Official agent skill

Azv Diagram To Bicep

by Azure in Azure/AZVerify

Generate deployment-ready Bicep templates and PowerShell scripts from an approved Draw.io Azure architecture diagram.

OfficialMITAuto-check: warningsDevOps & Cloud

Install Azv Diagram To Bicep

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add Azure/AZVerify --skill azv-diagram-to-bicep -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/AZVerify azv-diagram-to-bicep --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/AZVerify.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/azv-diagram-to-bicep .claude/skills/azv-diagram-to-bicep && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azv-diagram-to-bicep
GitHub stars
101
Token cost
~3.1k tokens
SKILL.md length
1,080 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

Generate deployment-ready Bicep templates and PowerShell scripts from an approved Draw.io Azure architecture diagram.

  • Works in 6 steps: Accept Draw.io Diagram Input → Parse Diagram into Resource Model → Check for Existing Bicepparam File → …
  • Tasks that involve Infrastructure as code
  • Calls az
  • Tasks that involve Diagrams

What it does

Azv Diagram To Bicep is an agent skill from Azure/AZVerify, published by the product's own GitHub organization. Generate deployment-ready Bicep templates and PowerShell scripts from an approved Draw.io Azure architecture diagram. Parses the diagram, generates a user-editable .bicepparam file with descriptive comments, validates against Azure constraints, and outputs modular Bicep with deployment scripts.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code, Diagrams and Cloud architecture. It works with Bicep, Microsoft Azure, draw.io and GitHub. The licence is MIT.

When your agent uses it

  • Tasks that involve Infrastructure as code
  • Tasks that involve Diagrams
  • Tasks that involve Cloud architecture

Example prompts

  • “/azv-diagram-to-bicep”

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Accept Draw.io Diagram Input
  2. Parse Diagram into Resource Model
  3. Check for Existing Bicepparam File
  4. Generate Bicep Templates and Bicepparam File
  5. Validate Generated Bicep
  6. Write README and Present Output Summary

What it can do on your machine

Read from SKILL.md and the folder at commit d6a2b92. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azv Diagram To Bicep loads about 3.1k tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 1,080 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningTells the agent its actions are pre-authorized / not to stop for confirmationSKILL.md:65
    y or hold them for a combined response. Do not wait for user confirmation — the `.bicepparam` file is the user-editable

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/AZVerify at commit d6a2b92, republished under its MIT licence (© Azure). 1,080 words, ~3,061 tokens.

Download SKILL.mdSave it as .claude/skills/azv-diagram-to-bicep/SKILL.md (or your agent's skills folder).
name
azv-diagram-to-bicep
description
Generate deployment-ready Bicep templates and PowerShell scripts from an approved Draw.io Azure architecture diagram. Parses the diagram, generates a user-editable .bicepparam file with descriptive comments, validates against Azure constraints, and outputs modular Bicep with deployment scripts.
license
MIT
metadata.author
AzVerify
metadata.version
1.0
metadata.project
AzVerify

Generate Bicep templates and PowerShell deployment scripts from a Draw.io Azure architecture diagram.

Input: A Draw.io diagram file (.drawio or .drawio.xml) in the workspace. The user can specify the file path, or the skill will look for .drawio files in the workspace.

Tools required: File system tools (read/write files), Bicep MCP server (for best-practice validation)

Reference files:

  • .github/skills/shared/azure-resource-model.md — Shared resource metadata model definition
  • .github/skills/shared/azure-stencil-mapping.json — Azure resource type to Draw.io stencil mapping (used for reverse-lookup: image path → resource type)
  • .github/skills/shared/azure-resource-configs.md — Per-resource-type configuration schemas and auto-detection rules
  • .github/skills/shared/data/azure-property-paths.json — Azure Property Retrieval Mapping (MCP tools, CLI fallbacks, ARM JSON paths, defaults)
  • .github/skills/shared/azure-deployment-verification.md — Pre-deployment verification rules (MUST run before presenting results)

Shared procedures (MUST follow):

  • .github/skills/shared/bicep-best-practices.md — Bicep generation rules, defaults, and security settings (MUST read before generating Bicep)
  • .github/skills/shared/version-currency.md — Version verification rules (MUST verify before generating code)
  • .github/skills/shared/procedures/diagram-parsing.md — Diagram-to-resource-model parsing procedure


Steps

1. Accept Draw.io Diagram Input

Identify the Draw.io diagram to process.

