Official agent skill

Azure Well Architected Review

by github in github/awesome-copilot

Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Well Architected Review

skills CLI
$ npx skills add github/awesome-copilot --skill azure-well-architected-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot azure-well-architected-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-well-architected-review .claude/skills/azure-well-architected-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-well-architected-review
GitHub stars
40k
Token cost
~2.5k tokens
SKILL.md length
1,027 words
Files
1
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

  • Works in 7 steps: Load Well-Architected Framework Reference → Discover IaC & Architecture → Pillar-by-Pillar Review → …
  • Tasks that involve Cloud architecture
  • SKILL.md covers Prerequisites, Workflow Steps, Error Handling and Success Criteria
  • Calls az; reaches learn.microsoft.com

What it does

Azure Well Architected Review is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Cloud architecture and Infrastructure as code. It works with Microsoft Azure, GitHub, Model Context Protocol and Bicep. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud architecture
  • Tasks that involve Infrastructure as code

Example prompts

  • “/azure-well-architected-review”

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Load Well-Architected Framework Reference
  2. Discover IaC & Architecture
  3. Pillar-by-Pillar Review
  4. Risk Classification
  5. User Confirmation
  6. Create Individual Finding Issues
  7. Create EPIC Tracking Issue

What it can do on your machine

Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Well Architected Review loads about 2.5k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 1,027 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 1,027 words, ~2,523 tokens.

Download SKILL.mdSave it as .claude/skills/azure-well-architected-review/SKILL.md (or your agent's skills folder).
name
azure-well-architected-review
description
Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

Azure Well-Architected Review

This workflow performs a structured Azure Well-Architected Framework (WAF) review against your workload's IaC files and deployed infrastructure. It identifies risks across all 5 WAF pillars and creates GitHub issues to track remediation.

Prerequisites

  • Azure CLI (az) configured and authenticated
  • IaC files present in the repository (Bicep, Terraform, or ARM templates)
  • GitHub MCP server configured and authenticated

Workflow Steps

Step 1: Load Well-Architected Framework Reference

Fetch current Azure WAF best practices:

  • https://learn.microsoft.com/en-us/azure/well-architected/
  • Service guides for the Azure services in use (https://learn.microsoft.com/en-us/azure/well-architected/service-guides/)
  • Workload-specific guidance relevant to the workload type (SaaS, mission-critical, AI, etc.)

If the microsoft.docs.mcp MCP server is available, use it to query the latest pillar checklists and service-specific recommendations.

Step 2: Discover IaC & Architecture

Establish the review scope, then inventory both the code and the live environment:

  1. Confirm the Azure scope: Ask the user which subscription(s)/resource group(s) are in scope, or infer them from IaC parameters and confirm.
  2. Scan the repository for IaC files:
    • Bicep: **/*.bicep, bicepconfig.json
    • Terraform: **/*.tf (azurerm/azapi providers)
    • ARM templates: **/azuredeploy*.json, **/*.template.json, files with $schema containing deploymentTemplate
  3. Inventory live resources (always, even when IaC exists): az resource list --resource-group <rg> --output json (or subscription-wide), plus targeted az <service> show calls for configuration details the pillar checks need.
  4. Compare IaC with live inventory: Flag drift — resources present in Azure but absent from IaC (portal-created), resources defined in IaC but not deployed, and configuration mismatches. Record drift findings for Step 3 (they typically map to the Operational Excellence pillar).

Identify key Azure services in use (compute, data, networking, security, observability) and generate a Mermaid architecture diagram.

