Azure Architecture Autopilot
github/awesome-copilot
Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.
End-of-session validation for MI and OBO deployment paths. An agent skill from microsoft-foundry/foundry-agent-webapp.
$ npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft-foundry/foundry-agent-webapp validating-deployments --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft-foundry/foundry-agent-webapp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/validating-deployments .claude/skills/validating-deployments && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "validating-deployments" agent skill from https://github.com/microsoft-foundry/foundry-agent-webapp/tree/main/.github/skills/validating-deployments into .claude/skills/validating-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-deployments", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft-foundry/foundry-agent-webapp/tree/main/.github/skills/validating-deploymentsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft-foundry/foundry-agent-webapp validating-deployments --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft-foundry/foundry-agent-webapp.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/validating-deployments .agents/skills/validating-deployments && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "validating-deployments" agent skill from https://github.com/microsoft-foundry/foundry-agent-webapp/tree/main/.github/skills/validating-deployments into .agents/skills/validating-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-deployments", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft-foundry/foundry-agent-webapp validating-deployments --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft-foundry/foundry-agent-webapp.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/validating-deployments .cursor/skills/validating-deployments && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "validating-deployments" agent skill from https://github.com/microsoft-foundry/foundry-agent-webapp/tree/main/.github/skills/validating-deployments into .cursor/skills/validating-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-deployments", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft-foundry/foundry-agent-webapp.git --path .github/skills/validating-deployments--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft-foundry/foundry-agent-webapp validating-deployments --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft-foundry/foundry-agent-webapp.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/validating-deployments .gemini/skills/validating-deployments && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "validating-deployments" agent skill from https://github.com/microsoft-foundry/foundry-agent-webapp/tree/main/.github/skills/validating-deployments into .gemini/skills/validating-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-deployments", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft-foundry/foundry-agent-webapp validating-deploymentsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft-foundry/foundry-agent-webapp.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/validating-deployments .github/skills/validating-deployments && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "validating-deployments" agent skill from https://github.com/microsoft-foundry/foundry-agent-webapp/tree/main/.github/skills/validating-deployments into .github/skills/validating-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-deployments", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft-foundry/foundry-agent-webapp validating-deployments --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft-foundry/foundry-agent-webapp.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/validating-deployments .opencode/skills/validating-deployments && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "validating-deployments" agent skill from https://github.com/microsoft-foundry/foundry-agent-webapp/tree/main/.github/skills/validating-deployments into .opencode/skills/validating-deployments/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "validating-deployments", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
validating-deploymentsEnd-of-session validation for MI and OBO deployment paths. An agent skill from microsoft-foundry/foundry-agent-webapp.
Validating Deployments is an agent skill from microsoft-foundry/foundry-agent-webapp. End-of-session validation for MI and OBO deployment paths. Use after code changes to verify deploy → test → teardown works end-to-end.
Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Deployment. It works with Bicep and Playwright. The repository describes itself as: GitHub Copilot enabled repo for building and deploying a web application with Entra ID authentication and integrated with Azure AI Foundry Agents. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit f6cb362. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmdotnetaznodehadolintnpxFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
ai.azure.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Validating Deployments loads about 1.1k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 279 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
# - frontend/.env.local deleted# - backend/WebApp.Api/.env deletedAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from microsoft-foundry/foundry-agent-webapp at commit f6cb362, republished under its MIT licence (© microsoft-foundry). 279 words, ~1,056 tokens.
.claude/skills/validating-deployments/SKILL.md (or your agent's skills folder).Run this at the end of any session that changes backend, frontend, infra, or auth code.
dotnet test + npm test)npm run build)az bicep build --file infra/main.bicep)npx playwright install chromium)Run before every deployment:
# Backend: check for vulnerable NuGet packages
cd backend && dotnet list package --vulnerable
# Frontend: check for vulnerable npm packages
cd frontend && npm audit
# Docker: lint Dockerfile for security issues (if hadolint installed)
hadolint deployment/docker/frontend.DockerfileThe Dockerfile runs as non-root (USER app). Verify this hasn't been removed after changes.
azd env new mi-test --no-prompt
azd env set ENTRA_SERVICE_MANAGEMENT_REFERENCE "<guid-from-admin>" # Required by some orgs
azd env set AZURE_LOCATION eastus2 --no-prompt
azd up --no-prompt$endpoint = azd env get-value WEB_ENDPOINT
node deployment/scripts/smoke-test.js $endpointVerify: health 200, agent name displayed, chat streaming works, token usage visible.
cd backend/WebApp.Api
$env:ASPNETCORE_ENVIRONMENT = "Development" # CRITICAL — without this, uses ManagedIdentityCredential which fails locally
$env:ASPNETCORE_URLS = "http://localhost:8080"
dotnet watch run --no-launch-profile &
cd ../../frontend
npm run dev &
# Wait for both servers, then:
node deployment/scripts/smoke-test.js http://localhost:5173azd down --force --purge --environment mi-test --no-prompt
# Verify:
# - frontend/.env.local deleted
# - backend/WebApp.Api/.env deleted
# - .azure/mi-test/ deleted
# - Entra app deleted (check azd logs)azd env new obo-test --no-prompt
azd env set ENABLE_OBO true --no-prompt
azd env set AZURE_LOCATION eastus2 --no-prompt
# No SMR needed if using a non-MSFT tenant
azd up --no-prompt# Check backend logs for OBO mode
az containerapp logs show --name <app-name> --resource-group <rg> --type console --tail 20 | Select-String "OBO"
# Expected: "OBO mode enabled: backendClientId=..."
# Expected: "Created OBO credential for request" (after first chat)Run smoke test. OBO requires interactive MSAL login (user must sign in with test tenant credentials). The smoke test will wait at auth if no cached session exists.
