Agent Prompt Engineering
agentailor/fullstack-langgraph-nextjs-agent
Comprehensive guide for designing, refining, and auditing system prompts for autonomous AI agents based on Anthropic's production practices.
Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill microsoft-foundry -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure microsoft-foundry --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-skills/skills/microsoft-foundry .claude/skills/microsoft-foundry && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "microsoft-foundry" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/microsoft-foundry into .claude/skills/microsoft-foundry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "microsoft-foundry", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/microsoft-foundryType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill microsoft-foundry -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure microsoft-foundry --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/azure-skills/skills/microsoft-foundry .agents/skills/microsoft-foundry && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "microsoft-foundry" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/microsoft-foundry into .agents/skills/microsoft-foundry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "microsoft-foundry", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill microsoft-foundry -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure microsoft-foundry --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/azure-skills/skills/microsoft-foundry .cursor/skills/microsoft-foundry && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "microsoft-foundry" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/microsoft-foundry into .cursor/skills/microsoft-foundry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "microsoft-foundry", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/GitHub-Copilot-for-Azure.git --path plugins/azure-skills/skills/microsoft-foundry--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill microsoft-foundry -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure microsoft-foundry --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/azure-skills/skills/microsoft-foundry .gemini/skills/microsoft-foundry && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "microsoft-foundry" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/microsoft-foundry into .gemini/skills/microsoft-foundry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "microsoft-foundry", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/GitHub-Copilot-for-Azure microsoft-foundryInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill microsoft-foundry -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/azure-skills/skills/microsoft-foundry .github/skills/microsoft-foundry && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "microsoft-foundry" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/microsoft-foundry into .github/skills/microsoft-foundry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "microsoft-foundry", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill microsoft-foundry -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure microsoft-foundry --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/azure-skills/skills/microsoft-foundry .opencode/skills/microsoft-foundry && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "microsoft-foundry" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/microsoft-foundry into .opencode/skills/microsoft-foundry/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "microsoft-foundry", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
microsoft-foundryBuild, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.
Microsoft Foundry is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. USE FOR: foundry, azd ai agent, azd provision/deploy, hosted agent scaffold/develop/run/deploy/troubleshoot, prompt agent create, create agent, update agent, add tool to agent, invoke agent, agent.yaml, agent insights, pull agent insights, evaluate agent, batch eval, continuous eval, continuous monitoring, agent CI/CD, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions…
Its SKILL.md is about 6.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 192 other files, including scripts and reference files (for example `foundry-agent/agent-optimizer/agent-optimizer.md`, `foundry-agent/agent-optimizer/references/azd-setup.md` and `foundry-agent/agent-optimizer/references/eval-yaml.md`).
It sits in AI & LLM Engineering, covering Fine-tuning, Agent evaluation and testing and Deployment. It works with Microsoft Azure, Azure Functions and Model Context Protocol. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit d8f4f4e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
azFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Microsoft Foundry loads about 6.7k tokens when it runs, and up to ~12k if it reads all its reference files. Until then it costs about 255 tokens; SKILL.md has 2,776 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from microsoft/GitHub-Copilot-for-Azure at commit d8f4f4e, republished under its MIT licence (© microsoft). 2,776 words, ~6,701 tokens.
.claude/skills/microsoft-foundry/SKILL.md (or your agent's skills folder). This skill also uses 185 other files; get the full folder from GitHub.This skill helps developers work with Microsoft Foundry resources, covering model discovery and deployment, complete dev lifecycle of AI agent, evaluation workflows, and troubleshooting.
Follow each applicable subsection below before starting its corresponding action or workflow.
MANDATORY: As the first step after this skill loads, run the dependency check and setup script below from this skill's root and wait for it to finish before continuing. The script checks first and installs only missing dependencies; it does not reinstall dependencies that are already available.
You MUST complete this check before reading or entering any sub-skill, workflow, or workflow-specific reference.
./scripts/check-and-setup-dependencies.sh # macOS / Linux
./scripts/check-and-setup-dependencies.ps1 # Windows (pwsh)Strictly follow the script output for subsequent actions.