If the user specifies a file path:

  • Verify the file exists and is a .drawio or .drawio.xml file
  • Read the file contents

If no file is specified:

  • Search the workspace for .drawio files
  • If exactly one is found, use it (announce which file)
  • If multiple are found, present the list and ask the user to select one
  • If none are found, ask the user to provide a diagram file
2. Parse Diagram into Resource Model

Follow the procedure in .github/skills/shared/procedures/diagram-parsing.md to parse the Draw.io XML into a structured resource model.

Display the parsed resource model as a table with columns: #, Resource, Type, Container, plus any connections.

3. Check for Existing Bicepparam File

Before generating new files, check if infrastructure already exists:

  1. Look for a file named <diagram-name>.bicepparam in the same directory as the Draw.io file
  2. If found: Load it, identify any new resources from the diagram not yet represented, and present a summary. Merge new parameters with the user's existing values preserved.
  3. If not found: Proceed to generate everything fresh (Step 4)
4. Generate Bicep Templates and Bicepparam File

Generate and write each file to disk immediately as it is produced — do not accumulate file contents in memory or hold them for a combined response. Do not wait for user confirmation — the .bicepparam file is the user-editable configuration, and the user can modify it and redeploy at any time.

Critical — response verbosity rule: After writing each file, emit only a single confirmation line (e.g., ✓ Written: modules/networking.bicep). Do not echo file contents back into the response. This prevents hitting response length limits on complex diagrams.

Use the schemas defined in .github/skills/shared/azure-resource-configs.md for per-resource defaults and the rules in .github/skills/shared/bicep-best-practices.md for Bicep structure.

Output structure:

<solution-folder>/
├── main.bicep                    # Entry point — orchestrates all modules
├── <diagram-name>.bicepparam     # User-editable parameter values with comments
└── modules/
    ├── networking.bicep          # VNets, subnets, NSGs, peerings, private endpoints
    ├── compute.bicep             # VMs, App Services, Container Apps
    └── data.bicep                # SQL, Cosmos DB, Storage, Key Vault

Bicep generation rules:

  1. main.bicep:

    • targetScope = 'resourceGroup'
    • Declare all parameters with @description() decorators explaining each setting
    • Include @allowed() where a fixed set of values applies (e.g., environment names)
    • Use default values on parameters where a sensible default exists
    • Mark sensitive parameters with @secure() (passwords, keys, connection strings)
    • Module references for each category — omit the name field on module blocks
    • Outputs for key resource IDs and endpoints
  2. Module files (networking.bicep, compute.bicep, data.bicep):

    • Only generate modules that have resources (skip empty categories)
    • Use parent: property for child resources (e.g., subnets under VNet) — never / in name
    • Add existing resource blocks when referencing a parent not declared in the same file
    • Use symbolic references (foo.id) instead of resourceId()
    • Use secure defaults: httpsOnly: true, minimumTlsVersion: '1.2', publicNetworkAccess: 'Disabled' where private endpoints exist
    • Use user-defined types instead of open array/object where appropriate
  3. <diagram-name>.bicepparam:

    • using 'main.bicep'
    • Include all parameter values
    • Add comments above each parameter or group explaining:
      • What the setting controls in plain language
      • 2-3 common alternatives with a one-line description
      • Cost impact where relevant (e.g., "$30/mo" vs "$140/mo")
      • Capacity/scaling consequences (e.g., "A /24 gives 251 usable IPs")
      • Security consequences where applicable
    • Use readEnvironmentVariable() for sensitive values (passwords, keys)
    • Keep each comment block to 1-3 lines — concise, not exhaustive
  4. Parameter naming: Use camelCase, descriptive names (e.g., vmSize, appServicePlanSkuName, vnetAddressPrefix)

File write order (write and confirm each before moving to the next):

  1. modules/networking.bicep (if networking resources exist)
  2. modules/compute.bicep (if compute resources exist)
  3. modules/data.bicep (if data resources exist)
  4. Any additional module files (e.g., modules/identity.bicep, modules/monitoring.bicep)
  5. main.bicep
  6. <diagram-name>.bicepparam

Bicepparam comment guidelines:

bicep
using 'main.bicep'

// Azure region for all resources. Options: eastus, westeurope, westus2, northeurope
param location = 'eastus'

// VNet address space. /16 gives room for many subnets; /24 limits to ~251 hosts total.
param vnetAddressPrefixes = ['10.0.0.0/16']

// VM size — controls CPU, memory, cost.
//   Standard_B2s    → 2 vCPU, 4 GB  (~$30/mo) — dev/test
//   Standard_D2s_v3 → 2 vCPU, 8 GB  (~$70/mo) — general workloads
//   Standard_D4s_v3 → 4 vCPU, 16 GB (~$140/mo) — heavier workloads
param vmSize = 'Standard_B2s'

Rules for defaults:

  • Use cost-effective defaults (e.g., Standard_B2s for VMs, S1 for App Service Plans, Standard_LRS for Storage)
  • Default region: eastus
  • Enable secure defaults: HTTPS only, TLS 1.2 minimum, deny public access where private endpoints exist
  • Do NOT default to production-scale settings — prefer dev/test sizing that can be scaled up
  • Version currency — always verify runtime stacks, API versions, and OS images are current before using them (see "Version Currency" section above). Never blindly copy defaults from reference files without checking they are still current.
Show full SKILL.md (300 more words)Show less
5. Validate Generated Bicep

After generating all files, run the full verification ruleset defined in .github/skills/shared/azure-deployment-verification.md. This is mandatory — do not skip or partially run verification.

Read the shared verification reference and check every applicable rule category:

  1. SKU dependency rules — e.g., WAF_v2 requires a WAF policy, VNet integration requires Standard+ App Service Plan
  2. Resource compatibility rules — e.g., backend protocol matches, private DNS zones match service type
  3. Networking rules — e.g., no subnet overlap, dedicated subnets for App Gateway/Firewall/Bastion
  4. Security rules — e.g., TLS 1.2+, HTTPS enforced, @secure() decorators, public access disabled with private endpoints
  5. Regional availability rules — e.g., resource/SKU availability, capacity constraints, paired region suggestions
  6. Version currency rules — e.g., runtime stacks current, API versions latest stable, Kubernetes supported

Also verify:

  • Bicep best practices: Confirm all generated Bicep follows the Bicep MCP best-practice rules
  • Missing dependencies: Flag resources that need other resources not in the diagram (e.g., a VM without a NIC — add it automatically)

Present results as a compact summary only — list each check category with a pass/fail status and a one-line note per issue. Do not reproduce file contents or full rule descriptions in the response. Errors must be auto-fixed by updating the already-written file on disk (re-write the affected file and confirm ✓ Fixed: <filename>). Do not present generated code that contains known errors.

6. Write README and Present Output Summary

Write a README.md to the output root directory (alongside main.bicep) containing:

  • Source (diagram file path)
  • Generated date
  • Pre-deployment verification results (pass/warning/error counts and details)
  • Generated Files table (file path + description for every generated file)
  • Deployment commands (az deployment group create and New-AzResourceGroupDeployment examples with a placeholder resource group)
  • Next Steps section: edit .bicepparam to set real values, related skills (azv-bicep-whatif, azv-bicep-diagram-sync, azv-bicep-policy-check)

After writing the README, present the same summary in the chat response:

## Infrastructure Code Generated

**Source diagram:** webapp-private-endpoint-vm/webapp-private-endpoint-vm.drawio
**Output directory:** webapp-private-endpoint-vm/

### Generated Files
| File | Description |
|------|-------------|
| main.bicep | Entry point — 3 module references, all params with @description |
| <diagram-name>.bicepparam | User-editable parameter values with comments |
| modules/networking.bicep | VNet, 2 subnets, private endpoint |
| modules/compute.bicep | VM, App Service + Plan |

### Customize
Edit `<diagram-name>.bicepparam` to change any deployment settings.
Each parameter has comments explaining the setting, alternatives, and cost.