Same as MI path. Additionally verify:
| Gotcha | Detail |
|---|---|
ASPNETCORE_ENVIRONMENT=Development | Required for local dev — without it, backend tries ManagedIdentityCredential which fails on dev machines |
| SMR required | Set ENTRA_SERVICE_MANAGEMENT_REFERENCE or Entra app creation fails |
| Bicep FIC creation may fail | Graph API eventual consistency issue. Workaround: create FIC via az ad app federated-credential create |
v2 agent API requires kind: "prompt" | When creating agents via REST, use definition: { kind: "prompt", model: "...", instructions: "..." } |
OBO scope is api://{BACKEND}/Chat.ReadWrite | NOT api://{SPA}/Chat.ReadWrite. Token audience mismatch = AADSTS500131 |
| AI scope resolves to Azure ML Services | https://ai.azure.com/.default → appId 18a66f5f-... (Azure Machine Learning Services), NOT 7d312290-... (Cognitive Services) |
| Conversation history not user-scoped in MI mode | MI uses shared identity — all users see all conversations |
© microsoft-foundry, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/validating-deployments of microsoft-foundry/foundry-agent-webapp.
Open the folder on GitHubat commit f6cb362
Validating Deployments next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Validating Deployments this skillmicrosoft-foundry/foundry-agent-webapp | 127 | — | ~1.1k | Automated safety check: Notes | MIT | |
| Azure Architecture Autopilotgithub/awesome-copilot | 40k | 1 repos | ~1.9k | Automated safety check: Pass | MIT | |
| Aspiremicrosoft/aspire.dev | 196 | 4 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Azure Bicep Skilltimothywarner-org/claude-code | 224 | — | ~2.9k | Automated safety check: Pass | MIT | |
| APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills | 202 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Azsdk Common Live And Recorded TestsAzure/azure-sdk-tools | 134 | — | ~1.5k | Automated safety check: Notes | MIT |
github/awesome-copilot
Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.
microsoft/aspire.dev
Orchestrates Aspire distributed applications using the Aspire CLI for running, debugging, and managing distributed apps.
timothywarner-org/claude-code
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
thomast1906/github-copilot-agent-skills
Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.
Azure/azure-sdk-tools
Deploy test resources and run Azure SDK tests in live, record, or playback mode.
vercel/vercel-plugin
Access and test Vercel deployments protected by Vercel Authentication, SSO, or Deployment Protection.
microsoft-foundry/foundry-agent-webapp
Provides commit message format and workflow for this repository.
microsoft-foundry/foundry-agent-webapp
Provides SSE streaming patterns for the chat API and frontend.
microsoft-foundry/foundry-agent-webapp
Provides structured plan template for feature implementation.
microsoft-foundry/foundry-agent-webapp
Provides research patterns for Foundry Agent Service SDK. An agent skill from microsoft-foundry/foundry-agent-webapp.
microsoft-foundry/foundry-agent-webapp
Provides deployment commands and troubleshooting for Azure Container Apps.
microsoft-foundry/foundry-agent-webapp
Synchronize MCP server configuration between VS Code (.vscode/mcp.json) and Copilot CLI (~/.copilot/mcp-config.json).
Works with
Categories
End-of-session validation for MI and OBO deployment paths. An agent skill from microsoft-foundry/foundry-agent-webapp. Validating Deployments is an agent skill from microsoft-foundry/foundry-agent-webapp. End-of-session validation for MI and OBO deployment paths.
Validating Deployments fits situations like: tasks that involve Deployment.
Run `npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a claude-code`. Or copy the skill folder (.github/skills/validating-deployments in microsoft-foundry/foundry-agent-webapp) into .claude/skills/validating-deployments in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a codex`. Or copy the skill folder (.github/skills/validating-deployments in microsoft-foundry/foundry-agent-webapp) into .agents/skills/validating-deployments in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validating-deployments, .gemini/skills/validating-deployments, .github/skills/validating-deployments and .opencode/skills/validating-deployments in your project.
Going by SKILL.md and its folder, Validating Deployments needs the command-line tools its instructions call (npm, dotnet, az, node, hadolint and npx). Our summary lists: Node.js; Docker.
SKILL.md names 1 domain. In commands or code: ai.azure.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Validating Deployments is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Validating Deployments: Azure Architecture Autopilot (github/awesome-copilot, 40k stars), Aspire (microsoft/aspire.dev, 196 stars), Azure Bicep Skill (timothywarner-org/claude-code, 224 stars) and APIOps Deployment for Azure APIM (thomast1906/github-copilot-agent-skills, 202 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft-foundry (a GitHub organization) maintains it in microsoft-foundry/foundry-agent-webapp, which has 127 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on April 21, 2026.
Source: microsoft-foundry/foundry-agent-webapp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.