MANDATORY: Before executing ANY workflow-specific steps, you MUST read the corresponding sub-skill document. Do not call workflow-specific MCP tools for a workflow without reading its skill document. This applies even if you already know the MCP tool parameters — the skill document contains required workflow steps, pre-checks, and validation logic that must be followed. This rule applies on every new user message that triggers a different workflow, even if the skill is already loaded.
MANDATORY: Before using Foundry MCP operations, call the Azure MCP foundry tool and inspect the available Foundry MCP tools and related parameters. Treat this as the discovery/help step for MCP-based workflows.
MANDATORY: Before executing ANY azd command, you MUST read azd-guidance and strictly follow the shared rules defined in it, especially the AZURE_DEV_USER_AGENT setting rules.
This skill includes specialized sub-skills for specific workflows. When a sub-skill matches the task, strictly follow its workflow:
| Sub-Skill | When to Use | Reference |
|---|---|---|
| deploy | Deploy hosted agents to Foundry, smoke-test a deployment, create or update prompt agents, and manage agent versions and multi-environment deploys. | deploy |
| cicd | Set up a CI/CD deployment pipeline for a Foundry agent. | cicd |
| invoke | Send messages to an agent, single or multi-turn conversations | invoke |
| routine | Schedule or event-trigger Foundry agents with routines; use azd for CRUD, enable/disable, manual dispatch, and viewing past runs, or define routines in azure.yaml. | routine |
| invocations-ws | Build, deploy, and connect to hosted agents that speak the invocations_ws duplex WebSocket protocol — voice agents, real-time streams, and signaling for out-of-band media transports. | invocations-ws |
| observe | Evaluate agent quality, run batch evals, analyze failures, optimize prompts, improve agent instructions, compare versions, set up CI/CD monitoring, and enable continuous production evaluation | observe |
| insights | Pull generated agent insights, evidence, and recommendations from an existing monitor; read-only retrieval, not a new analysis run | insights |
| trace | Query traces, analyze latency/failures, correlate eval results to specific responses via App Insights customEvents | trace |
| troubleshoot | View hosted agent logs, query telemetry, diagnose failures | troubleshoot |
| validate | Use only when the user explicitly asks to use this validation sub-skill or to validate Microsoft Foundry hosted-agent code against best practices. Never invoke it proactively or add it to another workflow. | validate |
| create (quick start) | Create a new hosted Foundry agent from scratch end-to-end — scaffold, provision or use an existing Foundry project, deploy, and smoke-test. Do not use for any work on existing code. For anything not covered by the quickstart, use create. | create/quick-start-hosted.md |
| create | Use when the standard end-to-end happy path (quick start) doesn't fit. Create a new Foundry agent, update code of an existing agent, continue development of an existing agent, wire connections at scaffold time, use advanced setup or A2A (Agent2Agent), or recover from a failed quickstart run. | create |
| agent-optimizer | Make existing Python hosted-agent code optimization-ready, configure eval.yaml, run Agent Optimizer jobs, apply candidates locally, and deploy through azd after review. | agent-optimizer |
| eval-datasets | Harvest production traces into evaluation datasets, manage dataset versions and splits, track evaluation metrics over time, detect regressions, and maintain full lineage from trace to deployment. Use for: create dataset from traces, dataset versioning, evaluation trending, regression detection, dataset comparison, eval lineage. | eval-datasets |
| project/create | Creating a new Microsoft Foundry project for hosting agents and models. Use when onboarding to Foundry or setting up new infrastructure. | project/create/create-foundry-project.md |
| resource/create | Creating Azure AI Services multi-service resource (Foundry resource) using Azure CLI. Use when manually provisioning AI Services resources with granular control. | resource/create/create-foundry-resource.md |
