Tirith Policies
StackGuardian/tirith
Write, validate, run and debug Tirith IaC governance policies, install Tirith, and add it to a CI pipeline (GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, Azure DevOps, CircleCI or any…
Explain SDAF plan-only / test / apply semantics without pretending they are universal.
$ npx skills add Azure/sap-automation --skill sdaf-plan-and-test-semantics -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/sap-automation sdaf-plan-and-test-semantics --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sdaf-plan-and-test-semantics .claude/skills/sdaf-plan-and-test-semantics && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sdaf-plan-and-test-semantics" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-plan-and-test-semantics into .claude/skills/sdaf-plan-and-test-semantics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-plan-and-test-semantics", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/sap-automation/tree/main/skills/sdaf-plan-and-test-semanticsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/sap-automation --skill sdaf-plan-and-test-semantics -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/sap-automation sdaf-plan-and-test-semantics --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/sdaf-plan-and-test-semantics .agents/skills/sdaf-plan-and-test-semantics && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sdaf-plan-and-test-semantics" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-plan-and-test-semantics into .agents/skills/sdaf-plan-and-test-semantics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-plan-and-test-semantics", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/sap-automation --skill sdaf-plan-and-test-semantics -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/sap-automation sdaf-plan-and-test-semantics --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/sdaf-plan-and-test-semantics .cursor/skills/sdaf-plan-and-test-semantics && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sdaf-plan-and-test-semantics" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-plan-and-test-semantics into .cursor/skills/sdaf-plan-and-test-semantics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-plan-and-test-semantics", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/sap-automation.git --path skills/sdaf-plan-and-test-semantics--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/sap-automation --skill sdaf-plan-and-test-semantics -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/sap-automation sdaf-plan-and-test-semantics --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/sdaf-plan-and-test-semantics .gemini/skills/sdaf-plan-and-test-semantics && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sdaf-plan-and-test-semantics" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-plan-and-test-semantics into .gemini/skills/sdaf-plan-and-test-semantics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-plan-and-test-semantics", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/sap-automation sdaf-plan-and-test-semanticsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/sap-automation --skill sdaf-plan-and-test-semantics -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/sdaf-plan-and-test-semantics .github/skills/sdaf-plan-and-test-semantics && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sdaf-plan-and-test-semantics" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-plan-and-test-semantics into .github/skills/sdaf-plan-and-test-semantics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-plan-and-test-semantics", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/sap-automation --skill sdaf-plan-and-test-semantics -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/sap-automation sdaf-plan-and-test-semantics --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/sdaf-plan-and-test-semantics .opencode/skills/sdaf-plan-and-test-semantics && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sdaf-plan-and-test-semantics" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-plan-and-test-semantics into .opencode/skills/sdaf-plan-and-test-semantics/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-plan-and-test-semantics", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sdaf-plan-and-test-semanticsExplain SDAF plan-only / test / apply semantics without pretending they are universal.
Sdaf Plan And Test Semantics is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Explain SDAF plan-only / test / apply semantics without pretending they are universal. Compares the documented Local commands, Azure DevOps wrapper pipelines, and GitHub Actions workflows for control plane, workload zone, and SAP system: local stage commands show Terraform plans and then apply after approval; ADO/GitHub workload-zone and SAP-system test runs stop after the plan; the current hosted control-plane test options do not provide a plan-only run. Use when a user says "what does test do in SDAF", "is this…
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/plan-test-matrix.md`).
It sits in DevOps & Cloud, covering Infrastructure as code and CI/CD. It works with Azure DevOps, Terraform, GitHub and GitHub Actions. The repository describes itself as: This is the repository supporting the SAP deployment automation framework on Azure. The licence is MIT.
Read from SKILL.md and the folder at commit 78835f0. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
shellFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sdaf Plan And Test Semantics loads about 1.6k tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 202 tokens; SKILL.md has 684 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/sap-automation at commit 78835f0, republished under its MIT licence (© Azure). 684 words, ~1,602 tokens.
