Agent skill

Azure Bicep Skill

by timothywarner-org in timothywarner-org/claude-code

A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

MITAuto-check passedDevOps & Cloud

Install Azure Bicep Skill

skills CLI
$ npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install timothywarner-org/claude-code azure-bicep-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/timothywarner-org/claude-code.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/azure-bicep-skill .claude/skills/azure-bicep-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-bicep-skill
GitHub stars
224
Token cost
~2.9k tokens
SKILL.md length
1,118 words
Files
3 (incl. scripts, references)
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

  • Works in 8 steps: AVM first, custom second → Strong types and decorators on every param → Secrets come from Key Vault, never… → …
  • Refactoring Azure Bicep code
  • SKILL.md covers When to use, Core principles, Workflow and Validation commands, plus 4 more sections
  • Runs PowerShell scripts from its folder; calls az

What it does

Azure Bicep Skill is an agent skill from timothywarner-org/claude-code. Use when authoring, reviewing, or refactoring Azure Bicep code. Triggers on Bicep module design, Azure Verified Modules (AVM) selection, landing zone IaC, .bicepparam parameter files, what-if deployment validation, bicepconfig.json linting, GitHub Actions Bicep CI with OIDC, Key Vault secret references, and any decision about Bicep file structure, naming, tagging, or scope (resourceGroup, subscription, managementGroup, tenant).

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts and reference files (for example `references/AVM-GUIDE.md`).

It sits in DevOps & Cloud, covering Infrastructure as code, Secrets management and Cloud architecture. It works with Bicep, Microsoft Azure and GitHub Actions. The repository describes itself as: Claude Code and Large-Context Reasoning (O'Reilly Live Learning). The licence is MIT.

When your agent uses it

  • Refactoring Azure Bicep code
  • Bicep module design
  • Azure Verified Modules (AVM) selection
  • Landing zone IaC

Example prompts

  • “/azure-bicep-skill”

Requirements

  • PowerShell

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. AVM first, custom second
  2. Strong types and decorators on every param
  3. Secrets come from Key Vault, never parameters
  4. CAF naming and mandatory tags
  5. Explicit targetScope, even when it's the default
  6. Symbolic references over dependsOn
  7. Outputs are the contract, never the secret store
  8. what-if before create, always

What it can do on your machine

Read from SKILL.md and the folder at commit cb80eae. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (PowerShell), which the agent can run.

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Bicep Skill loads about 2.9k tokens when it runs, and up to ~4.6k if it reads all its reference files. Until then it costs about 112 tokens; SKILL.md has 1,118 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~112
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from timothywarner-org/claude-code at commit cb80eae, republished under its MIT licence (© timothywarner-org). 1,118 words, ~2,924 tokens.

Download SKILL.mdSave it as .claude/skills/azure-bicep-skill/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
azure-bicep-skill
description
Use when authoring, reviewing, or refactoring Azure Bicep code. Triggers on Bicep module design, Azure Verified Modules (AVM) selection, landing zone IaC, .bicepparam parameter files, what-if deployment validation, bicepconfig.json linting, GitHub Actions Bicep CI with OIDC, Key Vault secret references, and any decision about Bicep file structure, naming, tagging, or scope (resourceGroup, subscription, managementGroup, tenant).

Azure Bicep Skill

Microsoft's proven-practice guidance for production Bicep deployments, distilled. Use this skill whenever Bicep code is being authored, reviewed, or refactored, or when picking between custom modules and Azure Verified Modules.

When to use

Trigger this skill when you see any of the following:

  • A .bicep or .bicepparam file being created, edited, or reviewed
  • A request involving "landing zone," "AVM," "Azure Verified Module," "what-if," or "bicepconfig"
  • A question about Bicep scopes (targetScope), parameter typing, or output design
  • A GitHub Actions workflow that deploys Bicep
  • A choice between Bicep and Terraform (Bicep is the default for Tim's stack; only deviate with explicit justification)
  • A custom module being proposed when an AVM module exists for the same resource

Do not trigger for: pure ARM JSON work (recommend converting to Bicep first), Terraform-only workflows, Azure portal click-ops walkthroughs.

Core principles

1. AVM first, custom second

Azure Verified Modules are Microsoft-published, WAF-aligned, versioned Bicep modules in the public Bicep Registry. They have built-in support for diagnostics, managed identities, private endpoints, RBAC assignments, and tagging. Prefer them over hand-rolled modules.

Why: AVM modules are maintained by the product groups, tested across regions, and updated for breaking API changes. Reinventing them is technical debt you will pay forever.

bicep
// Preferred: AVM resource module, version-pinned
module storage 'br/public:avm/res/storage/storage-account:0.14.3' = {
  name: 'storage-deployment'
  params: {
    name: storageAccountName
    location: location
    skuName: 'Standard_GRS'
    tags: tags
  }
}

See references/AVM-GUIDE.md for the module catalog, the resource (res) vs pattern (ptn) distinction, and version-pinning strategy.