| private-network | Answer questions about Foundry network isolation and deploy Foundry with VNet isolation (BYO VNet, Managed VNet, hybrid). Covers architecture concepts, template selection, deployment, and post-deployment validation. | resource/private-network/private-network.md |
| models/deploy-model | Unified model deployment with intelligent routing. Handles quick preset deployments, fully customized deployments (version/SKU/capacity/RAI), and capacity discovery across regions. Routes to sub-skills: preset (quick deploy), customize (full control), capacity (find availability). | models/deploy-model/SKILL.md |
| quota | Managing quotas and capacity for Microsoft Foundry resources. Use when checking quota usage, troubleshooting deployment failures due to insufficient quota, requesting quota increases, or planning capacity. | quota/quota.md |
| rbac | Managing RBAC permissions, role assignments, managed identities, and service principals for Microsoft Foundry resources. Use for access control, auditing permissions, and CI/CD setup. | rbac/rbac.md |
| finetuning | Fine-tune models on Microsoft Foundry — SFT distillation, DPO preference optimization, RFT with graders and tool calling. Dataset preparation, grader calibration, training, checkpoint selection, deployment, evaluation. Use for: fine-tune, SFT, DPO, RFT, training data, grader, distillation, fine-tuned model, large file upload. | finetuning/SKILL.md |
| azd-guidance | Provide shared azd knowledge and guidance for managing Foundry agents. Read this first for any workflows related to azd. | azd-guidance |
💡 Tip: For a complete onboarding flow:
project/create(public) orprivate-network(VNet isolation) →models/deploy-model→ agent workflows (create→deploy→invoke).
💡 Fine-Tuning: Use
finetuningfor all model customization — SFT distillation, DPO preference optimization, and RFT with graders. Includes quickstart, grader calibration, and training curve analysis.
💡 Model Deployment: Use
models/deploy-modelfor all deployment scenarios — it intelligently routes between quick preset deployment, customized deployment with full control, and capacity discovery across regions.
💡 Prompt Optimization: For requests like "optimize my prompt" or "improve my agent instructions," load observe and use the
prompt_optimizeMCP tool through that eval-driven workflow.
Match user intent to the correct infrastructure workflow.
| User Intent | Workflow |
|---|---|
| "Create Foundry" / "Set up Foundry" (ambiguous) | Use AskUserQuestion: (a) just an AI Services resource, (b) a project with public access, or (c) a project with network isolation? Route: (a) → resource/create, (b) → project/create, (c) → private-network |
| Set up Foundry with VNet isolation | private-network |
| Create a Foundry project (public) | project/create |
| Create a bare Foundry resource | resource/create |
Match user intent to the correct agent workflow. Read each sub-skill in order before executing.
| User Intent | Workflow (read in order) |
|---|---|
| Create a new hosted agent end-to-end (scaffold + deploy + test) | dependency check and setup → azd-guidance → quick-start-hosted (self-contained end-to-end) |
| Anything beyond the standard quickstart (existing code, migration, re-hosting, deployment customization, scaffold-time connections, A2A (Agent2Agent), recovery) | dependency check and setup → azd-guidance → create → deploy → invoke |
| Optimize existing Python hosted agent | dependency check and setup → azd-guidance → agent-optimizer → scaffold/review → eval.yaml → optimize → apply candidate → deploy → invoke |
| Deploy an agent (code already exists) | dependency check and setup → azd-guidance → deploy (includes eval-suite setup) → invoke → observe (evaluate/optimize) |
| Update/redeploy an agent after code changes | dependency check and setup → azd-guidance → deploy (includes eval-suite setup) → invoke → observe (evaluate/optimize) |
| Set up a CI/CD deployment pipeline for a hosted agent | dependency check and setup → azd-guidance → cicd |
| Invoke/test/chat with an agent | dependency check and setup → azd-guidance → invoke |
| Schedule/event-trigger an agent, or CRUD/enable/disable/dispatch a routine | dependency check and setup → azd-guidance → routine |
| Optimize / improve agent prompt or instructions | observe (Step 4: Optimize) |
| Evaluate and optimize agent (full loop) | observe |
| Enable continuous evaluation monitoring | observe (Step 6: CI/CD & Monitoring) |
