Agent skill

Validating Deployments

by microsoft-foundry in microsoft-foundry/foundry-agent-webapp

End-of-session validation for MI and OBO deployment paths. An agent skill from microsoft-foundry/foundry-agent-webapp.

MITAuto-check: notesDevOps & Cloud

Install Validating Deployments

skills CLI
$ npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft-foundry/foundry-agent-webapp validating-deployments --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft-foundry/foundry-agent-webapp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/validating-deployments .claude/skills/validating-deployments && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
validating-deployments
GitHub stars
127
Token cost
~1.1k tokens
SKILL.md length
279 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

End-of-session validation for MI and OBO deployment paths. An agent skill from microsoft-foundry/foundry-agent-webapp.

  • Works in 8 steps: Deploy → Test Remote → Test Local Dev → …
  • Tasks that involve Deployment
  • SKILL.md covers Prerequisites, Security Checks, MI Path (Default) and OBO Path, plus 2 more sections
  • Calls npm, dotnet and az; reaches ai.azure.com

What it does

Validating Deployments is an agent skill from microsoft-foundry/foundry-agent-webapp. End-of-session validation for MI and OBO deployment paths. Use after code changes to verify deploy → test → teardown works end-to-end.

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Deployment. It works with Bicep and Playwright. The repository describes itself as: GitHub Copilot enabled repo for building and deploying a web application with Entra ID authentication and integrated with Azure AI Foundry Agents. The licence is MIT.

When your agent uses it

  • Tasks that involve Deployment

Example prompts

  • “/validating-deployments”

Requirements

  • Node.js
  • Docker

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Deploy
  2. Test Remote
  3. Test Local Dev
  4. Teardown
  5. Deploy
  6. Verify OBO Wiring
  7. Test
  8. Teardown

What it can do on your machine

Read from SKILL.md and the folder at commit f6cb362. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • dotnet
    • az
    • node
    • hadolint
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • ai.azure.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Validating Deployments loads about 1.1k tokens when it runs. Until then it costs about 39 tokens; SKILL.md has 279 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~39
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:76
    # - frontend/.env.local deleted
  • NoteMentions a .env fileSKILL.md:77
    # - backend/WebApp.Api/.env deleted

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft-foundry/foundry-agent-webapp at commit f6cb362, republished under its MIT licence (© microsoft-foundry). 279 words, ~1,056 tokens.

Download SKILL.mdSave it as .claude/skills/validating-deployments/SKILL.md (or your agent's skills folder).
name
validating-deployments
description
End-of-session validation for MI and OBO deployment paths. Use after code changes to verify deploy → test → teardown works end-to-end.

Validating Deployments

Run this at the end of any session that changes backend, frontend, infra, or auth code.

Prerequisites

  • All unit tests pass (dotnet test + npm test)
  • Frontend builds (npm run build)
  • Bicep validates (az bicep build --file infra/main.bicep)
  • Playwright installed (npx playwright install chromium)

Security Checks

Run before every deployment:

powershell
# Backend: check for vulnerable NuGet packages
cd backend && dotnet list package --vulnerable

# Frontend: check for vulnerable npm packages
cd frontend && npm audit

# Docker: lint Dockerfile for security issues (if hadolint installed)
hadolint deployment/docker/frontend.Dockerfile

The Dockerfile runs as non-root (USER app). Verify this hasn't been removed after changes.

MI Path (Default)

1. Deploy
powershell
azd env new mi-test --no-prompt
azd env set ENTRA_SERVICE_MANAGEMENT_REFERENCE "<guid-from-admin>"  # Required by some orgs
azd env set AZURE_LOCATION eastus2 --no-prompt
azd up --no-prompt
2. Test Remote
powershell
$endpoint = azd env get-value WEB_ENDPOINT
node deployment/scripts/smoke-test.js $endpoint

Verify: health 200, agent name displayed, chat streaming works, token usage visible.

3. Test Local Dev
powershell
cd backend/WebApp.Api
$env:ASPNETCORE_ENVIRONMENT = "Development"  # CRITICAL — without this, uses ManagedIdentityCredential which fails locally
$env:ASPNETCORE_URLS = "http://localhost:8080"
dotnet watch run --no-launch-profile &

cd ../../frontend
npm run dev &

# Wait for both servers, then:
node deployment/scripts/smoke-test.js http://localhost:5173
4. Teardown
powershell
azd down --force --purge --environment mi-test --no-prompt
# Verify:
# - frontend/.env.local deleted
# - backend/WebApp.Api/.env deleted
# - .azure/mi-test/ deleted
# - Entra app deleted (check azd logs)

OBO Path

1. Deploy
powershell
azd env new obo-test --no-prompt
azd env set ENABLE_OBO true --no-prompt
azd env set AZURE_LOCATION eastus2 --no-prompt
# No SMR needed if using a non-MSFT tenant
azd up --no-prompt
2. Verify OBO Wiring
powershell
# Check backend logs for OBO mode
az containerapp logs show --name <app-name> --resource-group <rg> --type console --tail 20 | Select-String "OBO"
# Expected: "OBO mode enabled: backendClientId=..."
# Expected: "Created OBO credential for request" (after first chat)
3. Test

Run smoke test. OBO requires interactive MSAL login (user must sign in with test tenant credentials). The smoke test will wait at auth if no cached session exists.

