Official agent skill

Kql Validator

by Azure in Azure/azqr

Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.

OfficialMITAuto-check passedBackend & APIs

Install Kql Validator

skills CLI
$ npx skills add Azure/azqr --skill kql-validator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/azqr kql-validator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/azqr.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/kql-validator .claude/skills/kql-validator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kql-validator
GitHub stars
794
Token cost
~703 tokens
SKILL.md length
265 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.

  • Works in 3 steps: Determine scope from the user's request → Launch the KQLValidator subagent → Surface results to the user
  • The user wants to validate KQL syntax
  • SKILL.md covers What the subagent validates, How to invoke and Important notes
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Kql Validator is an agent skill from Azure/azqr, published by the product's own GitHub organization. Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions. Use when the user wants to validate KQL syntax, check semantic alignment with recommendations, verify property names against Azure REST API schemas, or audit KQL queries before a pull request. WHEN: "validate kql", "check kql files", "kql syntax error", "validate aks kql", "run kql validator", "validate azure resource graph queries", "check recommendations alignment", "validate kql for <service".

Its SKILL.md is about 700 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/kql-validator.md`).

It sits in Backend & APIs, covering REST APIs and Pull requests. It works with Microsoft Sentinel, Microsoft Azure and GitHub. The licence is MIT.

When your agent uses it

  • The user wants to validate KQL syntax
  • Check semantic alignment with recommendations
  • Verify property names against Azure REST API schemas
  • Audit KQL queries before a pull request

Example prompts

  • “validate kql”
  • “check kql files”
  • “kql syntax error”
  • “/kql-validator”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Determine scope from the user's request
  2. Launch the KQLValidator subagent
  3. Surface results to the user

What it can do on your machine

Read from SKILL.md and the folder at commit 3cf9f0a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kql Validator loads about 703 tokens when it runs. Until then it costs about 133 tokens; SKILL.md has 265 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~703

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/azqr at commit 3cf9f0a, republished under its MIT licence (© Azure). 265 words, ~703 tokens.

Download SKILL.mdSave it as .claude/skills/kql-validator/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
kql-validator
description
Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions. Use when the user wants to validate KQL syntax, check semantic alignment with recommendations, verify property names against Azure REST API schemas, or audit KQL queries before a pull request. WHEN: "validate kql", "check kql files", "kql syntax error", "validate aks kql", "run kql validator", "validate azure resource graph queries", "check recommendations alignment", "validate kql for <service>".

KQL Validator Skill

This skill validates KQL query files in Azure Quick Review by delegating to the KQLValidator subagent. The subagent handles the full validation pipeline — discovery, structural/semantic/schema checks, and report generation.

What the subagent validates

  • Syntax: Correct KQL grammar, type casts, projection clauses
  • Semantic alignment: Query finds violations (not compliance), recommendationId matches aprlGuid
  • Schema validity: Property references exist in Azure REST API specs (GitHub lookup, best-effort)
  • 100% coverage: Never samples — validates every file in scope

How to invoke

Step 1: Determine scope from the user's request

Parse what the user wants to validate:

User saysScope argument to pass
"validate all KQL" / no specific target(empty — validate everything)
"validate ContainerService" / "validate AKS"Service name, e.g. ContainerService
"validate aks-004.kql"Filename, e.g. aks-004.kql
"validate internal/graph/azqr/azure-resources/Sql/"Directory path
Step 2: Launch the KQLValidator subagent

Spawn the subagent using the agent file at .agents/skills/kql-validator/agents/kql-validator.md. Pass the scope as the user argument.

Subagent prompt template:

Read and follow the instructions in .agents/skills/kql-validator/agents/kql-validator.md exactly.

User argument: <SCOPE_ARGUMENT_OR_EMPTY>

Workspace: /home/cmendibl3/_dev/azqr

The subagent is self-contained — it will discover files, validate them, and generate a full markdown report. Do not attempt to re-implement its logic inline.

Step 3: Surface results to the user

Once the subagent completes, present its markdown report directly. If the subagent encountered issues, highlight the critical ones and suggest fixes.

Important notes

  • The subagent uses GitHub to look up Azure REST API schemas. If GitHub is unavailable, it continues with structural and semantic validation only and notes the limitation.
  • For large scopes (all services), the run may take several minutes. Let the user know and launch the subagent in background mode.
  • For focused scopes (single service or file), sync mode is fine.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in .agents/skills/kql-validator of Azure/azqr.

