All skills
microsoft avatar

/azure-app-onboard-prereq

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work. Evaluates build health, app completeness, dependencies and local services, stack compatibility, and deployment feasibility. Answers questions about what your app needs before it can be deployed — frameworks, dependencies, and configuration. Checks whether dependencies are compatible and identifies deployment blockers and unsupported frameworks. WHEN: "evaluate my repo", "is my app ready to deploy", "what does my app need to deploy", "what do I need before deploying", "does my app need", "can I ship this to Azure", "scan my repo for issues", "is this app deployable", "check if my app is ready for Azure", "do I need a Dockerfile", "what's blocking my deployment", "are there any blockers", "are my dependencies compatible", "does Azure support my framework", "what needs to change before deploying", "check my app configuration".

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-app-onboard-prereq

This session only. Nothing lands on disk.

referencessubscription-resolution.md

≈472 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Subscription Resolution — Defensive Fallback

The azure-app-onboard orchestrator resolves the subscription at Step 1 (login hard gate) and writes subscriptionId, subscriptionName, tenantId to context.json.azure before any sub-skill runs. In normal operation, context.json.azure.subscriptionId is always set by the time prepare runs.

At prepare phase entry, verify context.json.azure.subscriptionId is set. If it is (expected path), use it — done.

If context.json.azure is somehow empty, resolve now rather than halting the flow:

  1. Check env vars — if AZURE_SUBSCRIPTION_ID is set, use it directly (with AZURE_TENANT_ID if set). Write subscriptionId, subscriptionName, tenantId to context.json.azure, done.
  2. Run az account show — az account show --query "{id:id, name:name, tenantId:tenantId}" -o json. If it succeeds, auto-select — write subscriptionId, subscriptionName, tenantId to context.json.azure. Do NOT run az account list or present a picker.
  3. Fallback: mcp_azure_mcp_subscription_list + picker — only if az account show fails. Call mcp_azure_mcp_subscription_list to retrieve all subscriptions (returns subscriptionId, displayName, isDefault).
    • 1 subscription → auto-select, no question. Write subscriptionId, subscriptionName, tenantId to context.json.azure.
    • 2+ subscriptions → present a picker via ask_user: list each subscription as a choice "{displayName} ({subscriptionId})" with the default marked. The user selects one. Write subscriptionId, subscriptionName, tenantId to context.json.azure.
  4. MCP tool fails → run az login (interactive browser login). If that fails (no browser, remote session), fall back to az login --use-device-code. After login succeeds, retry from step 2. Do NOT proceed without a resolved subscription.

Source: SKILL.md on GitHub

1 warning1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill is an Azure deployment readiness evaluator authored by Microsoft. It performs static analysis of repositories to identify deployment blockers and can offer to fix them or generate starter code. While the skill has capabilities to execute build commands and modify files, these actions are strictly protected by user consent gates and are limited to the skill's intended purpose of onboarding applications to Azure.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: MEDIUM · 1 issue

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.2"
}

README badge

README badge for microsoft/skills/azure-app-onboard-prereq