2. Strong types and decorators on every param

Bicep parameters should be self-documenting and self-validating.

bicep
@description('Cost center for chargeback. Must match Finance master list.')
@minLength(4)
@maxLength(8)
param costCenter string

@description('Environment tier. Drives SKU selection and retention policies.')
@allowed([
  'dev'
  'test'
  'prod'
])
param environment string

@description('Admin password. Sourced from Key Vault via getSecret().')
@secure()
param sqlAdminPassword string

Why: Decorators turn deployment-time mistakes into authoring-time errors. @allowed is your cheapest policy enforcement.

3. Secrets come from Key Vault, never parameters

Never accept a secret as a plain parameter. Reference an existing Key Vault and pull the secret via getSecret():

bicep
resource kv 'Microsoft.KeyVault/vaults@2023-07-01' existing = {
  name: keyVaultName
  scope: resourceGroup(keyVaultRgName)
}

module sql 'br/public:avm/res/sql/server:0.10.0' = {
  name: 'sql-deployment'
  params: {
    name: sqlServerName
    location: location
    administratorLoginPassword: kv.getSecret('sql-admin-password')
  }
}

Why: Secret values passed as parameters end up in deployment history, CLI scrollback, and CI logs. getSecret() keeps them inside the ARM control plane only.

See references/SECURITY.md for managed identity patterns and OIDC federation.

4. CAF naming and mandatory tags

Follow Cloud Adoption Framework naming: <resource-type>-<workload>-<env>-<region>-<instance>. Use uniqueString() only for globally-scoped resources where collisions are real (storage accounts, Key Vaults, App Service plans hosting custom domains).

bicep
var namePrefix = 'kv-${workload}-${environment}-${location}'
var keyVaultName = '${namePrefix}-${take(uniqueString(resourceGroup().id), 4)}'

var mandatoryTags = {
  Environment: environment
  CostCenter: costCenter
  Owner: ownerEmail
  Workload: workload
  ManagedBy: 'Bicep'
}

See references/NAMING-AND-TAGGING.md for the full CAF table and tag governance.

5. Explicit targetScope, even when it's the default

Always declare targetScope at the top of the file. The default is resourceGroup, but stating it removes ambiguity for reviewers and prevents accidental scope mismatch when modules are reused.

bicep
targetScope = 'subscription'

@description('Landing zone resource group name.')
param resourceGroupName string

resource rg 'Microsoft.Resources/resourceGroups@2023-07-01' = {
  name: resourceGroupName
  location: location
  tags: mandatoryTags
}
6. Symbolic references over dependsOn

Bicep infers dependencies from symbolic references. Manual dependsOn arrays are usually a sign of a missing reference or a circular design.

bicep
// Preferred: dependency is implicit via storage.outputs.resourceId
module diagnostics 'modules/diagnostics.bicep' = {
  name: 'diag-deployment'
  params: {
    targetResourceId: storage.outputs.resourceId
    logAnalyticsWorkspaceId: laws.outputs.resourceId
  }
}

Why: Explicit dependsOn masks the actual data flow and breaks when modules are reordered or refactored.

7. Outputs are the contract, never the secret store

Outputs are read by humans and by downstream modules. They appear in deployment history. Output resource IDs, names, and endpoints. Never output a secret value. If a caller needs a secret, give them the Key Vault URI and let them call getSecret().

8. what-if before create, always
pwsh
az deployment sub what-if `
  --location eastus2 `
  --template-file main.bicep `
  --parameters main.bicepparam

Read every Modify, Delete, and DeployIgnored line. what-if is the closest thing Bicep has to a dry-run, and it catches drift, accidental deletes, and parameter mistakes before they become incidents.

Workflow

When generating or reviewing Bicep, walk this loop:

  1. Scope check. Confirm targetScope matches the intended deployment scope. Subscription scope for landing zones, resourceGroup for workload deployments.
  2. AVM check. For every resource being created, search the AVM registry. If a module exists, use it. If it doesn't, document why a custom module is needed.
  3. Parameter audit. Every param has @description. Strings have @allowed or length constraints where the value space is bounded. Secrets are @secure() and sourced from Key Vault.
  4. Identity audit. No service principal secrets. Managed identities for service-to-service auth. Key Vault role assignments via AVM module's roleAssignments parameter.
  5. Naming and tags. CAF naming convention. Mandatory tag set applied at the resource-group or subscription level and inherited.
  6. Output audit. Outputs are minimal, named, typed, and contain no secret values.
  7. Validation. Run bicep build (syntax), bicep lint (style, with bicepconfig.json), and az deployment <scope> what-if (deployment diff).
  8. CI integration. Ensure the change is reachable from a GitHub Actions workflow that uses OIDC, runs what-if, requires manual approval for prod, and posts the diff to the PR.
Show full SKILL.md (417 more words)Show less

