the property values that correspond to the tracked properties in azure-property-paths.json for that resource type. Use the ARM JSON paths from the mapping to navigate the JSON response.
Show full SKILL.md (440 more words)Show less
6. Compare Models and Classify Changes
Compare the expected resource model (Step 3) against the actual Azure resource model (Step 5) to classify each resource.
6a. Existence-level classification
Match resources by type AND name (case-insensitive). Classify each resource as:
Create — in the template but NOT in Azure (resource will be created when deployed)
Modify — in both template and Azure, but with property differences
Delete — in Azure but NOT in the template (resource would be removed if template is authoritative)
No Change — in both template and Azure, with all tracked properties matching
Matching rules:
Match by resource type and name (case-insensitive)
For child resources (subnets, DNS zone links, etc.), match within their parent's context
If only one resource of a given type exists in each model and names differ slightly, match them — report as "Modify (name differs)"
Azv Bicep Whatif next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.
Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.
A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…
Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.
Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.
Deep-compare a Draw.io Azure architecture diagram against a live Azure environment — checks both resource existence AND every tracked configuration property (SKU, size, settings, etc.) against…
Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template. Azv Bicep Whatif is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.
When should I use Azv Bicep Whatif?
Azv Bicep Whatif fits situations like: tasks that involve Infrastructure as code.
How do I install Azv Bicep Whatif in Claude Code?
Run `npx skills add Azure/AZVerify --skill azv-bicep-whatif -a claude-code`. Or copy the skill folder (.github/skills/azv-bicep-whatif in Azure/AZVerify) into .claude/skills/azv-bicep-whatif in your project. Claude Code loads it when a task matches its description.
How do I install Azv Bicep Whatif in Codex?
Run `npx skills add Azure/AZVerify --skill azv-bicep-whatif -a codex`. Or copy the skill folder (.github/skills/azv-bicep-whatif in Azure/AZVerify) into .agents/skills/azv-bicep-whatif in your project. Codex loads it when a task matches its description.
Can I use Azv Bicep Whatif in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/AZVerify --skill azv-bicep-whatif -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azv-bicep-whatif, .gemini/skills/azv-bicep-whatif, .github/skills/azv-bicep-whatif and .opencode/skills/azv-bicep-whatif in your project.
What does Azv Bicep Whatif need to run?
Going by SKILL.md and its folder, Azv Bicep Whatif needs the command-line tools its instructions call (az).
Does Azv Bicep Whatif access the network?
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Is Azv Bicep Whatif safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Azv Bicep Whatif use?
Azv Bicep Whatif is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Azv Bicep Whatif use?
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
What are the alternatives to Azv Bicep Whatif?
Skills that share tags, products or a category with Azv Bicep Whatif: Apex GitHub Operations (jonathan-vella/apex, 217 stars), Azure Well Architected Review (github/awesome-copilot, 40k stars), Azure Architecture Autopilot (github/awesome-copilot, 40k stars) and Azure Bicep Skill (timothywarner-org/claude-code, 224 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Azv Bicep Whatif?
Azure (a GitHub organization, an official publisher) maintains it in Azure/AZVerify, which has 101 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 27, 2026.
Source: Azure/AZVerify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.