Agent skill

Azure Bgp

by benchflow-ai in benchflow-ai/skillsbench

Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments).

Apache-2.0Auto-check passedDevOps & Cloud

Install Azure Bgp

skills CLI
$ npx skills add benchflow-ai/skillsbench --skill azure-bgp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install benchflow-ai/skillsbench azure-bgp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tasks/azure-bgp-oscillation-route-leak/environment/skills/azure-bgp .claude/skills/azure-bgp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-bgp
GitHub stars
1.8k
Token cost
~2.4k tokens
SKILL.md length
1,189 words
Files
1
Skills in repo
189
Repo updated
First seen
Licence
Apache-2.0

At a glance

Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments).

  • Works in 3 steps: Sanity-Check Inputs → Detect BGP Oscillation (Preference Cycle) → Detect BGP Route Leak (Valley-Free…
  • DevOps & Cloud work in your project
  • SKILL.md covers When to Use This Skill, Core Invariants (Must Never Be…, Expected Inputs and Reasoning Workflow (Executable…, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Azure Bgp is an agent skill from benchflow-ai/skillsbench. Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments). Detect preference cycles, identify valley-free violations, and propose allowed policy-level mitigations while rejecting prohibited fixes.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Microsoft Azure. The repository describes itself as: SkillsBench evaluates how well skills work and how effective agents are at using them. The licence is Apache-2.0.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/azure-bgp”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Sanity-Check Inputs
  2. Detect BGP Oscillation (Preference Cycle)
  3. Detect BGP Route Leak (Valley-Free Violation)

What it can do on your machine

Read from SKILL.md and the folder at commit 9a1f4dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Bgp loads about 2.4k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 1,189 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from benchflow-ai/skillsbench at commit 9a1f4dd, republished under its Apache-2.0 licence (© benchflow-ai). 1,189 words, ~2,436 tokens.

Download SKILL.mdSave it as .claude/skills/azure-bgp/SKILL.md (or your agent's skills folder).
name
azure-bgp
description
Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments). Detect preference cycles, identify valley-free violations, and propose allowed policy-level mitigations while rejecting prohibited fixes.

Azure BGP Oscillation & Route Leak Analysis

Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments).

This skill trains an agent to:

  • Detect preference cycles that cause BGP oscillation
  • Identify valley-free violations that constitute route leaks
  • Propose allowed, policy-level mitigations (routing intent, export policy, communities, UDR, ingress filtering)
  • Reject prohibited fixes (disabling BGP, shutting down peering, removing connectivity)

The focus is cloud-correct reasoning, not on-prem router manipulation.

When to Use This Skill

Use this skill when a task involves:

  • Azure Virtual WAN, hub-and-spoke BGP, ExpressRoute, or VPN gateways
  • Repeated route flapping or unstable path selection
  • Unexpected transit, leaked prefixes, or valley-free violations
  • Choosing between routing intent, UDRs, or BGP policy fixes
  • Evaluating whether a proposed "fix" is valid in Azure

Core Invariants (Must Never Be Violated)

An agent must internalize these constraints before reasoning:

  • ❌ BGP sessions between hubs cannot be administratively disabled by customers as it's owned by azure
  • ❌ Peering connections cannot be shut down as a fix as it break all other traffic running on the connections
  • ❌ Removing connectivity is not a valid solution as it break all other traffic running
  • ✅ Problems must be fixed using routing policy, not topology destruction

Any solution violating these rules is invalid.

Expected Inputs

Tasks using this skill typically provide small JSON files:

FileMeaning
topology.jsonDirected BGP adjacency graph
relationships.jsonEconomic relationship per edge (provider, customer, peer)
preferences.jsonPer-ASN preferred next hop (may cause oscillation)
route.jsonPrefix and origin ASN
route_leaks.jsonEvidence of invalid propagation
possible_solutions.jsonCandidate fixes to classify

Reasoning Workflow (Executable Checklist)

Step 1 — Sanity-Check Inputs
  • Every ASN referenced must exist in topology.json
  • Relationship symmetry must hold:
    • provider(A→B) ⇔ customer(B→A)
    • peer must be symmetric
  • If this fails, the input is invalid.
Step 2 — Detect BGP Oscillation (Preference Cycle)

Definition

BGP oscillation exists if ASes form a preference cycle, often between peers.

Detection Rule

  1. Build a directed graph: ASN → preferred next-hop ASN
  2. If the graph contains a cycle, oscillation is possible
  3. A 2-node cycle is sufficient to conclude oscillation.

