Azure Draw.io MCP Diagrams
thomast1906/github-copilot-agent-skills
Creates and edits architecture diagrams through the Draw.io MCP tool, with guidance for rendering Azure icons correctly and laying out network diagrams.
Compare a Draw.io Azure architecture diagram against a live Azure environment to detect drift.
$ npx skills add Azure/AZVerify --skill azv-diagram-azure-sync -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/AZVerify azv-diagram-azure-sync --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azv-diagram-azure-sync .claude/skills/azv-diagram-azure-sync && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azv-diagram-azure-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-diagram-azure-sync into .claude/skills/azv-diagram-azure-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-diagram-azure-sync", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-diagram-azure-syncType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/AZVerify --skill azv-diagram-azure-sync -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/AZVerify azv-diagram-azure-sync --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/azv-diagram-azure-sync .agents/skills/azv-diagram-azure-sync && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azv-diagram-azure-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-diagram-azure-sync into .agents/skills/azv-diagram-azure-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-diagram-azure-sync", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AZVerify --skill azv-diagram-azure-sync -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/AZVerify azv-diagram-azure-sync --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/azv-diagram-azure-sync .cursor/skills/azv-diagram-azure-sync && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azv-diagram-azure-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-diagram-azure-sync into .cursor/skills/azv-diagram-azure-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-diagram-azure-sync", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/AZVerify.git --path .github/skills/azv-diagram-azure-sync--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/AZVerify --skill azv-diagram-azure-sync -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/AZVerify azv-diagram-azure-sync --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/azv-diagram-azure-sync .gemini/skills/azv-diagram-azure-sync && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azv-diagram-azure-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-diagram-azure-sync into .gemini/skills/azv-diagram-azure-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-diagram-azure-sync", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/AZVerify azv-diagram-azure-syncInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/AZVerify --skill azv-diagram-azure-sync -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/azv-diagram-azure-sync .github/skills/azv-diagram-azure-sync && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azv-diagram-azure-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-diagram-azure-sync into .github/skills/azv-diagram-azure-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-diagram-azure-sync", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/AZVerify --skill azv-diagram-azure-sync -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/AZVerify azv-diagram-azure-sync --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/azv-diagram-azure-sync .opencode/skills/azv-diagram-azure-sync && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azv-diagram-azure-sync" agent skill from https://github.com/Azure/AZVerify/tree/main/.github/skills/azv-diagram-azure-sync into .opencode/skills/azv-diagram-azure-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azv-diagram-azure-sync", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azv-diagram-azure-syncCompare a Draw.io Azure architecture diagram against a live Azure environment to detect drift.
Azv Diagram Azure Sync is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Compare a Draw.io Azure architecture diagram against a live Azure environment to detect drift. Supports quick mode (existence check) and deep mode (full property-level comparison). Reports differences and offers resolution — update the diagram, update Azure, or selectively resolve per resource.
Its SKILL.md is about 3.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Diagrams and Cloud architecture. It works with Microsoft Azure, draw.io, Model Context Protocol and GitHub. The licence is MIT.
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d6a2b92. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
azFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azv Diagram Azure Sync loads about 3.7k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 1,740 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/AZVerify at commit d6a2b92, republished under its MIT licence (© Azure). 1,740 words, ~3,678 tokens.
.claude/skills/azv-diagram-azure-sync/SKILL.md (or your agent's skills folder).Compare a Draw.io Azure architecture diagram against a live Azure environment and resolve drift. Supports two modes: quick (existence-level) and deep (existence + property-level comparison against all tracked configuration properties).
Input: A Draw.io diagram file (.drawio or .drawio.xml) and an Azure scope — a resource group name or subscription ID. The user can specify both, or the skill will prompt for missing inputs.