Validation commands

Preferred: run all four gates at once via the bundled script.

pwsh
# All four gates: build + lint + AVM version-pin scan + what-if
./scripts/validate-bicep.ps1 `
  -TemplateFile main.bicep `
  -ParametersFile main.bicepparam `
  -Scope subscription `
  -Location eastus2

# Local authoring loop (skip the tenant call)
./scripts/validate-bicep.ps1 `
  -TemplateFile main.bicep `
  -ParametersFile main.bicepparam `
  -SkipWhatIf

The scripts/validate-bicep.ps1 script wraps the four mandatory pre-deploy gates (build, lint, AVM version-pin scan, what-if) and exits non-zero on any failure. Use it as the local pre-commit check and as the CI gate. It is the executable counterpart of this skill's guidance.

Individual gates (when you need to run one in isolation):

pwsh
# Syntax + transpile check
bicep build main.bicep

# Lint with project rules
bicep lint main.bicep

# Subscription-scope what-if
az deployment sub what-if `
  --location eastus2 `
  --template-file main.bicep `
  --parameters main.bicepparam

# Subscription-scope deploy (only after what-if review)
az deployment sub create `
  --location eastus2 `
  --template-file main.bicep `
  --parameters main.bicepparam

# PSRule for Azure (policy compliance, complementary to the gates above)
Invoke-PSRule -InputPath . -Module 'PSRule.Rules.Azure'

Anti-patterns to flag

Anti-patternWhy it's wrongWhat to do instead
Hardcoded subscription ID or tenant IDBreaks portability, leaks tenant info into sourceUse subscription().subscriptionId and tenant().tenantId
Inline secret in parameter fileSecret hits git history and CI logsKey Vault reference via getSecret()
dependsOn arrayHides real data flow, breaks on refactorSymbolic reference (module.outputs.x)
Custom module for a resource AVM coversReinventing maintained codeUse the AVM module, pin the version
@secure() missing on secret paramsSecret value rendered in deployment historyAdd @secure(), source from Key Vault
Outputting a secretSecret appears in deployment outputsOutput the Key Vault URI instead
JSON ARM where Bicep would workLoses type safety, decorators, lintingConvert with bicep decompile then refactor
No targetScope declarationAmbiguous deployment scopeDeclare it explicitly at the top of the file
uniqueString() on every nameNames become unreadable in the portalUse only for globally-scoped resources
Service principal with client secretLong-lived credential, rotation burdenManaged identity, or OIDC federation for CI

Tim's stack defaults

When generating Bicep for this environment, assume:

  • IaC: Bicep first. Terraform only when Bicep cannot do the job (multi-cloud, third-party providers).
  • CI/CD: GitHub Actions in timothywarner-org, OIDC federated credentials, no stored secrets.
  • Identity: Entra ID. Managed identities (system-assigned preferred, user-assigned when shared across resources).
  • Secrets: Azure Key Vault, referenced via getSecret() and managed identity.
  • Compute targets: Azure Container Apps, AKS, Functions, App Service.
  • Data targets: Cosmos DB, Azure SQL, Storage Account with hierarchical namespace, Azure AI Search.
  • Region default: eastus2 unless specified.
  • Tagging: Environment, CostCenter, Owner, Workload, ManagedBy are mandatory.

Deviation from these defaults requires an explicit justification in the response.

Bundled scripts

  • scripts/validate-bicep.ps1 - Runs all four pre-deploy gates (build, lint, AVM version-pin scan, what-if) in one shot. PowerShell 7+. Use locally before commit and in CI as a gate. See the Validation commands section above for invocation examples.

Reference files

  • references/AVM-GUIDE.md - Azure Verified Modules catalog, registry naming, version-pinning strategy

Additional reference files (NAMING-AND-TAGGING.md, SECURITY.md, CI-CD.md) and starter templates under assets/templates/ may be added as the skill matures. Until then, follow the inline guidance in this SKILL.md and the AVM guide.

© timothywarner-org, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts, references) in .claude/skills/azure-bicep-skill of timothywarner-org/claude-code.