### Deploy
```powershell
az deployment group create --resource-group "my-rg" --template-file main.bicep --parameters @<diagram-name>.bicepparam

---

## Important Notes

- This skill operates **independently** — it does not require sketch-to-diagram or diagram-azure-sync.
- The `.bicepparam` file is the persistent, user-editable source of truth for deployment settings. The user can open it in any editor, change values, and redeploy. Each parameter has comments explaining what it does and the consequences of changing it.
- Files are written to disk **one at a time** as they are generated — do not accumulate content in the response. Each file emits only a single `✓ Written:` confirmation line. This keeps responses within length limits for complex diagrams.
- Generated Bicep uses **secure defaults** — HTTPS only, TLS 1.2+, public access disabled where private endpoints are present.
- Bicep modules are only generated for categories that have resources (no empty module files).
- All generated Bicep MUST follow the best practices from the Bicep MCP server (`get_bicep_best_practices`). Call this tool before generating code.
- Reference `.github/skills/shared/azure-stencil-mapping.json` for icon-to-resource-type reverse lookups during diagram parsing.
- Reference `.github/skills/shared/azure-resource-configs.md` for per-resource-type configuration schemas and defaults.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/azv-diagram-to-bicep of Azure/AZVerify.

Open the folder on GitHubat commit d6a2b92

Compare with similar skills

Azv Diagram To Bicep next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azv Diagram To Bicep compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azv Diagram To Bicep this skillAzure/AZVerify101—~3.1kAutomated safety check: WarnMIT
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT
Azure Well Architected Reviewgithub/awesome-copilot40k—~2.5kAutomated safety check: PassMIT
Azure Diagramscmb211087/azure-diagrams-skill150—~4kAutomated safety check: NotesMIT
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Apex Azure Bicep Patternsjonathan-vella/apex217—~2.5kAutomated safety check: PassMIT

Similar skills

  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Azure Well Architected Review

    github/awesome-copilot

    Official

    Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

    40k GitHub stars~2.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Azure Diagrams

    cmb211087/azure-diagrams-skill

    Comprehensive technical diagramming toolkit for solutions architects, presales, and developers.

    150 GitHub stars~4k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: notes
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Apex Azure Bicep Patterns

    jonathan-vella/apex

    UTILITY SKILL — Reusable Azure Bicep patterns: hub-spoke, private endpoints, diagnostics, AVM composition.

    217 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Architecture Diagram

    awslabs/agent-plugins

    Official

    Generate validated AWS architecture diagrams as draw.io XML using official AWS4 icon libraries.

    916 GitHub stars~3.8k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from Azure/AZVerify

All 9 skills in this repo
  • Azv Azure To Diagram

    Azure/AZVerify

    Official

    Reverse-engineer a live Azure scope (resource group or filtered subscription) into a professional Draw.io architecture diagram following established AzVerify conventions.

    101 GitHub stars~5.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Official

    Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.

    101 GitHub stars~2.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Azv Azure To Bicep

    Azure/AZVerify

    Official

    Reverse-engineer a live Azure scope (resource group or filtered subscription) into deployment-ready, modular Bicep templates with parameter files.

    101 GitHub stars~5.4k tokensUpdated 1 mo ago
    Auto-check: warnings
  • Official

    Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.

    101 GitHub stars~4.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Azv Bicep Whatif

    Azure/AZVerify

    Official

    Compare Bicep templates against a live Azure environment by querying Azure directly and parsing the Bicep template.

    101 GitHub stars~3.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Official

    Compare a Draw.io Azure architecture diagram against a live Azure environment to detect drift.

    101 GitHub stars~3.7k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Azv Diagram To Bicep

What does Azv Diagram To Bicep do?

Generate deployment-ready Bicep templates and PowerShell scripts from an approved Draw.io Azure architecture diagram. Azv Diagram To Bicep is an agent skill from Azure/AZVerify, published by the product's own GitHub organization.io Azure architecture diagram.

When should I use Azv Diagram To Bicep?

Azv Diagram To Bicep fits situations like: tasks that involve Infrastructure as code; tasks that involve Diagrams; tasks that involve Cloud architecture.

How do I install Azv Diagram To Bicep in Claude Code?

Run `npx skills add Azure/AZVerify --skill azv-diagram-to-bicep -a claude-code`. Or copy the skill folder (.github/skills/azv-diagram-to-bicep in Azure/AZVerify) into .claude/skills/azv-diagram-to-bicep in your project. Claude Code loads it when a task matches its description.

How do I install Azv Diagram To Bicep in Codex?

Run `npx skills add Azure/AZVerify --skill azv-diagram-to-bicep -a codex`. Or copy the skill folder (.github/skills/azv-diagram-to-bicep in Azure/AZVerify) into .agents/skills/azv-diagram-to-bicep in your project. Codex loads it when a task matches its description.

Can I use Azv Diagram To Bicep in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/AZVerify --skill azv-diagram-to-bicep -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azv-diagram-to-bicep, .gemini/skills/azv-diagram-to-bicep, .github/skills/azv-diagram-to-bicep and .opencode/skills/azv-diagram-to-bicep in your project.

What does Azv Diagram To Bicep need to run?

Going by SKILL.md and its folder, Azv Diagram To Bicep needs the command-line tools its instructions call (az).

Does Azv Diagram To Bicep access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Azv Diagram To Bicep safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): tells the agent its actions are pre-authorized / not to stop for confirmation. Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Azv Diagram To Bicep use?

Azv Diagram To Bicep is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azv Diagram To Bicep use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azv Diagram To Bicep?

Skills that share tags, products or a category with Azv Diagram To Bicep: Azure Architecture Autopilot (github/awesome-copilot, 40k stars), Azure Well Architected Review (github/awesome-copilot, 40k stars), Azure Diagrams (cmb211087/azure-diagrams-skill, 150 stars) and Azure Bicep Skill (timothywarner-org/claude-code, 224 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azv Diagram To Bicep?

Azure (a GitHub organization, an official publisher) maintains it in Azure/AZVerify, which has 101 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on August 27, 2026.

Source: Azure/AZVerify on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.