Official agent skill

Azure App Onboard Prereq

by microsoft in microsoft/GitHub-Copilot-for-Azure

Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure App Onboard Prereq

skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-app-onboard-prereq -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-app-onboard-prereq --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-skills/skills/azure-app-onboard-prereq .claude/skills/azure-app-onboard-prereq && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-app-onboard-prereq
GitHub stars
255
Token cost
~2.5k tokens
SKILL.md length
951 words
Files
17 (incl. references)
Skills in repo
61
Repo updated
First seen
Licence
MIT

At a glance

Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work.

  • Works in 8 steps: Session Check → Scan Workspace → Per-Component Evaluation → …
  • Tasks that involve Deployment
  • SKILL.md covers When NOT to Use, Rules, MCP Tools and Workflow, plus 1 more section
  • Runs TypeScript scripts from its folder; calls npm, dotnet and npx

What it does

Azure App Onboard Prereq is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work. Evaluates build health, app completeness, dependencies and local services, stack compatibility, and deployment feasibility. Answers questions about what your app needs before it can be deployed — frameworks, dependencies, and configuration. Checks whether dependencies are compatible and identifies deployment blockers and unsupported frameworks. WHEN: "evaluate my repo", "is my app ready to deploy", "what does my app…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 17 other files, including reference files (for example `references/build-check.md`, `references/cloud-sdk-migration.md` and `references/completeness-check.md`).

It sits in DevOps & Cloud, covering Deployment and Containers. It works with Microsoft Azure, Docker, npm and .NET. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.

When your agent uses it

  • Tasks that involve Deployment
  • Tasks that involve Containers

Example prompts

  • “evaluate my repo”
  • “is my app ready to deploy”
  • “what does my app need to deploy”
  • “/azure-app-onboard-prereq”

Requirements

  • Python 3
  • Node.js

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Session Check
  2. Scan Workspace
  3. Per-Component Evaluation
  4. Write Artifacts + Readiness Gate
  5. Present Findings
  6. Remediation (conditional)
  7. Write Final State
  8. Route

What it can do on your machine

Read from SKILL.md and the folder at commit ce94fce. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (TypeScript), which the agent can run.

    Shell commands in SKILL.md call:

    • npm
    • dotnet
    • npx
    • pip
    • go
    • cargo
    • az
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, npx, pip, az and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure App Onboard Prereq loads about 2.5k tokens when it runs, and up to ~20k if it reads all its reference files. Until then it costs about 239 tokens; SKILL.md has 951 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~239
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~20k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/GitHub-Copilot-for-Azure at commit ce94fce, republished under its MIT licence (© microsoft). 951 words, ~2,517 tokens.

Download SKILL.mdSave it as .claude/skills/azure-app-onboard-prereq/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.
name
azure-app-onboard-prereq
description
Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work. Evaluates build health, app completeness, dependencies and local services, stack compatibility, and deployment feasibility. Answers questions about what your app needs before it can be deployed — frameworks, dependencies, and configuration. Checks whether dependencies are compatible and identifies deployment blockers and unsupported frameworks. WHEN: "evaluate my repo", "is my app ready to deploy", "what does my app need to deploy", "what do I need before deploying", "does my app need", "can I ship this to Azure", "scan my repo for issues", "is this app deployable", "check if my app is ready for Azure", "do I need a Dockerfile", "what's blocking my deployment", "are there any blockers", "are my dependencies compatible", "does Azure support my framework", "what needs to change before deploying", "check my app configuration".
license
MIT
metadata.author
Microsoft
metadata.version
0.0.0-placeholder

Azure App Onboard Prereq — Repository Evaluation

Evaluate a user's repository for build health, app completeness, and Azure deployment feasibility — before infrastructure planning. Produces per-component verdicts (PASS/WARN/FAIL) consumed by downstream phases.

Orchestrator relationship: Called by azure-app-onboard at Step 3, or standalone for code readiness checks. When called by orchestrator, return control to azure-app-onboard after writing artifacts — do NOT invoke downstream phases directly.

Phase 1 of 4 in AppOnboard pipeline. Session: .copilot-azure/sessions/{session-id}/. Reads context.json. Writes components[], repo{}, detectedInfra[]. Produces prereq-output.json. Schema: prereq-schemas.ts — PrereqOutput, BuildRequirements. Direct entry supported.