Tools required: File system tools (read/write files), Azure MCP server tools (mcp_azure_group_resource_list, mcp_azure_compute, mcp_azure_storage, mcp_azure_subscription_list, etc.), Draw.io MCP (mcp_drawio_create_diagram or mcp_draw_io_create_diagram)
Reference files:
.github/skills/shared/azure-resource-model.md — Shared resource metadata model definition.github/skills/shared/azure-stencil-mapping.json — Azure resource type to Draw.io stencil mapping (used for reverse-lookup and diagram generation).github/skills/shared/azure-deployment-verification.md — Pre-deployment verification rules (MUST run before generating Azure update scripts).github/skills/shared/azure-resource-configs.md — Per-resource-type configuration schemas with defaults and auto-detection rules.github/skills/shared/data/azure-property-paths.json — Azure Property Retrieval Mapping (MCP tools, CLI fallbacks, ARM JSON paths, severity classifications)Shared procedures (MUST follow):
.github/skills/shared/procedures/azure-authentication.md — Azure session check procedure.github/skills/shared/procedures/diagram-parsing.md — Diagram-to-resource-model parsing procedure.github/skills/shared/procedures/resource-matching.md — Resource matching algorithm.github/skills/shared/procedures/resource-filtering.md — Resource exclusion lists (use "Exclude for Diagrams" column)Follow the procedure in .github/skills/shared/procedures/azure-authentication.md. HARD GATE — stop if not authenticated.
Identify the Draw.io diagram, the Azure scope, and the comparison depth.
Determine the depth mode from the user's request:
azure-property-paths.jsonIf the user says "deep", "detailed", "full", "property", or "configuration" → use deep mode. Otherwise default to quick.
If the user specifies a file path:
.drawio or .drawio.xml fileIf no file is specified:
.drawio filesIf the user specifies a resource group:
If the user specifies a subscription:
If no scope is specified:
<name>. Should I compare against that resource group?"Follow the procedure in .github/skills/shared/procedures/diagram-parsing.md to parse the Draw.io XML into a structured resource model.
Display the parsed resource model as a table with columns: #, Resource, Type, Container.
Query the Azure scope to build a resource model of what is actually deployed.
Discovery process:
List all resources in scope:
mcp_azure_group_resource_list to get all resources in the specified resource groupmcp_azure_subscription_list to get subscriptions, then list resources across the target subscriptionBuild the Azure resource model: For each discovered resource, create a resource model entry:
{
"id": "<resource-name-slug>",
"type": "<Microsoft.Provider/resourceType>",
"name": "<resource-name>",
"resourceGroup": "<resource-group-name>",
"location": "<region>",
"properties": {},
"relationships": []
}Enrich with resource-type-specific details where available:
mcp_azure_compute for VM details (size, OS, status)mcp_azure_storage for Storage Account details (SKU, kind, access tier)Discover relationships:
virtualMachine property)privateLinkServiceConnections)Exclude infrastructure-only resources: Apply the "Exclude for Diagrams" column from .github/skills/shared/procedures/resource-filtering.md.
Output the Azure resource model as a table with columns: #, Resource, Type, Location.
Follow the matching algorithm in .github/skills/shared/procedures/resource-matching.md to compare diagram resources (Step 3) against Azure resources (Step 4). Use label "Diagram Only" for Model A and "Azure Only" for Model B.
Skip this step in quick mode.
For each resource matched in both models (In Sync or In Sync with name difference):
Retrieve full properties from Azure using the Azure Property Retrieval Mapping in .github/skills/shared/data/azure-property-paths.json. Use the listed MCP tool (primary) or az CLI command (fallback) for each resource type. Extract all tracked properties using the ARM JSON paths specified in the mapping.
Determine expected values: Use diagram-specified values if available; otherwise use defaults from azure-property-paths.json.
Normalize before comparing: Case-insensitive for enum values (SKUs, tiers, regions). Boolean normalization (true/"true"/"True" → true). Empty collection equivalence ([]/null/absent → equal). Numeric strings ("30" = 30). Region normalization ("West Europe" → "westeurope").
Record property drifts where normalized expected ≠ normalized actual, including property name, expected value (source: diagram/default), actual Azure value, and severity level from azure-property-paths.json.
