Official agent skill

Azv Bicep Whatif

by Azure in Azure/AZVerify

Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.

OfficialMITAuto-check passedDevOps & Cloud

Install Azv Bicep Whatif

skills CLI
$ npx skills add Azure/AZVerify --skill azv-bicep-whatif -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/AZVerify azv-bicep-whatif --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azv-bicep-whatif .claude/skills/azv-bicep-whatif && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azv-bicep-whatif
GitHub stars
101
Token cost
~3.5k tokens
SKILL.md length
1,496 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.

  • Works in 7 steps: Check Azure Authentication → Accept Inputs → Parse Templates into Expected Resource… → …
  • Tasks that involve Infrastructure as code
  • Calls az

What it does

Azv Bicep Whatif is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template. Presents categorized change results (Create, Modify, Delete, No Change) without deploying anything. Does NOT use ARM what-if.

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Bicep, Microsoft Azure and GitHub. The licence is MIT.

When your agent uses it

  • Tasks that involve Infrastructure as code

Example prompts

  • “/azv-bicep-whatif”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Check Azure Authentication
  2. Accept Inputs
  3. Parse Templates into Expected Resource Model
  4. Check Resource Provider Registration
  5. Compare Models and Classify Changes
  6. Present Change Report
  7. Offer Next Steps

What it can do on your machine

Read from SKILL.md and the folder at commit d6a2b92. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azv Bicep Whatif loads about 3.5k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 1,496 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/AZVerify at commit d6a2b92, republished under its MIT licence (© Azure). 1,496 words, ~3,505 tokens.

Download SKILL.mdSave it as .claude/skills/azv-bicep-whatif/SKILL.md (or your agent's skills folder).
name
azv-bicep-whatif
description
Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template. Presents categorized change results (Create, Modify, Delete, No Change) without deploying anything. Does NOT use ARM what-if.
license
MIT
metadata.author
AzVerify
metadata.version
1.0
metadata.project
AzVerify

Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template. Reports resources that will be created, modified, deleted, or left unchanged — without using ARM what-if.

Approach: This skill does NOT use az deployment group what-if. Instead it:

  1. Parses the Bicep template and parameter file to build an expected resource model
  2. Queries Azure directly using az resource list and per-resource az <service> show commands to build an actual resource model
  3. Compares both models to identify existence-level and property-level differences

Input: A solution folder containing Bicep templates (main.bicep) and a .bicepparam file, plus an Azure target scope (resource group name or subscription ID). The user can specify these, or the skill will auto-discover and prompt for missing inputs.

Tools required: File system tools (read files), Terminal (for running az CLI commands), Azure MCP server tools

Reference files:

  • .github/skills/shared/azure-resource-model.md — Shared resource metadata model definition
  • .github/skills/shared/azure-resource-configs.md — Per-resource-type configuration schemas (useful for interpreting property changes)
  • .github/skills/shared/data/azure-property-paths.json — Azure Property Retrieval Mapping (tracked properties, ARM JSON paths, defaults, severity classifications)

Shared procedures (MUST follow):

  • .github/skills/shared/procedures/azure-authentication.md — Azure session check procedure
  • .github/skills/shared/procedures/bicep-parsing.md — Bicep template parsing procedure

Steps

1. Check Azure Authentication

Follow the procedure in .github/skills/shared/procedures/azure-authentication.md. HARD GATE — stop if not authenticated.

2. Accept Inputs

Identify the solution folder, the Bicep template, the parameter file, and the target scope.

2a. Identify the Solution Folder

If the user specifies a folder path:

  • Verify the folder exists
  • Use it as the solution folder

If no folder is specified:

  • Search the workspace for folders containing a main.bicep file
  • If exactly one is found, use it (announce which folder)
  • If multiple are found, present the list and ask the user to select one
  • If none are found, ask the user to provide a solution folder
2b. Identify the Bicep Template
  • Verify main.bicep exists in the solution folder
  • If not found, report an error:
## No Bicep Template Found

No `main.bicep` file found in `<folder-path>`.
This skill requires a Bicep template to run the what-if analysis.
  • Stop execution
2c. Identify the Parameter File

If exactly one .bicepparam file exists in the solution folder:

  • Use it as the parameter file (announce which file)

If multiple .bicepparam files exist:

  • Present the list and ask the user to select one:
## Multiple Parameter Files Found