When NOT to Use

SignalRedirect
Validate infrastructure (Bicep/TF/azure.yaml)azure-validate
Generate IaCazure-prepare
End-to-end idea-to-productionazure-app-onboard
Run azd up or deployazure-deploy

Rules

⛔ ABSOLUTE PROHIBITION — npm install, npm test, npx jest, pytest, and ALL install/build/test commands are NEVER allowed. Under NO circumstances may you run npm install, npm test, npx jest, pip install, pytest, dotnet build, dotnet restore, dotnet test, go mod download, cargo build, or ANY package-manager install, build, or test command during the prereq phase. Do NOT run test suites to verify code — check for test config files statically instead. The prereq phase is read-only evaluation + static-only verification. ONLY exception — two sanctioned contexts, both consent-gated: (a) code the agent modified during migration/remediation (see remediation-protocol.md step 6), or (b) code the agent wrote from scratch on the zero-code path (see zero-code-path.md). In either case, install/build/test runs ONLY via the user-confirmed build-validation gate (build-check.md Step 3), after the user answers that specific per-command consent prompt. General prior consent never counts.

  1. ⛔ Full pipeline (Steps 1–8), no exceptions. All prompts → Step 1 directly. Answer specific questions AS PART OF findings (Step 5), not before.
  2. ⛔ No sub-agents for evaluation. 3-axis evaluation is inline. Exception: zero-code-path scaffolding (Step 2).
  3. Code/destructive modifications require ask_user. Max 3 questions before results. Direct entry: don't repeat orchestrator's intent questions.

MCP Tools

ToolPurpose
mcp_azure_mcp_get_azure_bestpracticesValidate detected stack patterns against Azure best practices
mcp_azure_mcp_extension_cli_installCheck/install required CLI tools (az, azd, func)

Workflow

Step 1: Session Check

Orchestrator entry: Session exists — read context.json, proceed to Step 2.

Direct entry: Check .copilot-azure/sessions/active-session.json:

  • Exists → ⛔ read session-protocol.md for resume/fresh gate. Do NOT proceed until user answers.
  • Missing → create session: generate UUID, New-Item -ItemType Directory -Path ".copilot-azure/sessions/{uuid}" -Force, write context.json + active-session.json via create tool.

Then: az account show → merge {id, name, tenantId} into context.json.azure. ⛔ Session MUST exist on disk before any scanning.

Step 2: Scan Workspace

Scan for project files. Detect components, repo{}, detectedInfra[], detectedServices[]. Classify Terraform providers. Check CLI availability. Stack detection conflicts: user explicit statement wins (write to context.json, mark scan as override); scan-only → confirm with user; multiple stacks → show all and ask (see component-mapping.md); no code → zero-code-path.md.

If no project files, no Dockerfile, AND no index.html → ⛔ read zero-code-path.md.

⛔ Cloud SDK early gate. Grep for aws-sdk|@aws-sdk|boto3|google-cloud|@google-cloud|firebase. If functional deps found → read cloud-sdk-migration.md, then ask_user: "Redirect to Azure Cloud Migrate" (set routeToSkill: "azure-cloud-migrate") · "Continue evaluation anyway" (finish readiness eval + SDK→Azure mapping, then STOP at Step 8 — no plan until the deps are swapped) · "Cancel".

Step 3: Per-Component Evaluation
Sub-stepActionReference
3.1Build check⛔ You MUST read build-check.md
3.2Completeness check⛔ You MUST read completeness-check.md
3.3Deployability check⛔ You MUST read deployability-check.md
3.3aComponent mapping (conditional)Read component-mapping.md ONLY IF >1 project manifest found (monorepo)

Populate buildRequirements per component after evaluation. Verdict propagation, tier rules, and f1Viable aggregation are in readiness-gate.md and the individual check references.

Step 4: Write Artifacts + Readiness Gate

⛔ Verify context.json exists on disk. Read readiness-gate.md (verdicts, tiers, batch-then-approve, fast-track) then prereq-artifacts.md (write procedures, schemas).

Show full SKILL.md (378 more words)Show less
Step 5: Present Findings

Per readiness-gate.md § Present Findings — show verdicts grouped by severity before proceeding.