Step 3: Pillar-by-Pillar Review
Pillar 1: Reliability
  • Availability zones enabled for zonal services (VMs, VMSS, AKS node pools, App Service, SQL, Storage ZRS)
  • Production SKUs support the required SLA (no Basic/Free tiers on critical paths)
  • Azure SQL / Cosmos DB backup and point-in-time restore configured with appropriate retention
  • Geo-redundancy configured where RPO requires it (GRS/RA-GRS storage, SQL failover groups, Cosmos DB multi-region)
  • Autoscale rules configured for App Service plans, VMSS, AKS (no fixed single instance for production)
  • Health probes configured on Load Balancer / Application Gateway / Front Door backends
  • Dead-lettering enabled for Service Bus queues/subscriptions and Event Grid subscriptions
  • Retry policies with exponential backoff implemented for transient fault handling
  • Disaster recovery plan defined (documented RTO/RPO, tested failover)
Pillar 2: Security
  • Managed identities used instead of service principals with secrets or connection strings
  • No hardcoded credentials, keys, or connection strings in IaC or code
  • Secrets stored in Azure Key Vault with RBAC authorization (not access policies)
  • Storage accounts deny public blob access and disallow shared key access where possible
  • Private endpoints (or at minimum service endpoints + firewall rules) for PaaS data services
  • NSGs restrict inbound traffic to minimum required ports/CIDRs (no * → * allow rules)
  • TLS 1.2+ enforced on all endpoints (minimumTlsVersion, httpsOnly)
  • Azure RBAC follows least privilege (no Owner/Contributor at subscription scope for workload identities)
  • Microsoft Defender for Cloud enabled on relevant resource types (az security pricing list)
  • Azure WAF (Application Gateway or Front Door) configured for public-facing web endpoints
  • Diagnostic settings send security logs to Log Analytics / Microsoft Sentinel
Pillar 3: Cost Optimization
  • Reservations or savings plans evaluated for steady-state compute (VMs, App Service, SQL)
  • Storage lifecycle management policies move blobs to cool/archive tiers
  • Right-sized SKUs based on actual utilization (no oversized VMs/App Service plans)
  • Dev/test environments use auto-shutdown schedules and Dev/Test pricing where eligible
  • Azure Budgets and cost alerts configured (az consumption budget list)
  • Unattached managed disks and orphaned public IPs identified and removed
  • Consumption/serverless tiers used for spiky or low-volume workloads (Functions, Container Apps, SQL serverless)
  • Log Analytics retention and data-cap settings tuned to avoid ingestion overruns
Show full SKILL.md (426 more words)Show less
Pillar 4: Operational Excellence
  • All infrastructure defined as IaC (no manual portal changes; deny assignments or policy where feasible)
  • Consistent tagging strategy applied across all resources (owner, environment, cost center)
  • Azure Monitor alerts defined for key metrics and service health
  • Automated deployment pipeline present (GitHub Actions / Azure Pipelines, no manual deployments)
  • Azure Activity Log and resource diagnostic settings routed to Log Analytics
  • Application Insights (or OpenTelemetry equivalent) instrumented for application workloads
  • Azure Policy assignments enforce organizational standards (allowed locations, SKUs, tags)
  • Runbooks or operational documentation present
Pillar 5: Performance Efficiency
  • Right-sized compute SKUs validated against load requirements
  • Caching implemented where beneficial (Azure Cache for Redis, CDN/Front Door caching)
  • Azure Front Door or CDN used for global static content delivery
  • Autoscale based on load metrics rather than fixed instance counts
  • Database performance tier appropriate (DTU vs vCore, elastic pools, Cosmos DB RU autoscale)
  • Premium/zone-redundant storage used for latency-sensitive disk workloads
  • Connection pooling and async patterns used for database and HTTP clients
Step 4: Risk Classification

For each finding, classify:

  • High Risk: Security vulnerability, single point of failure, no backup/recovery
  • Medium Risk: Suboptimal reliability, cost inefficiency, performance concern
  • Low Risk: Best practice deviation, minor optimization opportunity
Step 5: User Confirmation
🏗️ Azure Well-Architected Review Summary

📊 Review Results:
• IaC Files Analyzed: X
• Azure Services Identified: Y
• Total Findings: Z
  • High Risk: A (immediate action required)
  • Medium Risk: B (should address soon)
  • Low Risk: C (nice to have)

🔴 Top High Risk Findings:
1. [Pillar]: [Finding] — [Why it matters]
2. [Pillar]: [Finding] — [Why it matters]

💡 This will create Z individual GitHub issues + 1 EPIC issue.

❓ Proceed with creating GitHub issues? (y/n)

Gate: Only proceed to Steps 6–7 if the user gives an explicit affirmative response (e.g. "y", "yes"). On a negative, ambiguous, or missing response, do not create any GitHub issues — output the full findings as formatted markdown to the console and stop.

Step 6: Create Individual Finding Issues

Label with "well-architected" and the pillar name (e.g., "security", "reliability").

Title: [WAF-<PILLAR>] [Brief Finding] — [Risk Level]

Body:

markdown
## 🏗️ Well-Architected Finding: [Brief Title]

**Pillar**: [Name] | **Risk Level**: [High/Medium/Low] | **Effort**: [Low/Medium/High]

### 📋 Description
[Clear explanation of the finding and why it matters]

### 🔧 Remediation

**IaC Fix** (preferred):
```bicep
// Bicep example
resource storageAccount 'Microsoft.Storage/storageAccounts@2023-05-01' = {
  name: storageAccountName
  location: location
  sku: { name: 'Standard_ZRS' }
  kind: 'StorageV2'
  properties: {
    minimumTlsVersion: 'TLS1_2'
    allowBlobPublicAccess: false
    supportsHttpsTrafficOnly: true
  }
}
```

**Azure CLI fallback**:
```bash
az storage account update --name <name> --resource-group <rg> \
  --min-tls-version TLS1_2 --allow-blob-public-access false --https-only true
```

### 📚 Azure Reference
- [WAF Best Practice Link]
- [Microsoft Learn Documentation Link]

### ✅ Validation
- [ ] Change implemented in IaC and deployed
- [ ] Azure Policy compliance passes (if applicable)
- [ ] Microsoft Defender for Cloud recommendation resolved (if applicable)

**Well-Architected Recommendation**: [WAF checklist item this maps to]
Step 7: Create EPIC Tracking Issue

Label with "well-architected" and "epic".