.claude/skills/sdaf-plan-and-test-semantics/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Context-primer. Answers "what does test / plan-only / apply mean here?" across surfaces. Canonical rule: there is no SDAF-wide dry-run switch. Classify by execution surface and deployment stage before answering.
For the file-by-file evidence matrix, including the hosted wrapper docs and
workflow/pipeline paths, see
references/plan-test-matrix.md.
Trigger on: "what does test do", "is this a dry run", "plan-only vs apply", "control-plane dry-run limitation", "workflow 01 dry-run", "pipeline 02 test", "TEST_ONLY", "which SDAF stages can review a Terraform plan without applying".
Do NOT trigger on: actually deploying a control plane / workload zone / SAP system, or triaging a failed run after the fact.
docs/deployment-options.md is explicit that Local, Azure DevOps, and GitHub
Actions are different execution models. Never answer "test means X in
SDAF" without naming:
| Path | What plan/test means | What apply means |
|---|---|---|
| Local control plane | No separate documented test switch. deploy_controlplane.sh displays Terraform plans and asks for approval before apply. | The same run applies after operator approval. |
| Local workload zone | No separate documented local test path. install_workloadzone.sh shows the plan and waits for approval. | The same run applies after approval. |
| Local SAP system | No separate documented local test path. installer.sh shows the plan and waits for approval. | The same run applies after approval. |
ADO control plane (01) | test exists on the wrapper/template, but current docs say it is not forwarded to the control-plane scripts. Treat it as not plan-only. | The queued run is state-changing. |
ADO workload zone (02) | test: true becomes TEST_ONLY and the hosted installer exits after Terraform plan. | Re-queue the same pipeline with test: false. |
ADO SAP system (03) | test: true becomes TEST_ONLY and the hosted installer exits after Terraform plan. | Re-queue the same pipeline with test: false. |
GitHub control plane (01) | The workflow exposes a dry-run input, but the docs say it does not reach either control-plane script. | Treat the run as state-changing; get a reviewed control-plane plan through a separately validated SDAF path first. |
GitHub workload zone (03) | Enable the test option, review the plan, then rerun with test disabled. The workflow exports TEST_ONLY. | Re-dispatch workflow 03 with test disabled. |
GitHub SAP system (05) | Enable the test option, review the plan, then rerun with test disabled. The workflow exports TEST_ONLY. | Re-dispatch workflow 05 with test disabled. |
For local execution, the docs do not define a universal test flag that
operators should export by hand. Instead, the documented stage commands
themselves are the review gate:
docs/local/03-00-control-plane.md § Run: deploy_controlplane.sh
displays Terraform plans and asks for approval before apply.docs/local/04-00-workload-zone.md § Run: install_workloadzone.sh
displays the plan and asks for approval before apply.docs/local/05-00-sap-system.md § Run: installer.sh displays the plan
and asks for approval before apply.If the operator is on Local, answer with the documented stage command, not
with a hosted-only TEST_ONLY story.
This is the boundary that prevents most bad advice:
For Azure DevOps or GitHub Actions, answer from the documented pipeline or
workflow inputs and outcomes. Do not transfer Local behavior to hosted
automation merely because both surfaces use the word test.
The control plane is different from workload zone and SAP system:
test/dry-run
input, but the reviewed docs say that input is not forwarded to the
control-plane scripts.So the correct answer to "is control-plane test safe?" is no for the
hosted wrappers as currently documented.
test as a
safety gate.--auto-approve
(docs/local/03-00-control-plane.md § Review before execution;
docs/local/04-00-workload-zone.md § Review before execution;
docs/local/05-00-sap-system.md § Review before execution).sdaf-control-plane-bootstrapsdaf-workload-zonesdaf-sap-systemsdaf-failure-triagereferences/plan-test-matrix.mdsdaf-control-plane-bootstrap, sdaf-workload-zone, sdaf-sap-system,
sdaf-failure-triagedocs/deployment-options.md, docs/local/README.md,
docs/local/03-00-control-plane.md, docs/local/04-00-workload-zone.md,
docs/local/05-00-sap-system.md© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/sdaf-plan-and-test-semantics of Azure/sap-automation.
