azure-prepare
Prepare Azure Projects for azd Deployment
Preparing an application for Azure requires coordinated configuration, infrastructure, security, and service choices. This skill creates an approved azd plan and generates deployment artifacts.
Do not auto-install this skill.
The canonical policy requires operator review before any installation action.
Install with my Agent
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "azure-prepare" from https://skillstore.io/skills/microsoft-azure-prepare.md and its manifest at https://skillstore.io/api/skills/microsoft-azure-prepare/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.Your Agent should still show its plan and request any confirmation required by the security policy.
Agent-readable resources
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Test it
Using "azure-prepare". Prepare this Python function for Azure with azd and Bicep.
Expected outcome:
- A deployment plan identifies the Function App, storage, managed identity, RBAC roles, region, and quota checks.
- The prepared artifacts include azure.yaml, Bicep modules, application settings, and a validation handoff.
Using "azure-prepare". Modernize this API and worker for Azure Container Apps with Terraform.
Expected outcome:
- The architecture separates API and worker services, adds managed identity, and defines private service dependencies.
- Terraform resources, Dockerfiles, azd configuration, and an approval checklist are prepared for validation.
Using "azure-prepare". Add Azure SQL to this azd project without passwords.
Expected outcome:
- The plan selects Entra-only authentication and a managed identity for the application.
- The infrastructure includes scoped SQL RBAC, secure settings, and no administrator password.
Security Audit
CriticalMost static matches are documentation false positives, including Markdown links, SDK environment lookups, and Azure resource identifiers. Confirmed risks include a pipe-to-shell installer, broad network rules, embedded storage keys, and an unsafe session-secret fallback. Semantic review found prompt injection, unverified remote templates, and approval bypasses; 279 capped static matches still require manual review. Static review was capped at 400/679 representative findings; omitted static matches are unconfirmed, so automatic publishing stays disabled until manual review.
Confirmed security concerns (16)
Show all 16 confirmed findings
Capability review items (8)
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Risk Factors
โ๏ธ External commands (50)
๐ Filesystem access (50)
๐ Env variables (50)
๐ Network access (50)
โก Contains scripts (8)
Detected Patterns
Share & cite this report
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
Copy report link
https://skillstore.io/skills/microsoft-azure-prepare/audits/5?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_reportMarkdown badge
[](https://skillstore.io/skills/microsoft-azure-prepare?utm_source=security_passport_badge)HTML badge
<a href="https://skillstore.io/skills/microsoft-azure-prepare?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/microsoft-azure-prepare/security.svg" alt="Skillstore security assessment" loading="lazy"></a>Embed card
<iframe src="https://skillstore.io/embed/skills/microsoft-azure-prepare.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>Academic citations (APA ยท BibTeX ยท CFF)
APA citation
microsoft. (2026). azure-prepare security audit report (audit version 5) [Author version 0.0.0-placeholder]. Skillstore. https://skillstore.io/skills/microsoft-azure-prepare/audits/5BibTeX citation
@techreport{microsoft-microsoft-azure-prepare-2026,
author = {microsoft},
title = {azure-prepare security audit report (audit version 5)},
institution = {Skillstore},
year = {2026},
number = {5},
url = {https://skillstore.io/skills/microsoft-azure-prepare/audits/5},
note = {Author version 0.0.0-placeholder}
}CITATION.cff
cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "azure-prepare security audit report (audit version 5)"
version: "0.0.0-placeholder"
type: report
authors:
- name: "microsoft"
date-released: "2026-07-23"
url: "https://skillstore.io/skills/microsoft-azure-prepare/audits/5"
identifiers:
- type: other
value: "skillstore:microsoft-azure-prepare:audit:5"
description: "Skillstore immutable audit report identifier"
Skillstore Score
Why this score Evidence Confidence: MediumWhat You Can Build
Prepare a New Azure Application
Create an approved azd plan, service mapping, infrastructure, and application configuration for a new project.
Modernize an Existing Service
Preserve existing code while adding managed Azure services, containers, identity, networking, and deployment configuration.
Design Multi-Service Infrastructure
Plan Bicep or Terraform resources, RBAC, quotas, and service dependencies for a coordinated Azure architecture.
Try These Prompts
Prepare this application for Azure with azd. Inspect the workspace and create the required deployment plan. Do not execute the plan until I approve it.
Create azd configuration and Bicep infrastructure for this Node.js API. Use managed identity and document every resource choice before generating files.
Modernize this multi-service application for Azure Container Apps with azd and Terraform. Preserve existing code and propose a phased plan for approval.
Design Azure Functions with Service Bus and Durable Task Scheduler. Include RBAC, networking, quota checks, and validation handoff. Do not deploy.
Best Practices
- Review and approve the deployment plan before any file generation or cloud action.
- Use managed identity and narrowly scoped RBAC instead of keys, passwords, or broad roles.
- Validate generated infrastructure, network boundaries, quotas, and cost assumptions before deployment.
Avoid
- Do not run remote installers or templates without pinning and verification.
- Do not deploy from the preparation workflow or bypass the validation handoff.
- Do not expose public endpoints, shared keys, or plaintext secrets by default.