Found multiple `.bicepparam` files in `<folder-path>`:
1. `app-dev.bicepparam`
2. `app-prod.bicepparam`

Which parameter file should I use? (1/2)
  • Wait for user selection

If no .bicepparam file exists:

  • Warn the user:
⚠️ No `.bicepparam` file found in `<folder-path>`. Default parameter values from `azure-property-paths.json` will be used as expected values.
  • Proceed without a parameter file
2d. Identify the Target Scope

If the user specifies a resource group name:

  • Use it as the target scope
  • Verify the resource group exists: run az group show --name <name> — if this fails, report an error and stop

If the user specifies a subscription ID:

  • Use it as the target scope for a subscription-level comparison

If no scope is specified, try to infer it:

  1. From the .bicepparam file: Look for a using declaration or comments indicating the target resource group
  2. If a resource group name is found, propose it:
The `.bicepparam` file references resource group `<name>`. Use this as the target scope? (yes/no)
  1. If no scope can be inferred, ask the user:
Which Azure resource group should I compare the templates against?
  • Wait for user input
3. Parse Templates into Expected Resource Model

Read the Bicep template and parameter file to build an expected resource model — what the templates declare should exist.

3a. Read and parse the .bicepparam file

Read the .bicepparam file and extract all parameter values. These are the user-specified values that override defaults. For each param <name> = <value> line, record the name and resolved value.

3b. Read and parse main.bicep and all module files

Read main.bicep and every Bicep module it references in modules/. For each resource block that is either declared inline or inside a module, extract:

  • Resource type (e.g., Microsoft.Web/sites)
  • Resource name — resolve from parameter values in the .bicepparam file if the name is a parameter reference (e.g., name: appServiceName → resolve appServiceName to its value)
  • Key properties — extract any properties that map to tracked properties in .github/skills/shared/data/azure-property-paths.json for this resource type (e.g., sku.name, properties.siteConfig.linuxFxVersion, properties.httpsOnly)
  • Relationships — note explicit references between resources (e.g., App Service → App Service Plan via serverFarmId)

For properties that reference parameters (e.g., linuxFxVersion: appServiceRuntimeStack), resolve them using the .bicepparam values. If the parameter has no value in .bicepparam, use the default from azure-property-paths.json.

3c. Build the expected resource model

Produce a structured model (as defined in .github/skills/shared/azure-resource-model.md) with all declared resources and their resolved property values. This is the "desired state" from the templates.

Display a summary of what was parsed:

## Template Resources

Parsed **N resources** from `<solution-folder>/main.bicep`:

| # | Resource | Type | Key Properties |
|---|----------|------|----------------|
| 1 | vnet-01 | Microsoft.Network/virtualNetworks | addressPrefix: 10.0.0.0/16 |
| 2 | vm-01 | Microsoft.Compute/virtualMachines | vmSize: Standard_B2s |
| 3 | webapp-azverify | Microsoft.Web/sites | runtime: DOTNET\|10.0, httpsOnly: true |
4. Check Resource Provider Registration

Before querying Azure, verify that all resource providers required by the Bicep template are registered in the active subscription. Unregistered providers will cause deployment failures.

4a. Extract required provider namespaces

From the expected resource model (Step 3), extract a unique list of top-level resource provider namespaces. Derive the namespace from each resource type by taking the first segment (e.g., Microsoft.Compute/virtualMachines → Microsoft.Compute, Microsoft.Network/virtualNetworks → Microsoft.Network).

4b. Query registered providers

Run:

bash
az provider list --query "[?registrationState=='Registered'].namespace" -o json

This returns all currently registered provider namespaces in the subscription.

4c. Compare and report

Compare the required namespaces (4a) against the registered namespaces (4b) using case-insensitive matching.

If all providers are registered:

  • Continue to Step 5 (no message needed)

If one or more providers are NOT registered:

  • Display a warning with registration commands:
## ⚠️ Unregistered Resource Providers

The following resource providers are **required by the Bicep template** but are **not registered** in subscription `<sub-name>` (`<sub-id>`). Deployment will fail unless they are registered first.

| # | Provider Namespace | Required By |
|---|-------------------|-------------|
| 1 | Microsoft.App | my-container-app (Microsoft.App/containerApps) |
| 2 | Microsoft.Cache | my-redis (Microsoft.Cache/redis) |

**To register the missing providers, run:**
```bash
az provider register --namespace Microsoft.App
az provider register --namespace Microsoft.Cache

Note: Provider registration can take a few minutes. Check status with:

bash
az provider show --namespace <namespace> --query registrationState -o tsv

- **Continue execution** — this is a warning, not a hard gate. The what-if comparison is still valuable for planning.

### 5. Query Azure for Actual Resource Model

Query the target resource group to build an **actual resource model** — what is currently deployed in Azure.

**5a. List all resources in the target scope**

Run:
```bash
az resource list --resource-group <rg-name> -o json

This returns all resources currently in the resource group. Build an initial resource model from the results.