  • SKILL.md
  • references/AVM-GUIDE.md
  • scripts/validate-bicep.ps1

Open the folder on GitHubat commit cb80eae

Compare with similar skills

Azure Bicep Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Bicep Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Bicep Skill this skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Managing Workflow Secretsbitwarden/ai-plugins155—~4kAutomated safety check: PassCustom licence
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT
APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills202—~3.6kAutomated safety check: PassMIT
Azure Preparemicrosoft/GitHub-Copilot-for-Azure2551 repos~3.2kAutomated safety check: PassMIT
Azure To AWSaws/agent-toolkit-for-aws2.8k—~5.5kAutomated safety check: PassApache-2.0

Similar skills

  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    155 GitHub stars~4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • Azure Prepare

    microsoft/GitHub-Copilot-for-Azure

    Official

    Prepare azd-based Azure projects for deployment: generates azure.yaml, infrastructure (Bicep/Terraform), and Dockerfiles for the Azure Developer CLI (azd) workflow.

    255 GitHub starsUsed in 1 repo~3.2k tokens
    DevOps & CloudAuto-check passed
  • Azure To AWS

    aws/agent-toolkit-for-aws

    Official

    Migrate workloads from Microsoft Azure to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~5.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • AWS Cloudformation Task Ecs Deploy Gh

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to deploy ECS tasks and services with GitHub Actions CI/CD.

    357 GitHub stars~2.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes

More from timothywarner-org/claude-code

  • MCP Scaffold

    timothywarner-org/claude-code

    Scaffold production-ready Python MCP servers using FastMCP. An agent skill from timothywarner-org/claude-code.

    224 GitHub stars~940 tokensUpdated 2 mo ago
    Auto-check passed
  • Claude Md Audit

    timothywarner-org/claude-code

    Audit the CLAUDE.md hierarchy in a repo for drift between what each CLAUDE.md claims and what's actually on disk.

    224 GitHub stars~649 tokensUpdated 2 mo ago
    Auto-check passed
  • Azure AI Deploy

    timothywarner-org/claude-code

    Ship a Python generative-AI app to Azure the keyless way, using DefaultAzureCredential and azd.

    224 GitHub stars~731 tokensUpdated 2 mo ago
    Auto-check: notes
  • Genai Prompt Eval

    timothywarner-org/claude-code

    Score a Python generative-AI app's outputs on groundedness, relevance, coherence, and safety before it ships.

    224 GitHub stars~696 tokensUpdated 2 mo ago
    Auto-check: notes
  • Kubernetes Patterns

    timothywarner-org/claude-code

    Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments.

    224 GitHub stars~4.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Review Changes

    timothywarner-org/claude-code

    Review uncommitted local changes in the current git working tree for bugs, smells, missing tests, and CLAUDE.md voice violations.

    224 GitHub stars~506 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Azure Bicep Skill

What does Azure Bicep Skill do?

A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code. Azure Bicep Skill is an agent skill from timothywarner-org/claude-code. Use when authoring, reviewing, or refactoring Azure Bicep code.

When should I use Azure Bicep Skill?

Azure Bicep Skill fits situations like: refactoring Azure Bicep code; bicep module design; azure Verified Modules (AVM) selection; landing zone IaC.

How do I install Azure Bicep Skill in Claude Code?

Run `npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a claude-code`. Or copy the skill folder (.claude/skills/azure-bicep-skill in timothywarner-org/claude-code) into .claude/skills/azure-bicep-skill in your project. Claude Code loads it when a task matches its description.

How do I install Azure Bicep Skill in Codex?

Run `npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a codex`. Or copy the skill folder (.claude/skills/azure-bicep-skill in timothywarner-org/claude-code) into .agents/skills/azure-bicep-skill in your project. Codex loads it when a task matches its description.

Can I use Azure Bicep Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add timothywarner-org/claude-code --skill azure-bicep-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-bicep-skill, .gemini/skills/azure-bicep-skill, .github/skills/azure-bicep-skill and .opencode/skills/azure-bicep-skill in your project.

What does Azure Bicep Skill need to run?

Going by SKILL.md and its folder, Azure Bicep Skill needs PowerShell for the scripts in its folder and the command-line tools its instructions call (az). Our summary lists: PowerShell.

Does Azure Bicep Skill access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Azure Bicep Skill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Azure Bicep Skill use?

Azure Bicep Skill is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Bicep Skill use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Azure Bicep Skill?

Skills that share tags, products or a category with Azure Bicep Skill: Managing Workflow Secrets (bitwarden/ai-plugins, 155 stars), Azure Architecture Autopilot (github/awesome-copilot, 40k stars), APIOps Deployment for Azure APIM (thomast1906/github-copilot-agent-skills, 202 stars) and Azure Prepare (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Bicep Skill?

timothywarner-org (a GitHub organization) maintains it in timothywarner-org/claude-code, which has 224 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on July 20, 2026.

Source: timothywarner-org/claude-code on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.