Frequently Asked Questions
Does this skill deploy resources to Azure?
Which infrastructure formats can it generate?
Can it modify an existing application?
How does it handle Azure credentials?
Does it require user confirmation?
Is the generated infrastructure production ready?
Developer Details
Author
microsoftLicense
MIT
Author version
v0.0.0-placeholder
Skillstore revision
r2
Repository
https://github.com/microsoft/github-copilot-for-azure/tree/main/plugin/skills/azure-prepare/Ref
ebdfe608f5de2b66ff37ab4af12af8ac4f5e8006
Maintenance freshness
7/25/2026
Usage
10 downloads ยท 566 views
File structure
๐ references/
๐ analyze.md
๐ apim.md
๐ architecture.md
๐ aspire.md
๐ azure-context.md
๐ functional-verification.md
๐ generate.md
๐ global-rules.md
๐ plan-template.md
๐ recipe-selection.md
๐ recipes/
๐ azcli/
๐ commands.md
๐ README.md
๐ scripts.md
๐ azd/
๐ aspire.md
๐ azure-yaml.md
๐ docker.md
๐ iac-rules.md
๐ README.md
๐ terraform.md
๐ bicep/
๐ patterns.md
๐ README.md
๐ terraform/
๐ patterns.md
๐ README.md
๐ requirements.md
๐ research.md
๐ resources-limits-quotas.md
๐ runtimes/
๐ nodejs.md
๐ scan.md
๐ sdk/
๐ azd-deployment.md
๐ azure-appconfiguration-java.md
๐ azure-appconfiguration-py.md
๐ azure-appconfiguration-ts.md
๐ azure-identity-py.md
๐ azure-identity-ts.md
๐ security.md
๐ services/
๐ aks/
๐ addons.md
๐ bicep.md
๐ manifests.md
๐ README.md
๐ app-insights/
๐ README.md
๐ app-service/
๐ bicep.md
๐ custom-domains.md
๐ deployment-slots.md
๐ networking.md
๐ README.md
๐ scaling.md
๐ sku-selection.md
๐ templates/
๐ recipes/
๐ auth/
๐ README.md
๐ source/
๐ dotnet.md
๐ nodejs.md
๐ python.md
๐ composition.md
๐ cosmos/
๐ README.md
๐ source/
๐ dotnet.md
๐ nodejs.md
๐ python.md
๐ README.md
๐ redis/
๐ README.md
๐ source/
๐ dotnet.md
๐ nodejs.md
๐ python.md
๐ sql/
๐ README.md
๐ source/
๐ dotnet.md
๐ nodejs.md
๐ python.md
๐ selection.md
๐ web-api.md
๐ web-app.md
๐ container-apps/
๐ bicep.md
๐ day2-operations.md
๐ environment.md
๐ health-probes.md
๐ networking.md
๐ README.md
๐ revisions.md
๐ scaling.md
๐ terraform.md
๐ cosmos-db/
๐ bicep.md
๐ partitioning.md
๐ README.md
๐ sdk.md
๐ bicep.md
๐ dotnet.md
๐ java.md
๐ javascript.md
๐ python.md
๐ README.md
๐ event-grid/
๐ bicep.md
๐ README.md
๐ subscriptions.md
๐ foundry/
๐ README.md
๐ functions/
๐ bicep.md
๐ durable.md
๐ README.md
๐ templates/
๐ base/
๐ eval/
๐ python.md
๐ summary.md
๐ typescript.md
๐ README.md
๐ recipes/
๐ blob-eventgrid/
๐ eval/
๐ python.md
๐ summary.md
๐ README.md
๐ common/
๐ error-handling.md
๐ health-check.md
๐ composition.md
๐ cosmosdb/
๐ eval/
๐ python.md
๐ summary.md
๐ typescript.md
๐ README.md
๐ durable/
๐ eval/
๐ python.md
๐ summary.md
๐ README.md
๐ eventhubs/
๐ eval/
๐ python.md
๐ summary.md
๐ README.md
๐ mcp/
๐ eval/
๐ python.md
๐ summary.md
๐ README.md
๐ README.md
๐ servicebus/
๐ eval/
๐ python.md
๐ summary.md
๐ typescript.md
๐ README.md
๐ sql/
๐ eval/
๐ python.md
๐ summary.md
๐ README.md
๐ timer/
๐ eval/
๐ python.md
๐ summary.md
๐ README.md
๐ selection.md
๐ terraform.md
๐ key-vault/
๐ bicep.md
๐ README.md
๐ sdk.md
๐ logic-apps/
๐ bicep.md
๐ README.md
๐ triggers.md
๐ service-bus/
๐ bicep.md
๐ patterns.md
๐ README.md
๐ sql-database/
๐ auth.md
๐ bicep.md
๐ README.md
๐ scripts/
๐ grant-sql-access.ps1
๐ grant-sql-access.sh
๐ sdk.md
๐ static-web-apps/
๐ bicep.md
๐ deployment.md
๐ README.md
๐ routing.md
๐ terraform.md
๐ storage/
๐ access.md
๐ bicep.md
๐ README.md
๐ SKILL.md
๐ version.json