Exclude infrastructure-only resources that are auto-created by Azure and not declared in Bicep templates:

  • Microsoft.Compute/disks that are OS disks (managed by VMs)
  • Microsoft.Network/networkInterfaces that are PE-managed NICs (where managedBy is set to a Private Endpoint)
  • Microsoft.Network/networkWatchers — auto-created by Azure
  • microsoft.alertsManagement/smartDetectorAlertRules — auto-created
  • Microsoft.Portal/dashboards — portal artifacts

5b. Retrieve full properties for each resource

For each resource, retrieve full properties using the most specific CLI command available:

  • Use resource-specific commands where available: az vm show, az webapp show, az appservice plan show, az network vnet show, az network vnet subnet show, az network nic show, az network private-endpoint show, az network private-dns zone show, az storage account show, az keyvault show, az redis show, az cosmosdb show, az sql server show, az acr show, az containerapp show
  • Fall back to az resource show --ids <resourceId> -o json for child resources or types without specific CLI commands
  • All commands use --ids <resourceId> -o json

Show progress: Querying Azure resources (1/N): vnet-01...

5c. Extract tracked properties from query results

For each resource, extract the property values that correspond to the tracked properties in azure-property-paths.json for that resource type. Use the ARM JSON paths from the mapping to navigate the JSON response.

Show full SKILL.md (440 more words)Show less
6. Compare Models and Classify Changes

Compare the expected resource model (Step 3) against the actual Azure resource model (Step 5) to classify each resource.

6a. Existence-level classification

Match resources by type AND name (case-insensitive). Classify each resource as:

  • Create — in the template but NOT in Azure (resource will be created when deployed)
  • Modify — in both template and Azure, but with property differences
  • Delete — in Azure but NOT in the template (resource would be removed if template is authoritative)
  • No Change — in both template and Azure, with all tracked properties matching

Matching rules:

  • Match by resource type and name (case-insensitive)
  • For child resources (subnets, DNS zone links, etc.), match within their parent's context
  • If only one resource of a given type exists in each model and names differ slightly, match them — report as "Modify (name differs)"

6b. Property-level comparison (for matched resources)

For resources matched in both models, compare each tracked property from azure-property-paths.json:

  1. Expected value: use the resolved value from the template (Step 3b); if not specified, use the default from azure-property-paths.json
  2. Actual value: the value retrieved from Azure (Step 5c)
  3. Apply normalization rules before comparing:
    • Case-insensitive string comparison for enum-like values (SKU names, tiers, regions)
    • Boolean normalization: true/"true"/"True" all equal true
    • Empty collection equivalence: [], null, absent → all equivalent for array properties
    • Numeric string normalization: "30" equals 30
  4. If normalized expected ≠ normalized actual, record as a property difference with:
    • Property name
    • Current value (Azure)
    • Expected value (template)
    • Severity from azure-property-paths.json

6c. Classify final change type

After property comparison, refine the classification:

  • No Change — resource exists in Azure and all tracked properties match the template
  • Modify — resource exists in Azure but one or more tracked properties differ (list the diffs)
  • Create — resource is in the template but not found in Azure
  • Delete — resource is in Azure but not in the template
7. Present Change Report

Display a categorized comparison report.

Header (always shown): Title, target scope, template/parameters paths, summary table with counts per category (🆕 Create, ✏️ Modify, 🗑️ Delete, ✅ No Change).

If no changes: Show "✅ No changes — all template resources match Azure" and stop.

Per-category sections:

  • 🆕 Create: Table of resources in template but not in Azure (columns: #, Resource, Type, Resource Group)
  • ✏️ Modify: Per-resource property diff tables (columns: Property, Current Azure Value, Template Value, Severity). Severity levels from azure-property-paths.json.
  • 🗑️ Delete: Table of resources in Azure but not in template, with warning about authoritative deployment
  • ✅ No Change: Collapsible <details> section listing matched resources
8. Offer Next Steps

If deletions detected, warn user to verify intentional exclusions and check diagram with azv-bicep-diagram-sync.