Refine classification: Matched resources get sub-status: "all properties match" or "properties drifted" (with count per severity level).
Display a categorized drift report.
Quick mode: Summary table (In Sync / Diagram Only / Azure Only counts), details table (Resource, Type, Status, Notes). If fully in sync, show "✅ Fully in sync!" and stop.
Deep mode: Add property drift information:
If drift is detected, proceed to Step 7.
When drift is detected, present resolution options to the user.
Quick mode options: Update Diagram (1), Update Azure (2), Selective (3), No action (4).
Deep mode options (vary by drift type):
| Drift Type | Options |
|---|---|
| Existence only | Update Diagram, Update Azure, Selective, No action |
| Property only | Resolve Property Drifts, No action |
| Both | Update Diagram, Update Azure, Selective, Resolve Property Drifts, No action |
Wait for the user's choice before proceeding.
If the user chooses to update the diagram to match Azure:
8a. Confirm destructive operations
List resources to add and remove from the diagram. Warn that diagram removals are irreversible without a backup. Wait for explicit "yes" confirmation; "no" returns to Step 7.
8b. Generate updated diagram
mxCell elements with icons from .github/skills/shared/azure-stencil-mapping.json, placed in correct containers. For container resources, create both container and icon cells.mxCell, its -icon child, and any connected edges8c. Update Bicep files to match the updated diagram
If main.bicep + .bicepparam exist in the diagram's directory:
azure-resource-configs.md, bicep-best-practices.md)azure-deployment-verification.md.bicepparam values where parameters still apply; add/remove as neededmain.bicep outputsIf no Bicep files exist, skip this step.
8d. Present result
Show summary: resources added/removed from diagram, path to saved file. If Bicep was regenerated, show a table of changed Bicep files with their changes.
If the user chooses to update Azure to match the diagram:
9a. Confirm destructive operations
List resources to create and delete, warn that Azure deletions are destructive and may cause data loss. Require user to type "confirm" to proceed; any other response returns to Step 7.
9b. Run deployment verification
Before generating Bicep, read and run the full verification ruleset from .github/skills/shared/azure-deployment-verification.md:
Present verification results. Errors must be auto-fixed where possible. Do not generate code with known errors.
9c. Generate Bicep for resources to create
For diagram-only resources, generate Bicep templates using azure-resource-configs.md and bicep-best-practices.md. Generate .bicepparam with descriptive comments. Follow diagram-to-bicep conventions (parent:, @secure(), @description(), secure defaults).
9d. Generate Bicep for resources to delete
For Azure-only resources that need to be removed, generate a Bicep template that omits those resources. Note: the user can deploy this template in Complete mode to remove them, or manually delete via the Azure portal or CLI.
9e. Present output
Show a summary table of generated files (create Bicep + removal notes) with deployment commands. Warn user to review all files before deploying.
If the user chooses selective resolution:
10a. Present per-resource choices
Show a table with columns: #, Resource, Type, Status, Resolve. For each drifted resource, offer direction-specific options (Diagram Only → "Create in Azure / Remove from diagram / Skip"; Azure Only → "Add to diagram / Delete from Azure / Skip"). Wait for user decisions.
10b. Apply decisions
Group into two buckets: diagram updates (follow Step 8 flow including 8c Bicep regeneration) and Azure updates (follow Step 9 flow). Apply confirmation gates per bucket separately.
10c. Present combined result
Show what was changed in each direction and what was skipped.
If the user chooses to resolve property drifts:
11a. Present per-resource property choices: table with columns #, Property, Expected, Actual, Severity, Action (Update Azure / Accept Azure / Skip). Wait for per-property decisions.
11b. For "Update Azure" properties: generate Bicep snippets using existing references targeting only drifted properties, plus CLI command alternatives. Note VM deallocation when vmSize changes.
11c. For "Accept Azure" decisions: update .bicepparam values to match Azure actuals. Present for confirmation before writing.
11d. Show summary of all resolutions and wait for explicit confirmation before applying.