Example pseudocode:

python
pref = {asn: prefer_via_asn, ...}

def find_cycle(start):
    path = []
    seen = {}
    cur = start
    while cur in pref:
        if cur in seen:
            return path[seen[cur]:]  # cycle found
        seen[cur] = len(path)
        path.append(cur)
        cur = pref[cur]
    return None
Step 3 — Detect BGP Route Leak (Valley-Free Violation)

Valley-Free Rule

Learned fromMay export to
CustomerAnyone
PeerCustomers only
ProviderCustomers only

Leak Conditions

A route leak exists if either is true:

  1. Route learned from a provider is exported to a peer or provider
  2. Route learned from a peer is exported to a peer or provider

Fix Selection Logic (Ranked)

Tier 1 — Virtual WAN Routing Intent (Preferred)

Applies to:

  • ✔ Oscillation
  • ✔ Route leaks

Why it works:

  • Routing intent operates above BGP — BGP still learns routes, but does not decide forwarding
  • Forwarding becomes deterministic and policy-driven — Intent policy overrides BGP path selection
  • Decouples forwarding correctness from BGP stability — Even if BGP oscillates, forwarding is stable

For oscillation:

  • Breaks preference cycles by enforcing a single forwarding hierarchy
  • Even if both hubs prefer each other's routes, intent policy ensures traffic follows one path

For route leaks:

  • Prevents leaked peer routes from being used as transit
  • When intent mandates hub-to-hub traffic goes through Virtual WAN (ASN 65001), leaked routes cannot be used
  • Enforces valley-free routing by keeping provider routes in proper hierarchy

Agent reasoning: If routing intent is available, recommend it first.

Tier 2 — Export / Route Policy (Protocol-Correct)

For oscillation:

  • Filter routes learned from a peer before re-advertising — Removes one edge of the preference cycle
  • Why this works: In a cycle where Hub A prefers routes via Hub B and vice versa, filtering breaks one "leg":
    • If Hub A filters routes learned from Hub B before re-announcing, Hub B stops receiving routes via Hub A
    • Hub B can no longer prefer the path through Hub A because it no longer exists
    • The cycle collapses, routing stabilizes

Example: If vhubvnet1 (ASN 65002) filters routes learned from vhubvnet2 (ASN 65003) before re-advertising, vhubvnet2 stops receiving routes via vhubvnet1, breaking the oscillation cycle.

For route leaks:

  • Enforce valley-free export rules — Prevent announcing provider/peer-learned routes to peers/providers
  • Use communities (e.g., no-export) where applicable
  • Ingress filtering — Reject routes with invalid AS_PATH from peers
  • RPKI origin validation — Cryptographically rejects BGP announcements from ASes that are not authorized to originate a given prefix, preventing many accidental and sub-prefix leaks from propagating

Limitation: Does not control forwarding if multiple valid paths remain.

Show full SKILL.md (485 more words)Show less
Tier 3 — User Defined Routes (UDR)

Applies to:

  • ✔ Oscillation
  • ✔ Route leaks

Purpose: Authoritative, static routing mechanism in Azure that explicitly defines the next hop for network traffic based on destination IP prefixes, overriding Azure system routes and BGP-learned routes.

Routing Behavior: Enforces deterministic forwarding independent of BGP decision processes. UDRs operate at the data plane layer and take precedence over dynamic BGP routes.

For oscillation:

  • Oscillation Neutralization — Breaks the impact of BGP preference cycles by imposing a fixed forwarding path
  • Even if vhubvnet1 and vhubvnet2 continue to flip-flop their route preferences, the UDR ensures traffic always goes to the same deterministic next hop

For route leaks:

  • Route Leak Mitigation — Overrides leaked BGP routes by changing the effective next hop
  • When a UDR specifies a next hop (e.g., prefer specific Virtual WAN hub), traffic cannot follow leaked peer routes even if BGP has learned them
  • Leaked Prefix Neutralization — UDR's explicit next hop supersedes the leaked route's next hop, preventing unauthorized transit

Use when:

  • Routing intent is unavailable
  • Immediate containment is required

Trade-off: UDR is a data-plane fix that "masks" the control-plane issue. BGP may continue to have problems, but forwarding is stabilized. Prefer policy fixes (routing intent, export controls) when available for cleaner architecture.

Prohibited Fixes (Must Be Rejected)

These solutions are always invalid:

Proposed FixReason
Disable BGPNot customer-controllable
Disable peeringprohibited operation and cannot solve the issue
Shutdown gatewaysBreaks SLA / shared control plane
Restart devicesResets symptoms only

Required explanation:

Cloud providers separate policy control from connectivity existence to protect shared infrastructure and SLAs.

Why these are not allowed in Azure:

BGP sessions and peering connections in Azure (Virtual WAN, ExpressRoute, VPN Gateway) cannot be administratively shut down or disabled by customers. This is a fundamental architectural constraint:

  1. Shared control plane: BGP and peering are part of Azure's provider-managed, SLA-backed control plane that operates at cloud scale.
  2. Availability guarantees: Azure's connectivity SLAs depend on these sessions remaining active.
  3. Security boundaries: Customers control routing policy (what routes are advertised/accepted) but not the existence of BGP sessions themselves.
  4. Operational scale: Managing BGP session state for thousands of customers requires automation that manual shutdown would undermine.

Correct approach: Fix BGP issues through policy changes (route filters, preferences, export controls, communities) rather than disabling connectivity.

Common Pitfalls

  • ❌ Timer tuning or dampening fixes oscillation — False. These reduce symptoms but don't break preference cycles.
  • ❌ Accepting fewer prefixes prevents route leaks — False. Ingress filtering alone doesn't stop export of other leaked routes.
  • ❌ Removing peers is a valid mitigation — False. This is prohibited in Azure.
  • ❌ Restarting gateways fixes root cause — False. Only resets transient state.