| Pull agent insights / list generated issues and recommendations | dependency check and setup → insights (all pages with expanded evidence; read-only) |
| Troubleshoot an agent issue | dependency check and setup → azd-guidance → invoke → troubleshoot |
| Fix a broken agent (troubleshoot + redeploy) | dependency check and setup → azd-guidance → invoke → troubleshoot → apply fixes → deploy → invoke |
Every agent source folder can keep Foundry-specific cache and overlay state under .foundry/:
<agent-root>/
.foundry/
agent-metadata.yaml
agent-metadata.prod.yaml
suites/
datasets/
evaluators/
results/azure.yaml plus azd env get-values; do not duplicate those values in metadata when azd already provides them.agent-metadata.yaml is the preferred local/dev overlay for non-azd values, remote Foundry suite references, local cache paths, result summaries, and explicit overrides. Optional sidecar files such as agent-metadata.prod.yaml can hold a single prod or CI-targeted overlay without mixing multiple environments in one file.suites/, datasets/, and evaluators/ are local cache folders. Reuse them when they are current, and ask before refreshing or overwriting them.azd ai agent flow uses Basic Agent Setup and does not provision capabilityHosts/agents — do not flag its absence as a bug. For default post-provision state, see the "Expected env-var fingerprint" section in foundry-agent/create/create-hosted.md.Agent skills should run this step only when they need configuration values they don't already have. If a value (for example, agent root, environment, project endpoint, or agent name) is already known from the user's message or a previous skill in the same session, skip resolution for that value.
First check whether the workspace has azure.yaml with services using host: azure.ai.agent.
project folder as the agent root..foundry/ folders that contain agent-metadata.yaml or agent-metadata.<env>.yaml..foundry/ folder during setup; for other workflows, stop and ask the user which agent source folder to initialize.After selecting an agent root, keep all local .foundry cache inspection, source inspection, evaluator suggestions, dataset suggestions, and prompt-optimization context inside that folder only. Do not scan sibling agent folders unless the user explicitly switches roots.
If azure.yaml is present, resolve the azd environment first:
AZURE_ENV_NAME from azd env get-values.azure/config.jsonRun azd env get-values for the selected environment when project/deployment values are not already known. Prefer azd values for deployment context:
| azd Variable | Resolves To |
|---|---|
AZURE_AI_PROJECT_ENDPOINT or AZURE_AIPROJECT_ENDPOINT | Project endpoint |
AGENT_<SERVICE>_NAME | Agent name for the selected azd service |
AGENT_<SERVICE>_VERSION | Agent version for the selected azd service |
AZURE_CONTAINER_REGISTRY_NAME or AZURE_CONTAINER_REGISTRY_ENDPOINT | ACR registry name / image URL prefix |
APPLICATIONINSIGHTS_CONNECTION_STRING | App Insights connection string for trace workflows |
AZURE_SUBSCRIPTION_ID, AZURE_RESOURCE_GROUP, AZURE_AI_ACCOUNT_NAME, AZURE_AI_PROJECT_NAME | Azure resource lookup and Playground links |
When azd supplies these values, use them as the source of truth and do not copy them into .foundry/agent-metadata*.yaml on metadata writes.
Inside the selected agent root, choose the metadata file in this order:
.foundry/agent-metadata.<env>.yaml exists, use that file.foundry/agent-metadata.yamlRead the selected metadata file and resolve any remaining environment choice in this order:
defaultEnvironment from metadataIf the selected metadata file still contains multiple environments and none of the rules above selects one, prompt the user to choose. Keep the selected agent root, metadata file, environment, and whether context came from azd or metadata visible in every workflow summary.
If the selected environment exposes older testSuites[] metadata but not evaluationSuites[], treat testSuites[] as the source for this session and normalize each entry in memory to the evaluationSuites[] shape before continuing. If the metadata is older still and only exposes legacy testCases[], normalize that list the same way. Preserve dataset and evaluator fields, keep any existing tags, and map legacy priority to tags.tier only when tags.tier is missing: P0 -> smoke, P1 -> regression, P2 -> coverage.