If the user chooses no action, confirm the report is for reference only and suggest related skills (azv-diagram-to-bicep, azv-sketch-to-diagram).
azure-property-paths.json with severity classification (Critical/Warning/Info) and normalization rules..github/skills/shared/procedures/resource-filtering.md.az deployment group create or New-AzResourceGroupDeployment.© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/azv-diagram-azure-sync of Azure/AZVerify.
Open the folder on GitHubat commit d6a2b92
Azv Diagram Azure Sync next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azv Diagram Azure Sync this skillAzure/AZVerify | 101 | — | ~3.7k | Automated safety check: Pass | MIT | |
| Azure Draw.io MCP Diagramsthomast1906/github-copilot-agent-skills | 202 | — | ~3.1k | Automated safety check: Pass | None | |
| Azure Well Architected Reviewgithub/awesome-copilot | 40k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Drawio Azuresparklabx/drawio-ai-kit | 655 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Drawio MCP Diagrammingthomast1906/github-copilot-agent-skills | 202 | — | ~6.6k | Automated safety check: Pass | None | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only |
thomast1906/github-copilot-agent-skills
Creates and edits architecture diagrams through the Draw.io MCP tool, with guidance for rendering Azure icons correctly and laying out network diagrams.
github/awesome-copilot
Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.
sparklabx/drawio-ai-kit
A skill your agent uses when the user asks for an Azure architecture diagram — VNet/networking, App Service, AKS, landing zone, multi-region, or any diagram built with Azure service icons.
thomast1906/github-copilot-agent-skills
Create and edit diagrams using the Draw.io MCP server — any shape, any vendor.
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
vidanov/aws-architecture-diagram-skill
Generate AWS architecture diagrams in draw.io format. An agent skill from vidanov/aws-architecture-diagram-skill.
Azure/AZVerify
Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.
Azure/AZVerify
Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.
Azure/AZVerify
Reverse-engineer a live Azure scope (resource group or filtered subscription) into deployment-ready, modular Bicep templates with parameter files.
Azure/AZVerify
Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.
Azure/AZVerify
Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.
Azure/AZVerify
Deep-compare a Draw.io Azure architecture diagram against a live Azure environment — checks both resource existence AND every tracked configuration property (SKU, size, settings, etc.) against…
Categories
Compare a Draw.io Azure architecture diagram against a live Azure environment to detect drift. Azv Diagram Azure Sync is an agent skill from Azure/AZVerify, published by the product's own GitHub organization.io Azure architecture diagram against a live Azure environment to detect drift.
Azv Diagram Azure Sync fits situations like: tasks that involve Diagrams; tasks that involve Cloud architecture.
Run `npx skills add Azure/AZVerify --skill azv-diagram-azure-sync -a claude-code`. Or copy the skill folder (.github/skills/azv-diagram-azure-sync in Azure/AZVerify) into .claude/skills/azv-diagram-azure-sync in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/AZVerify --skill azv-diagram-azure-sync -a codex`. Or copy the skill folder (.github/skills/azv-diagram-azure-sync in Azure/AZVerify) into .agents/skills/azv-diagram-azure-sync in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/AZVerify --skill azv-diagram-azure-sync -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azv-diagram-azure-sync, .gemini/skills/azv-diagram-azure-sync, .github/skills/azv-diagram-azure-sync and .opencode/skills/azv-diagram-azure-sync in your project.
Going by SKILL.md and its folder, Azv Diagram Azure Sync needs the command-line tools its instructions call (az).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Azv Diagram Azure Sync is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.7k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Azv Diagram Azure Sync: Azure Draw.io MCP Diagrams (thomast1906/github-copilot-agent-skills, 202 stars), Azure Well Architected Review (github/awesome-copilot, 40k stars), Drawio Azure (sparklabx/drawio-ai-kit, 655 stars) and Drawio MCP Diagramming (thomast1906/github-copilot-agent-skills, 202 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/AZVerify, which has 101 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 27, 2026.
Source: Azure/AZVerify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.