When changes exist, suggest: deploy command (az deployment group create), review Critical severity items, and sync check with azv-bicep-diagram-sync.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/azv-bicep-whatif of Azure/AZVerify.

Open the folder on GitHubat commit d6a2b92

Compare with similar skills

Azv Bicep Whatif next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azv Bicep Whatif compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azv Bicep Whatif this skillAzure/AZVerify101—~3.5kAutomated safety check: PassMIT
Apex GitHub Operationsjonathan-vella/apex217—~1.5kAutomated safety check: PassMIT
Azure Well Architected Reviewgithub/awesome-copilot40k—~2.5kAutomated safety check: PassMIT
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Update Help PlaceholdersPSBicep/PSBicep152—~299Automated safety check: PassMIT

Similar skills

  • Apex GitHub Operations

    jonathan-vella/apex

    WORKFLOW SKILL — Full GitHub contribution lifecycle: branches, conventional commits, issues, PRs, Actions, releases.

    217 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure Well Architected Review

    github/awesome-copilot

    Official

    Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

    40k GitHub stars~2.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Update placeholders in PSBicep help markdown files. An agent skill from PSBicep/PSBicep.

    152 GitHub stars~299 tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Avm Tf Classifications

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…

    135 GitHub stars~2.9k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed

More from Azure/AZVerify

All 9 skills in this repo
  • Azv Azure To Diagram

    Azure/AZVerify

    Official

    Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.

    101 GitHub stars~5.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Official

    Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.

    101 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Azv Azure To Bicep

    Azure/AZVerify

    Official

    Reverse-engineer a live Azure scope (resource group or filtered subscription) into deployment-ready, modular Bicep templates with parameter files.

    101 GitHub stars~5.4k tokensUpdated 1 mo ago
    Auto-check: warnings
  • Official

    Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.

    101 GitHub stars~4.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Official

    Compare a Draw.io Azure architecture diagram against a live Azure environment to detect drift.

    101 GitHub stars~3.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Official

    Deep-compare a Draw.io Azure architecture diagram against a live Azure environment — checks both resource existence AND every tracked configuration property (SKU, size, settings, etc.) against…

    101 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Azv Bicep Whatif

What does Azv Bicep Whatif do?

Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template. Azv Bicep Whatif is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.

When should I use Azv Bicep Whatif?

Azv Bicep Whatif fits situations like: tasks that involve Infrastructure as code.

How do I install Azv Bicep Whatif in Claude Code?

Run `npx skills add Azure/AZVerify --skill azv-bicep-whatif -a claude-code`. Or copy the skill folder (.github/skills/azv-bicep-whatif in Azure/AZVerify) into .claude/skills/azv-bicep-whatif in your project. Claude Code loads it when a task matches its description.

How do I install Azv Bicep Whatif in Codex?

Run `npx skills add Azure/AZVerify --skill azv-bicep-whatif -a codex`. Or copy the skill folder (.github/skills/azv-bicep-whatif in Azure/AZVerify) into .agents/skills/azv-bicep-whatif in your project. Codex loads it when a task matches its description.

Can I use Azv Bicep Whatif in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/AZVerify --skill azv-bicep-whatif -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azv-bicep-whatif, .gemini/skills/azv-bicep-whatif, .github/skills/azv-bicep-whatif and .opencode/skills/azv-bicep-whatif in your project.

What does Azv Bicep Whatif need to run?

Going by SKILL.md and its folder, Azv Bicep Whatif needs the command-line tools its instructions call (az).

Does Azv Bicep Whatif access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Azv Bicep Whatif safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azv Bicep Whatif use?

Azv Bicep Whatif is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azv Bicep Whatif use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azv Bicep Whatif?

Skills that share tags, products or a category with Azv Bicep Whatif: Apex GitHub Operations (jonathan-vella/apex, 217 stars), Azure Well Architected Review (github/awesome-copilot, 40k stars), Azure Architecture Autopilot (github/awesome-copilot, 40k stars) and Azure Bicep Skill (timothywarner-org/claude-code, 224 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azv Bicep Whatif?

Azure (a GitHub organization, an official publisher) maintains it in Azure/AZVerify, which has 101 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 27, 2026.

Source: Azure/AZVerify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.