If eval.yaml exists in the selected agent root, parse it before generating new suites:
agent.name -> target agent candidate; verify it matches the selected azd/metadata agent before using it.dataset.local_uri -> local seed dataset candidate; legacy dataset_file may be normalized in memory.dataset.name / dataset.version -> registered dataset candidate.validation_dataset -> optional validation dataset candidate.evaluators[] -> candidate Foundry evaluator names; verify with evaluator_catalog_get before treating them as remote evaluators.name -> local eval/suite candidate; verify remotely before persisting as suiteName.options.eval_model, options.optimization_model, options.max_candidates, options.optimization_config.model_search_space, options.pass_threshold, max_samples, trace_days, and generation_instruction -> setup defaults.Treat eval.yaml as local evaluation intent, not proof that a Foundry suite exists. Persist synced suite/dataset/evaluator references to .foundry only after remote lookup or registration succeeds.
Layer sources in this order:
.foundry/agent-metadata*.yaml overlay values and remote suite/cache referencesazure.yaml and eval.yaml local source configurationIf azd and metadata both provide the same value and they differ, stop and ask which source is authoritative. If they match, use the azd value and avoid rewriting the duplicate on future metadata writes.
| Effective Value | Preferred Source | Used By |
|---|---|---|
| Project endpoint | azd env | deploy, invoke, observe, trace, troubleshoot |
| Agent name/version | azd agent variables, then azure.yaml | invoke, observe, trace, troubleshoot |
| ACR | azd env | deploy |
| Evaluation suites and cache paths | .foundry/agent-metadata*.yaml | observe, eval-datasets |
| Local seed dataset/evaluator intent | eval.yaml | observe, eval-datasets |
On any metadata write (deploy, auto-setup, dataset refresh, or trace-to-dataset update), persist only non-derivable overlay/cache state in the selected metadata file:
azd.environmentName, azd.service) when useful for future resolutionevaluationSuites[] with remote suite/dataset/evaluator references and local cache pathslastEval, result files, comparison summaries, or explicit non-azd overridesDo not copy azd-owned deployment values into metadata when azd already provides them. If the selected file is a preferred single-environment file, rewrite only that one environment block. If the selected file is a legacy multi-environment file, rewrite only the selected environment block. Never copy or merge environments across sibling metadata files automatically. If the selected environment still uses older testSuites[] or legacy testCases[], rewrite it to evaluationSuites[] and remove migrated priority fields from the rewritten entries.
Use the ask_user or askQuestions tool only for values not resolved from the user's message, session context, metadata, or azd bootstrap. Common values skills may need:
.foundry/agent-metadata*.yamlagent-metadata.yaml for local/dev, or an explicit sidecar such as agent-metadata.prod.yamldev, prod, or another environment key from metadata💡 Tip: If the user already provides the agent path, environment, project endpoint, or agent name, extract it directly — do not ask again.
All agent skills support two agent types:
| Type | Kind | Description |
|---|---|---|
| Prompt | "prompt" | LLM-based agents backed by a model deployment |
| Hosted | "hosted" | Container-based agents running custom code |
Treat an azure.yaml service with host: azure.ai.agent as Hosted. Use agent_get only when the type cannot be resolved from project context.
ask_user or askQuestions tool whenever collecting information from the usertask or runSubagent tool to delegate long-running or independent sub-tasks (e.g., env var scanning, status polling, Dockerfile generation)Applies to any call against a Foundry project or its parent Foundry account — Foundry MCP tools, azd, az CLI, curl, REST, or SDK.
If an error matches Public access is disabled / PublicNetworkAccessDisabled / 403 Forbidden from a private endpoint / connection timeout / the project endpoint FQDN resolves to a public IP, this typically means the parent Foundry account has publicNetworkAccess=Disabled or Enabled from selected IP addresses, and the current shell is outside its VNet.
Only if the error is ambiguous, confirm against the Foundry account using a management-plane call (works from anywhere with reader access):
az cognitiveservices account show \
--name <account> --resource-group <rg> \
--query "properties.{publicNetworkAccess:publicNetworkAccess, networkAcls:networkAcls, privateEndpointConnections:privateEndpointConnections[].properties.privateLinkServiceConnectionState.status}"publicNetworkAccess: "Disabled" — or "Enabled" together with non-empty networkAcls.ipRules / virtualNetworkRules — confirms isolation. If publicNetworkAccess: "Enabled" and networkAcls is empty, the failure is a caller-side network issue (e.g. Private DNS resolving the FQDN to a public IP from inside a VNet with a private endpoint), not an account-config issue.