Step 6: Remediation (conditional)

⛔ You MUST read remediation-protocol.md IF any ❌ FAIL verdict, 🔧 Recommended Fix, or ⚠️ WARN with fixPhase: "prereq" exists. Contains remediation loop, static verification, re-eval mandate, post-remediation artifact updates, and the build-validation consent gate. If all verdicts are ✅ PASS or ⚠️ WARN without fixPhase: "prereq", skip to Step 7.

Step 7: Write Final State

completedPhases already has "prereq" + currentPhase: null (from Step 4). Then:

⛔ Write lastScanCommit. Run git rev-parse HEAD and store the full 40-character SHA as context.json.repo.lastScanCommit. Required — staleness guard in Step 1 compares to HEAD on resume to detect changes.

Step 8: Route

⛔ Mandatory — do NOT skip this step.

Routing fields: All routing writes routeToSkill and routeReason to context.json.

Post-remediation context: If Step 6 ran, lead the routing prompt with: "Remediation complete — {N} issues fixed, your app is now {overallHealth}."

⛔ Evaluate rows top to bottom — first match wins.

#ConditionAction
1routeToSkill set (any entry)ask_user: "Redirect to {routeToSkill}" / "Not now". ⛔ Pipeline stops — do NOT proceed to architecture planning.
2cloudSdkFindings[] non-empty (user chose "Continue evaluation anyway")Present the cloud-SDK → Azure swap mapping as 🔶 blockers, then ask_user with this exact prompt: "🔶 Cloud SDK migration required — these dependencies must be swapped before this app can deploy to Azure. (Redirect to azure-cloud-migrate / Stop — swap manually and re-run)" — Redirect sets routeToSkill: "azure-cloud-migrate", Stop halts. ⛔ Pipeline stops — do NOT proceed to architecture planning, and do NOT offer a "continue to prepare" option; the app can't deploy until the deps are swapped.
3Orchestrator + no routeToSkillTell the user: "✅ Your app has been evaluated and is ready — let's plan your Azure deployment." Then invoke azure-app-onboard. ⛔ Do NOT stop, do NOT wait for user input, do NOT narrate internal handoffs. The user already consented to the full pipeline at scope triage.
4Direct + ready/readyWithCaveats + no Azure infraask_user: "Deploy to Azure (full pipeline)" → invoke azure-app-onboard / "Not now"
5Direct + ready/readyWithCaveats + existing Azure infraask_user: "Start fresh" → invoke azure-app-onboard / "Use existing infra" → invoke azure-prepare / "Not now"
6Direct + blockedReport blocker summary + "Fix and re-run."

Severity tiers (🛑🔶❌🔧⚠️✅) are defined in readiness-gate.md.

Outputs

ArtifactLocationConsumer
Session contextcontext.json → components[], repo{}, detectedInfra[], detectedServices[]All downstream phases
Prereq outputprereq-output.jsonprepare phase (via azure-app-onboard)
Readiness report.copilot-azure/sessions/{uuid}/readiness-report.mdUser (offline reference)

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 16 other files (references) in plugins/azure-skills/skills/azure-app-onboard-prereq of microsoft/GitHub-Copilot-for-Azure.

  • SKILL.md
  • references/build-check.md
  • references/cloud-sdk-migration.md
  • references/completeness-check.md
  • references/component-mapping.md
  • references/dependency-compatibility.md
  • references/deployability-check.md
  • references/prereq-artifacts.md
  • references/prereq-schemas.ts
  • references/readiness-gate.md
  • references/remediation-protocol.md
  • references/session-protocol.md
  • references/session-schemas.ts
  • references/subagent-starter-scaffold.md
  • references/subscription-resolution.md
  • references/zero-code-path.md
  • version.json

Open the folder on GitHubat commit ce94fce

Used in 2 other repositories

We found 3 copies of this SKILL.md (exact, near-identical or edited) in other folders. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Azure App Onboard Prereq next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure App Onboard Prereq compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure App Onboard Prereq this skillmicrosoft/GitHub-Copilot-for-Azure255—~2.5kAutomated safety check: PassMIT
Reflexo ReleaseMyriad-Dreamin/typst.ts1.2k—~1.5kAutomated safety check: PassApache-2.0
Aspiremicrosoft/aspire.dev1964 repos~1.1kAutomated safety check: PassMIT
Image Managementdotnet/dotnet-docker4.9k—~1.1kAutomated safety check: PassMIT
Aspire DeploymentCommunityToolkit/Aspire629—~4.5kAutomated safety check: NotesMIT
Deploying To Azuremicrosoft-foundry/foundry-agent-webapp127—~2.2kAutomated safety check: WarnMIT

Similar skills

  • Reflexo Release

    Myriad-Dreamin/typst.ts

    Guide Reflexo/typst.ts release preparation and operator handoffs.