4. Teardown

Same as MI path. Additionally verify:

  • Backend API app registration deleted (postdown.ps1 handles this)
  • FIC removed with the app

Gotchas

GotchaDetail
ASPNETCORE_ENVIRONMENT=DevelopmentRequired for local dev — without it, backend tries ManagedIdentityCredential which fails on dev machines
SMR requiredSet ENTRA_SERVICE_MANAGEMENT_REFERENCE or Entra app creation fails
Bicep FIC creation may failGraph API eventual consistency issue. Workaround: create FIC via az ad app federated-credential create
v2 agent API requires kind: "prompt"When creating agents via REST, use definition: { kind: "prompt", model: "...", instructions: "..." }
OBO scope is api://{BACKEND}/Chat.ReadWriteNOT api://{SPA}/Chat.ReadWrite. Token audience mismatch = AADSTS500131
AI scope resolves to Azure ML Serviceshttps://ai.azure.com/.default → appId 18a66f5f-... (Azure Machine Learning Services), NOT 7d312290-... (Cognitive Services)
Conversation history not user-scoped in MI modeMI uses shared identity — all users see all conversations
  • testing-with-playwright — Playwright MCP patterns for interactive testing
  • validating-ui-features — Step-by-step UI feature validation
  • deploying-to-azure — azd commands and troubleshooting
  • troubleshooting-authentication — MSAL/JWT debugging

© microsoft-foundry, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/validating-deployments of microsoft-foundry/foundry-agent-webapp.

Open the folder on GitHubat commit f6cb362

Compare with similar skills

Validating Deployments next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Validating Deployments compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Validating Deployments this skillmicrosoft-foundry/foundry-agent-webapp127—~1.1kAutomated safety check: NotesMIT
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT
Aspiremicrosoft/aspire.dev1964 repos~1.1kAutomated safety check: PassMIT
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills202—~3.6kAutomated safety check: PassMIT
Azsdk Common Live And Recorded TestsAzure/azure-sdk-tools134—~1.5kAutomated safety check: NotesMIT

Similar skills

  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Aspire

    microsoft/aspire.dev

    Official

    Orchestrates Aspire distributed applications using the Aspire CLI for running, debugging, and managing distributed apps.

    196 GitHub starsUsed in 4 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Deploy test resources and run Azure SDK tests in live, record, or playback mode.

    134 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Official

    Access and test Vercel deployments protected by Vercel Authentication, SSO, or Deployment Protection.

    301 GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from microsoft-foundry/foundry-agent-webapp

All 19 skills in this repo
  • Committing Code

    microsoft-foundry/foundry-agent-webapp

    Provides commit message format and workflow for this repository.

    127 GitHub stars~512 tokensUpdated 5 mo ago
    Auto-check passed
  • Implementing Chat Streaming

    microsoft-foundry/foundry-agent-webapp

    Provides SSE streaming patterns for the chat API and frontend.

    127 GitHub stars~1.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Planning Features

    microsoft-foundry/foundry-agent-webapp

    Provides structured plan template for feature implementation.

    127 GitHub stars~548 tokensUpdated 5 mo ago
    Auto-check passed
  • Researching Azure AI SDK

    microsoft-foundry/foundry-agent-webapp

    Provides research patterns for Foundry Agent Service SDK. An agent skill from microsoft-foundry/foundry-agent-webapp.

    127 GitHub stars~4.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Deploying To Azure

    microsoft-foundry/foundry-agent-webapp

    Provides deployment commands and troubleshooting for Azure Container Apps.

    127 GitHub stars~2.2k tokensUpdated 5 mo ago
    Auto-check: warnings
  • Syncing MCP Servers

    microsoft-foundry/foundry-agent-webapp

    Synchronize MCP server configuration between VS Code (.vscode/mcp.json) and Copilot CLI (~/.copilot/mcp-config.json).

    127 GitHub stars~1.3k tokensUpdated 5 mo ago
    Auto-check passed

Works with

Questions about Validating Deployments

What does Validating Deployments do?

End-of-session validation for MI and OBO deployment paths. An agent skill from microsoft-foundry/foundry-agent-webapp. Validating Deployments is an agent skill from microsoft-foundry/foundry-agent-webapp. End-of-session validation for MI and OBO deployment paths.

When should I use Validating Deployments?

Validating Deployments fits situations like: tasks that involve Deployment.

How do I install Validating Deployments in Claude Code?

Run `npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a claude-code`. Or copy the skill folder (.github/skills/validating-deployments in microsoft-foundry/foundry-agent-webapp) into .claude/skills/validating-deployments in your project. Claude Code loads it when a task matches its description.

How do I install Validating Deployments in Codex?

Run `npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a codex`. Or copy the skill folder (.github/skills/validating-deployments in microsoft-foundry/foundry-agent-webapp) into .agents/skills/validating-deployments in your project. Codex loads it when a task matches its description.

Can I use Validating Deployments in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft-foundry/foundry-agent-webapp --skill validating-deployments -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/validating-deployments, .gemini/skills/validating-deployments, .github/skills/validating-deployments and .opencode/skills/validating-deployments in your project.

What does Validating Deployments need to run?

Going by SKILL.md and its folder, Validating Deployments needs the command-line tools its instructions call (npm, dotnet, az, node, hadolint and npx). Our summary lists: Node.js; Docker.

Does Validating Deployments access the network?

SKILL.md names 1 domain. In commands or code: ai.azure.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Validating Deployments safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Validating Deployments use?

Validating Deployments is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Validating Deployments use?

About 1.1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Validating Deployments?

Skills that share tags, products or a category with Validating Deployments: Azure Architecture Autopilot (github/awesome-copilot, 40k stars), Aspire (microsoft/aspire.dev, 196 stars), Azure Bicep Skill (timothywarner-org/claude-code, 224 stars) and APIOps Deployment for Azure APIM (thomast1906/github-copilot-agent-skills, 202 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Validating Deployments?

microsoft-foundry (a GitHub organization) maintains it in microsoft-foundry/foundry-agent-webapp, which has 127 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on April 21, 2026.

Source: microsoft-foundry/foundry-agent-webapp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.