If it's indeed a network isolation issue, supported connection options are documented in Choose a secure connection method to Foundry.
ℹ️ Foundry MCP tools cannot reach a VNet-isolated project even from inside the VNet.
© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 185 other files (scripts, references) in plugins/azure-skills/skills/microsoft-foundry of microsoft/GitHub-Copilot-for-Azure.
Open the folder on GitHubat commit d8f4f4e
We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.
Microsoft Foundry next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Microsoft Foundry this skillmicrosoft/GitHub-Copilot-for-Azure | 255 | 1 repos | ~6.7k | Automated safety check: Pass | MIT | |
| Agent Prompt Engineeringagentailor/fullstack-langgraph-nextjs-agent | 132 | — | ~3.6k | Automated safety check: Pass | MIT | |
| AWS AI MLaws/agent-toolkit-for-aws | 2.8k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Ak Inityaalalabs/agent-kernel | 191 | — | ~2.8k | Automated safety check: Pass | Apache-2.0 | |
| Azure Custom VisionMicrosoftDocs/Agent-Skills | 775 | — | ~1.6k | Automated safety check: Pass | CC-BY-4.0 | |
| Microsoft Docsmicrosoft/ai-agents-for-beginners | 77k | 3 repos | ~1.2k | Automated safety check: Pass | MIT |
agentailor/fullstack-langgraph-nextjs-agent
Comprehensive guide for designing, refining, and auditing system prompts for autonomous AI agents based on Anthropic's production practices.
aws/agent-toolkit-for-aws
Selects, deploys, and customizes AI models on Amazon SageMaker.
yaalalabs/agent-kernel
Scaffold a new Agent Kernel project from scratch. An agent skill from yaalalabs/agent-kernel.
MicrosoftDocs/Agent-Skills
Expert knowledge for Azure AI Custom Vision development including best practices, decision making, limits & quotas, security, integrations & coding patterns, and deployment.
microsoft/ai-agents-for-beginners
Query official Microsoft documentation to find concepts, tutorials, and code examples across Azure, .NET, Agent Framework, Aspire, VS Code, GitHub, and more.
vinayaklatthe/microsoft-security-skills
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.
microsoft/GitHub-Copilot-for-Azure
Discovers available Azure OpenAI model capacity across regions and projects.
microsoft/GitHub-Copilot-for-Azure
Unified Azure OpenAI model deployment skill with intelligent intent-based routing.
microsoft/GitHub-Copilot-for-Azure
Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…
microsoft/GitHub-Copilot-for-Azure
Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.
microsoft/GitHub-Copilot-for-Azure
Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage.
microsoft/GitHub-Copilot-for-Azure
Check/manage Azure quotas and usage across providers. An agent skill from microsoft/GitHub-Copilot-for-Azure.
Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. Microsoft Foundry is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.
Microsoft Foundry fits situations like: azd provision/deploy; hosted agent scaffold/develop/run/deploy/troubleshoot; prompt agent create; add tool to agent.
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill microsoft-foundry -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/microsoft-foundry in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/microsoft-foundry in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill microsoft-foundry -a codex`. Or copy the skill folder (plugins/azure-skills/skills/microsoft-foundry in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/microsoft-foundry in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill microsoft-foundry -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/microsoft-foundry, .gemini/skills/microsoft-foundry, .github/skills/microsoft-foundry and .opencode/skills/microsoft-foundry in your project.
Going by SKILL.md and its folder, Microsoft Foundry needs the command-line tools its instructions call (az). Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Microsoft Foundry is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.7k tokens (SKILL.md is roughly 27k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Microsoft Foundry: Agent Prompt Engineering (agentailor/fullstack-langgraph-nextjs-agent, 132 stars), AWS AI ML (aws/agent-toolkit-for-aws, 2.8k stars), Ak Init (yaalalabs/agent-kernel, 191 stars) and Azure Custom Vision (MicrosoftDocs/Agent-Skills, 775 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 7, 2026.
Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.