    1.2k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Aspire

    microsoft/aspire.dev

    Official

    Orchestrates Aspire distributed applications using the Aspire CLI for running, debugging, and managing distributed apps.

    196 GitHub starsUsed in 4 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Image Management

    dotnet/dotnet-docker

    Official

    Manages .NET Docker images including adding images for new .NET versions, new Linux distros (Alpine, Ubuntu, Azure Linux), and new Windows versions.

    4.9k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Aspire Deployment

    CommunityToolkit/Aspire

    WORKFLOW SKILL — Deploy Aspire apps from AppHost models to Docker Compose, Kubernetes, Azure, AWS, or preview Radius.

    629 GitHub stars~4.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Deploying To Azure

    microsoft-foundry/foundry-agent-webapp

    Provides deployment commands and troubleshooting for Azure Container Apps.

    127 GitHub stars~2.2k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check: warnings
  • Azure Anomaly Detector

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Anomaly Detector development including troubleshooting, best practices, limits & quotas, configuration, and deployment.

    777 GitHub stars~1.1k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed

More from microsoft/GitHub-Copilot-for-Azure

All 61 skills in this repo
  • Capacity

    microsoft/GitHub-Copilot-for-Azure

    Official

    Discovers available Azure OpenAI model capacity across regions and projects.

    255 GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • Deploy Model

    microsoft/GitHub-Copilot-for-Azure

    Official

    Unified Azure OpenAI model deployment skill with intelligent intent-based routing.

    255 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Microsoft Foundry

    microsoft/GitHub-Copilot-for-Azure

    Official

    Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.

    255 GitHub starsUsed in 1 repo~6.7k tokens
    Auto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 2 repos~4k tokens
    Auto-check passed
  • Azure Kubernetes Automatic Readiness

    microsoft/GitHub-Copilot-for-Azure

    Official

    Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.

    255 GitHub starsUsed in 1 repo~4.4k tokens
    Auto-check passed

Categories

Questions about Azure App Onboard Prereq

What does Azure App Onboard Prereq do?

Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work. Azure App Onboard Prereq is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work.

When should I use Azure App Onboard Prereq?

Azure App Onboard Prereq fits situations like: tasks that involve Deployment; tasks that involve Containers.

How do I install Azure App Onboard Prereq in Claude Code?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-app-onboard-prereq -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/azure-app-onboard-prereq in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/azure-app-onboard-prereq in your project. Claude Code loads it when a task matches its description.

How do I install Azure App Onboard Prereq in Codex?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-app-onboard-prereq -a codex`. Or copy the skill folder (plugins/azure-skills/skills/azure-app-onboard-prereq in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/azure-app-onboard-prereq in your project. Codex loads it when a task matches its description.

Can I use Azure App Onboard Prereq in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-app-onboard-prereq -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-app-onboard-prereq, .gemini/skills/azure-app-onboard-prereq, .github/skills/azure-app-onboard-prereq and .opencode/skills/azure-app-onboard-prereq in your project.

What does Azure App Onboard Prereq need to run?

Going by SKILL.md and its folder, Azure App Onboard Prereq needs TypeScript for the scripts in its folder and the command-line tools its instructions call (npm, dotnet, npx, pip, go and cargo). Our summary lists: Python 3; Node.js.

Does Azure App Onboard Prereq access the network?

SKILL.md contains no URLs. Its commands use npm, npx, pip and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Azure App Onboard Prereq safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure App Onboard Prereq use?

Azure App Onboard Prereq is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure App Onboard Prereq use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 17k tokens, read only when the agent opens those files.

What are the alternatives to Azure App Onboard Prereq?

Skills that share tags, products or a category with Azure App Onboard Prereq: Reflexo Release (Myriad-Dreamin/typst.ts, 1.2k stars), Aspire (microsoft/aspire.dev, 196 stars), Image Management (dotnet/dotnet-docker, 4.9k stars) and Aspire Deployment (CommunityToolkit/Aspire, 629 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure App Onboard Prereq?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 9, 2026.

Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.