Title: [EPIC] Azure Well-Architected Review — X findings across 5 pillars

Body: Executive summary with pillar breakdown table (finding counts by pillar and risk level), Mermaid architecture diagram, prioritized checklist linking all individual issues (High → Medium → Low), and success criteria:

  • All High-risk findings resolved
  • Medium findings have accepted mitigation plans
  • No regression in existing Azure Monitor alerts or Azure Policy compliance

Error Handling

  • No IaC Files Found: Limit review to live resource discovery via Azure CLI (az resource list) and note the gap
  • Insufficient Azure Permissions: List required read-only roles for the review (Reader, Security Reader)
  • GitHub Creation Failure: Output all findings as formatted markdown to console

Success Criteria

  • ✅ All 5 WAF pillars reviewed against IaC and live infrastructure
  • ✅ All findings classified by risk level and pillar
  • ✅ Actionable remediation steps with IaC examples for each finding
  • ✅ GitHub issues created for team tracking
  • ✅ Architecture diagram generated for EPIC context
  • ✅ Microsoft Learn documentation references included

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-well-architected-review of github/awesome-copilot.

Open the folder on GitHubat commit 727ff2e

Compare with similar skills

Azure Well Architected Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Well Architected Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Well Architected Review this skillgithub/awesome-copilot40k—~2.5kAutomated safety check: PassMIT
Azv Bicep Diagram SyncAzure/AZVerify101—~2.9kAutomated safety check: PassMIT
Apex GitHub Operationsjonathan-vella/apex217—~1.5kAutomated safety check: PassMIT
Azv Diagram To BicepAzure/AZVerify101—~3.1kAutomated safety check: WarnMIT
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Azsdk Common Live And Recorded TestsAzure/azure-sdk-tools134—~1.5kAutomated safety check: NotesMIT

Similar skills

  • Official

    Compare Bicep templates against a Draw.io Azure architecture diagram to detect resource-level divergence.

    101 GitHub stars~2.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Apex GitHub Operations

    jonathan-vella/apex

    WORKFLOW SKILL — Full GitHub contribution lifecycle: branches, conventional commits, issues, PRs, Actions, releases.

    217 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azv Diagram To Bicep

    Azure/AZVerify

    Official

    Generate deployment-ready Bicep templates and PowerShell scripts from an approved Draw.io Azure architecture diagram.

    101 GitHub stars~3.1k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: warnings
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Official

    Deploy test resources and run Azure SDK tests in live, record, or playback mode.

    134 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Azv Azure To Bicep

    Azure/AZVerify

    Official

    Reverse-engineer a live Azure scope (resource group or filtered subscription) into deployment-ready, modular Bicep templates with parameter files.

    101 GitHub stars~5.4k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: warnings

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Azure Well Architected Review

What does Azure Well Architected Review do?

Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements. Azure Well Architected Review is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Perform an Azure Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements.

When should I use Azure Well Architected Review?

Azure Well Architected Review fits situations like: tasks that involve Cloud architecture; tasks that involve Infrastructure as code.

How do I install Azure Well Architected Review in Claude Code?

Run `npx skills add github/awesome-copilot --skill azure-well-architected-review -a claude-code`. Or copy the skill folder (skills/azure-well-architected-review in github/awesome-copilot) into .claude/skills/azure-well-architected-review in your project. Claude Code loads it when a task matches its description.

How do I install Azure Well Architected Review in Codex?

Run `npx skills add github/awesome-copilot --skill azure-well-architected-review -a codex`. Or copy the skill folder (skills/azure-well-architected-review in github/awesome-copilot) into .agents/skills/azure-well-architected-review in your project. Codex loads it when a task matches its description.

Can I use Azure Well Architected Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill azure-well-architected-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-well-architected-review, .gemini/skills/azure-well-architected-review, .github/skills/azure-well-architected-review and .opencode/skills/azure-well-architected-review in your project.

What does Azure Well Architected Review need to run?

Going by SKILL.md and its folder, Azure Well Architected Review needs the command-line tools its instructions call (az).

Does Azure Well Architected Review access the network?

SKILL.md names 1 domain. In commands or code: learn.microsoft.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Azure Well Architected Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Well Architected Review use?

Azure Well Architected Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Well Architected Review use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Well Architected Review?

Skills that share tags, products or a category with Azure Well Architected Review: Azv Bicep Diagram Sync (Azure/AZVerify, 101 stars), Apex GitHub Operations (jonathan-vella/apex, 217 stars), Azv Diagram To Bicep (Azure/AZVerify, 101 stars) and Azure Bicep Skill (timothywarner-org/claude-code, 224 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Well Architected Review?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.