All are false.

Output Expectations

A correct solution should:

  1. Identify oscillation and/or route leak correctly
  2. Explain why it occurs (preference cycle or valley-free violation)
  3. Recommend allowed policy-level fixes
  4. Explicitly reject prohibited fixes with reasoning

References

  • RFC 4271 — Border Gateway Protocol 4 (BGP-4)
  • Gao–Rexford model — Valley-free routing economics

© benchflow-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in tasks/azure-bgp-oscillation-route-leak/environment/skills/azure-bgp of benchflow-ai/skillsbench.

Open the folder on GitHubat commit 9a1f4dd

Compare with similar skills

Azure Bgp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Bgp compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Bgp this skillbenchflow-ai/skillsbench1.8k—~2.4kAutomated safety check: PassApache-2.0
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Thesvgglincker/thesvg2.8k—~1.5kAutomated safety check: PassMIT
Azure PricingAzure/Copilot-Studio-and-Azure1102 repos~2.4kAutomated safety check: PassMIT
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azure Pricing

    Azure/Copilot-Studio-and-Azure

    Official

    Fetches real-time Azure retail pricing using the Azure Retail Prices API (prices.azure.com) and estimates Copilot Studio agent credit consumption.

    110 GitHub starsUsed in 2 repos~2.4k tokens
    DevOps & CloudAuto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Aspire

    microsoft/aspire.dev

    Official

    Orchestrates Aspire distributed applications using the Aspire CLI for running, debugging, and managing distributed apps.

    196 GitHub starsUsed in 4 repos~1.1k tokens
    DevOps & CloudAuto-check passed

More from benchflow-ai/skillsbench

All 189 skills in this repo
  • Lean4 Memories

    benchflow-ai/skillsbench

    This skill should be used when working on Lean 4 formalization projects to maintain persistent memory of successful proof patterns, failed approaches, project conventions, and user preferences…

    1.8k GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Senior Data Engineer

    benchflow-ai/skillsbench

    World-class data engineering skill for building scalable data pipelines, ETL/ELT systems, real-time streaming, and data infrastructure.

    1.8k GitHub stars~5.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Ac Branch Pi Model

    benchflow-ai/skillsbench

    AC branch pi-model power flow equations (P/Q and |S|) with transformer tap ratio and phase shift, matching acopf-math-model.md and MATPOWER branch fields.

    1.8k GitHub stars~1.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Civ6lib

    benchflow-ai/skillsbench

    Civilization 6 district mechanics library. An agent skill from benchflow-ai/skillsbench.

    1.8k GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • D3 Visualization

    benchflow-ai/skillsbench

    Build deterministic, verifiable data visualizations with D3.js (v6).

    1.8k GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Dc Power Flow

    benchflow-ai/skillsbench

    DC power flow analysis for power systems. An agent skill from benchflow-ai/skillsbench.

    1.8k GitHub stars~717 tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Azure Bgp

What does Azure Bgp do?

Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments). Azure Bgp is an agent skill from benchflow-ai/skillsbench. Analyze and resolve BGP oscillation and BGP route leaks in Azure Virtual WAN–style hub-and-spoke topologies (and similar cloud-managed BGP environments).

When should I use Azure Bgp?

Azure Bgp fits situations like: devOps & Cloud work in your project.

How do I install Azure Bgp in Claude Code?

Run `npx skills add benchflow-ai/skillsbench --skill azure-bgp -a claude-code`. Or copy the skill folder (tasks/azure-bgp-oscillation-route-leak/environment/skills/azure-bgp in benchflow-ai/skillsbench) into .claude/skills/azure-bgp in your project. Claude Code loads it when a task matches its description.

How do I install Azure Bgp in Codex?

Run `npx skills add benchflow-ai/skillsbench --skill azure-bgp -a codex`. Or copy the skill folder (tasks/azure-bgp-oscillation-route-leak/environment/skills/azure-bgp in benchflow-ai/skillsbench) into .agents/skills/azure-bgp in your project. Codex loads it when a task matches its description.

Can I use Azure Bgp in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benchflow-ai/skillsbench --skill azure-bgp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-bgp, .gemini/skills/azure-bgp, .github/skills/azure-bgp and .opencode/skills/azure-bgp in your project.

What does Azure Bgp need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Bgp is instructions for the agent only. Our summary lists: Python 3.

Does Azure Bgp access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Azure Bgp safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Bgp use?

Azure Bgp is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Bgp use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Bgp?

Skills that share tags, products or a category with Azure Bgp: Cloud Cost Optimization (wshobson/agents, 40k stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Thesvg (glincker/thesvg, 2.8k stars) and Azure Pricing (Azure/Copilot-Studio-and-Azure, 110 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Bgp?

benchflow-ai (a GitHub organization) maintains it in benchflow-ai/skillsbench, which has 1,834 GitHub stars. The repository holds 189 skills in this directory. The repository was last updated on July 23, 2026.

Source: benchflow-ai/skillsbench on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.