All skills
microsoft avatar

/azure-resource-lookup

@cda1f27 official

List, find, and show Azure resources across subscriptions or resource groups. Handles prompts like "list the websites in my subscription", "list my web apps", "show my app services", "list virtual machines", "list my VMs", "show storage accounts", "find container apps", and "what resources do I have". USE FOR: list websites, list web apps, list app services, show websites in subscription, resource inventory, find resources by tag, tag analysis, orphaned resource discovery (not for cost analysis), unattached disks, count resources by type, cross-subscription lookup, and Azure Resource Graph queries. DO NOT USE FOR: deploying/changing resources (use azure-deploy), cost optimization (use cost-optimization from the optional azure-cost plugin), or non-Azure clouds.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-resource-lookup

This session only. Nothing lands on disk.

referencesazure-resource-graph.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Resource Graph Query Patterns

Azure Resource Graph (ARG) queries use a KQL subset against indexed Azure resource metadata. Results are near real-time across all subscriptions.

Command Format

az graph query -q "<KQL>" --query "data[].{col1:field1, col2:field2}" -o table
Flag Purpose
-q KQL query string
--query JMESPath to shape output columns
--first N Limit to N results
--subscriptions Scope to specific subscription IDs
-o table Table output (also: json, tsv)

Key Tables

Table Contents
Resources All ARM resources — name, type, location, properties, tags, sku
ResourceContainers Subscriptions, resource groups, management groups
HealthResources Resource health availability status
ServiceHealthResources Azure service health events/incidents
AuthorizationResources Role assignments and definitions
AdvisorResources Azure Advisor recommendations

KQL Essentials

  • =~ case-insensitive equals (use for type field — types are lowercase)
  • properties.fieldName navigates the properties JSON bag
  • mv-expand flattens arrays (subnets, IP configs)
  • isempty() / isnotnull() checks for null/empty fields
  • tostring() converts dynamic fields for display

Resource Inventory Patterns

Count all resources by type:

Resources | summarize count() by type | order by count_ desc

Inventory by type and location:

Resources | summarize count() by type, location | order by type asc

Cross-subscription inventory with subscription names:

Resources
| join kind=leftouter (
    ResourceContainers
    | where type == 'microsoft.resources/subscriptions'
    | project subscriptionId, subscriptionName=name
) on subscriptionId
| summarize count() by subscriptionName, type
| order by subscriptionName asc, count_ desc

All resources in a resource group:

Resources
| where resourceGroup =~ '<rg-name>'
| project name, type, location, sku.name, kind

Orphaned Resource Patterns

Unattached managed disks:

Resources
| where type =~ 'microsoft.compute/disks'
| where isempty(managedBy)
| project name, resourceGroup, location, diskSizeGb=properties.diskSizeGB, sku=sku.name

Unused public IP addresses:

Resources
| where type =~ 'microsoft.network/publicipaddresses'
| where isempty(properties.ipConfiguration)
| project name, resourceGroup, location, sku=sku.name

Orphaned network interfaces:

Resources
| where type =~ 'microsoft.network/networkinterfaces'
| where isempty(properties.virtualMachine)
| project name, resourceGroup, location

Idle load balancers (no backends):

Resources
| where type =~ 'microsoft.network/loadbalancers'
| where array_length(properties.backendAddressPools) == 0
| project name, resourceGroup, location

Tag & Compliance Patterns

Resources missing a required tag:

Resources
| where isnull(tags['Environment']) or isnull(tags['CostCenter'])
| project name, type, resourceGroup, tags

Tag coverage analysis by type:

Resources
| extend hasTag = isnotnull(tags['Environment'])
| summarize total=count(), tagged=countif(hasTag) by type
| extend coverage=round(100.0 * tagged / total, 1)
| order by coverage asc

Resources with public network access:

Resources
| where properties.publicNetworkAccess =~ 'Enabled'
| project name, type, resourceGroup, location

Health & Diagnostics Patterns

Resource health status:

HealthResources
| where type =~ 'microsoft.resourcehealth/availabilitystatuses'
| where properties.availabilityState != 'Available'
| project name, state=properties.availabilityState, reason=properties.reasonType

Active service health incidents:

ServiceHealthResources
| where type =~ 'microsoft.resourcehealth/events'
| where properties.Status == 'Active'
| project name, title=properties.Title, status=properties.Status

Failed provisioning states:

Resources
| where properties.provisioningState != 'Succeeded'
| project name, type, resourceGroup, state=properties.provisioningState

Service-Specific Patterns

App Services and their plans:

Resources
| where type =~ 'microsoft.web/sites'
| project name, kind, location, plan=properties.serverFarmId, state=properties.state, resourceGroup

Container Apps:

Resources
| where type =~ 'microsoft.app/containerapps'
| project name, location, provisioningState=properties.provisioningState, resourceGroup

VNet and subnet discovery:

Resources
| where type =~ 'microsoft.network/virtualnetworks'
| mv-expand subnet=properties.subnets
| project vnetName=name, subnetName=subnet.name, prefix=subnet.properties.addressPrefix

Advisor cost recommendations:

AdvisorResources
| where properties.category == 'Cost'
| project name, impact=properties.impact, solution=properties.shortDescription.solution

Source: SKILL.md on GitHub

No alerts8d4 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    This skill provides utility for querying Azure resource metadata using Azure Resource Graph. It follows standard practices for Azure administration and utilizes read-only commands for resource discovery.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

  • Runlayer7mo

    2 files scanned · No issues

Signed by skilld at cda1f27. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • azure
  • resource-graph
  • kql
  • inventory
  • cross-subscription
  • vm
  • web-apps
  • storage
  • container-apps
  • tagging

README badge

README badge for microsoft/github-copilot-for-azure/azure-resource-lookup

Queries and lists Azure resources across subscriptions and resource groups using Azure Resource Graph, handling resource discovery requests that lack dedicated MCP tools like "list web apps" or "find orphaned disks". Targets cross-subscription inventory, tag audits, and resource state queries via KQL.

Generated from the current SKILL.md.

Does this skill handle App Service and Web Apps listing?
Yes. App Service has no dedicated MCP list command, so this skill uses Azure Resource Graph to query web apps and app services by intent.
Can I query across multiple subscriptions?
Yes. The skill generates Azure Resource Graph queries scoped with the --subscriptions flag to search across multiple subscriptions at once.
What if a dedicated MCP tool exists for my resource type?
The skill routes to dedicated MCP tools first (e.g., compute for VMs, storage for storage accounts). Use this skill only when no dedicated tool covers your resource type.
Can I use this to find orphaned or unattached resources?
Yes. The skill supports queries for orphaned resources like unattached disks, unused NICs, and idle IPs using Azure Resource Graph patterns.
Does this skill support mutations or deployments?
No. This skill is read-only and queries resources only. For deploying or modifying resources, use the azure-deploy skill.

Generated from the current SKILL.md. These answers refresh after source changes.