Open the folder on GitHubat commit 78835f0
Sdaf Plan And Test Semantics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sdaf Plan And Test Semantics this skillAzure/sap-automation | 145 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Tirith PoliciesStackGuardian/tirith | 170 | — | ~1.8k | Automated safety check: Pass | Apache-2.0 | |
| APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills | 202 | — | ~3.6k | Automated safety check: Pass | MIT | |
| AWS GitHub Oidc Scoped Rolemizchi/skills | 356 | — | ~1.6k | Automated safety check: Pass | None | |
| Devops Pipelineluongnv89/skills | 131 | — | ~4.8k | Automated safety check: Pass | MIT | |
| Oraclecloud CI Integrationjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2k | Automated safety check: Pass | MIT |
StackGuardian/tirith
Write, validate, run and debug Tirith IaC governance policies, install Tirith, and add it to a CI pipeline (GitHub Actions, GitLab CI, Bitbucket Pipelines, Jenkins, Azure DevOps, CircleCI or any…
thomast1906/github-copilot-agent-skills
Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.
mizchi/skills
OpenTofu/Terraform pattern for GitHub Actions OIDC trust with AWS IAM.
luongnv89/skills
Configure pre-commit hooks and lean GitHub Actions for shift-left quality assurance.
jeremylongshore/tons-of-skills-marketplace
Configure CI/CD pipelines for OCI with Terraform and GitHub Actions.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
Azure/sap-automation
Pick the right SDAF BOM for a target SAP product / release / DB platform / version / kernel / topology.
Azure/sap-automation
Orient a newcomer to the SAP Deployment Automation Framework (SDAF): explain the spine (control plane → workload zone → SAP system → software → install → operate/remove), summarise the three…
Azure/sap-automation
Validate a deployed SDAF SAP system through the SDAF-owned QA entry points: the local quality-assurance menu and the documented Azure DevOps pipeline 13 path.
Azure/sap-automation
Guide SDAF operating-system, database, and SAP installation after the SAP-system workspace and reviewed media are ready.
Azure/sap-automation
Explain the current SDAF sovereign-cloud deltas without inventing a generic "all sovereigns" runbook.
Azure/sap-automation
Inspect and repair SDAF Terraform state safely before any reviewed import/remove.
Categories
Explain SDAF plan-only / test / apply semantics without pretending they are universal. Sdaf Plan And Test Semantics is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Explain SDAF plan-only / test / apply semantics without pretending they are universal.
Sdaf Plan And Test Semantics fits situations like: A user says what does test do in SDAF; is this a real dry run; plan-only vs apply; workflow 01 dry-run.
Run `npx skills add Azure/sap-automation --skill sdaf-plan-and-test-semantics -a claude-code`. Or copy the skill folder (skills/sdaf-plan-and-test-semantics in Azure/sap-automation) into .claude/skills/sdaf-plan-and-test-semantics in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/sap-automation --skill sdaf-plan-and-test-semantics -a codex`. Or copy the skill folder (skills/sdaf-plan-and-test-semantics in Azure/sap-automation) into .agents/skills/sdaf-plan-and-test-semantics in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/sap-automation --skill sdaf-plan-and-test-semantics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sdaf-plan-and-test-semantics, .gemini/skills/sdaf-plan-and-test-semantics, .github/skills/sdaf-plan-and-test-semantics and .opencode/skills/sdaf-plan-and-test-semantics in your project.
SKILL.md names no scripts, command-line tools or credentials: Sdaf Plan And Test Semantics is instructions for the agent only. Its frontmatter pre-approves these tools: shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sdaf Plan And Test Semantics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 297 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Sdaf Plan And Test Semantics: Tirith Policies (StackGuardian/tirith, 170 stars), APIOps Deployment for Azure APIM (thomast1906/github-copilot-agent-skills, 202 stars), AWS GitHub Oidc Scoped Role (mizchi/skills, 356 stars) and Devops Pipeline (luongnv89/skills, 131 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/sap-automation, which has 145 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.
Source: Azure/sap-automation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.