  • SKILL.md
  • agents/kql-validator.md

Open the folder on GitHubat commit 3cf9f0a

Compare with similar skills

Kql Validator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kql Validator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kql Validator this skillAzure/azqr794—~703Automated safety check: PassMIT
B24phpsdk Maintainerbitrix24/b24phpsdk102—~10kAutomated safety check: NotesMIT
Azv Bicep Policy CheckAzure/AZVerify101—~4.3kAutomated safety check: PassMIT
GitHub PR WorkflowRedWoodOG/Hermes-Desktop1775 repos~2.5kAutomated safety check: NotesMIT
Readme Generator Probeizhi23/README-Generator-Pro113—~472Automated safety check: NotesNone
Finding TriageHacktronAI/skills115—~2.9kAutomated safety check: NotesMIT

Similar skills

  • B24phpsdk Maintainer

    bitrix24/b24phpsdk

    A skill your agent uses whenever working with GitHub issues in the bitrix24/b24phpsdk repository: creating new issues, reading existing ones, planning implementation from an issue, referencing an…

    102 GitHub stars~10k tokensUpdated 7 days ago
    Backend & APIsAuto-check: notes
  • Official

    Check a Bicep template against the Azure Policy assignments in the target Azure environment to determine whether the resources would be compliant before deployment.

    101 GitHub stars~4.3k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • GitHub PR Workflow

    RedWoodOG/Hermes-Desktop

    Full pull request lifecycle — create branches, commit changes, open PRs, monitor CI status, auto-fix failures, and merge.

    177 GitHub starsUsed in 5 repos~2.5k tokens
    DevelopmentAuto-check: notes
  • Readme Generator Pro

    beizhi23/README-Generator-Pro

    Generate, modify, and render professional README.md files and project introduction HTML pages using the bundled README Generator Pro FastAPI application.

    113 GitHub stars~472 tokensUpdated 3 mo ago
    Backend & APIsAuto-check: notes
  • Finding Triage

    HacktronAI/skills

    Interactively validate and triage Hacktron findings against the actual source code and (optionally) a live deployment, separate true positives from false positives, adjust severity, then either…

    115 GitHub stars~2.9k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Review PR Comments

    latitude-dev/latitude-llm

    Triages a PR with GitHub CLI: loads issue-level and inline review feedback (gh pr view, gh api REST, gh api graphql as appropriate), walks items in order, replies in the correct thread, optional…

    4.7k GitHub stars~2.6k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from Azure/azqr

  • Skill Creator

    Azure/azqr

    Official

    Create new skills, modify and improve existing skills, and measure skill performance.

    794 GitHub starsUsed in 89 repos~8.2k tokens
    Auto-check passed
  • Review Areas

    Azure/azqr

    Official

    In-depth code review that fans out parallel subagents across review areas — CRITICAL after non-trivial development.

    794 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Azqr Developer

    Azure/azqr

    Official

    Expert guidance for developing and contributing to Azure Quick Review (azqr) - A Go-based CLI tool for Azure resource compliance analysis

    794 GitHub stars~3k tokensUpdated 2 days ago
    Auto-check passed
  • Code Simplifier

    Azure/azqr

    Official

    Analyzes recently modified code and creates pull requests with simplifications that improve clarity, consistency, and maintainability while preserving functionality

    794 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed

Questions about Kql Validator

What does Kql Validator do?

Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions. Kql Validator is an agent skill from Azure/azqr, published by the product's own GitHub organization. Validate KQL (Kusto Query Language) files used in Azure Quick Review (azqr) against their recommendation definitions.

When should I use Kql Validator?

Kql Validator fits situations like: the user wants to validate KQL syntax; check semantic alignment with recommendations; verify property names against Azure REST API schemas; audit KQL queries before a pull request.

How do I install Kql Validator in Claude Code?

Run `npx skills add Azure/azqr --skill kql-validator -a claude-code`. Or copy the skill folder (.agents/skills/kql-validator in Azure/azqr) into .claude/skills/kql-validator in your project. Claude Code loads it when a task matches its description.

How do I install Kql Validator in Codex?

Run `npx skills add Azure/azqr --skill kql-validator -a codex`. Or copy the skill folder (.agents/skills/kql-validator in Azure/azqr) into .agents/skills/kql-validator in your project. Codex loads it when a task matches its description.

Can I use Kql Validator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/azqr --skill kql-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kql-validator, .gemini/skills/kql-validator, .github/skills/kql-validator and .opencode/skills/kql-validator in your project.

What does Kql Validator need to run?

SKILL.md names no scripts, command-line tools or credentials: Kql Validator is instructions for the agent only.

Does Kql Validator access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kql Validator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kql Validator use?

Kql Validator is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kql Validator use?

About 703 tokens (SKILL.md is roughly 2.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kql Validator?

Skills that share tags, products or a category with Kql Validator: B24phpsdk Maintainer (bitrix24/b24phpsdk, 102 stars), Azv Bicep Policy Check (Azure/AZVerify, 101 stars), GitHub PR Workflow (RedWoodOG/Hermes-Desktop, 177 stars) and Readme Generator Pro (beizhi23/README-Generator-Pro, 113 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kql Validator?

Azure (a GitHub organization, an official publisher) maintains it in Azure/azqr, which has 794 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 5, 2026.

Source: Azure/azqr on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.