All skills
microsoft avatar

/microsoft-foundry

@04110d9
by microsoftmicrosoft/skills3.1k stars
351

Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end. USE FOR: foundry, azd ai agent, azd provision/deploy, hosted agent scaffold/develop/run/deploy/troubleshoot, prompt agent create, create agent, update agent, add tool to agent, invoke agent, agent.yaml, agent insights, pull agent insights, evaluate agent, batch eval, continuous eval, continuous monitoring, agent CI/CD, optimize prompt, improve prompt, prompt optimizer, optimize agent instructions, Agent Optimizer scaffold, dataset curation from traces, deploy model, model fine-tuning (SFT/DPO/RFT), Foundry project, RBAC, role assignment, permissions, quota, capacity, region, deployment failure, AI Services, create Foundry resource, knowledge index, customize deployment, onboard, availability, training-data, grader, distillation, large file upload. DO NOT USE FOR: Azure Functions, App Service, general Azure deploy (use azure-deploy), general Azure prep (use azure-prepare).

Use this Skill: https://skilld.dev/gh/microsoft/skills/microsoft-foundry

This session only. Nothing lands on disk.

foundry-agenttoolboxreferencestool-mcp-noauth.md

≈987 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Tool — Remote MCP server, no auth (type: mcp)

Attach a public remote MCP server (no credentials) to a toolbox. A no-auth server still needs a connection (--kind remote-tool --auth-type none) — the toolbox references it by name and the created toolbox tool carries a populated project_connection_id.

🚦 Before creating a toolbox/connection either way, read create-hosted.md → Toolbox creation boundary.


A. Imperative CLI

Steps 1–3 of toolbox.md § The flow. Write the toolbox spec to a file — azd ai toolbox create --from-file takes a path (stdin - is not supported).

# 0. Install the CLI extension (once)
azd extension install azure.ai.toolboxes

# 1. Create the no-auth connection
azd ai connection create learn-mcp-conn \
  --kind remote-tool --target https://learn.microsoft.com/api/mcp \
  --auth-type none --project-endpoint "$FOUNDRY_PROJECT_ENDPOINT"

# Write the toolbox spec to a file
cat > learn-mcp.yaml <<'EOF'
description: learn-mcp toolbox
connections:
  - name: learn-mcp-conn
EOF

Create a new toolbox (first version auto-promoted):

azd ai toolbox create learn-tools --from-file learn-mcp.yaml --project-endpoint "$FOUNDRY_PROJECT_ENDPOINT"

azd ai toolbox create / delete require an azd environment (run inside an azd init'd directory), unlike connection create / toolbox show which work with just --project-endpoint.

Add to an existing toolbox (new version — then promote):

azd ai toolbox connection add learn-tools learn-mcp-conn --project-endpoint "$FOUNDRY_PROJECT_ENDPOINT"
azd ai toolbox publish learn-tools <new-version> --project-endpoint "$FOUNDRY_PROJECT_ENDPOINT"

connection add creates a new immutable version but leaves the default unchanged until you publish it.

--from-file entry:

connections:
  - name: learn-mcp-conn       # RemoteTool — just the name; project_connection_id is populated

B. Declarative azure.yaml

Declare the toolbox as a host: azure.ai.toolbox service in azure.yaml; azd deploy upserts it (and auto-promotes the new version). A no-auth MCP server is declared under tools: with an inline server_url — no connection needed on this path.

name: my-agent-project
services:
  agent-tools:
    host: azure.ai.toolbox
    description: learn-mcp toolbox
    tools:
      - type: mcp
        server_label: learn_mcp
        server_url: https://learn.microsoft.com/api/mcp
        require_approval: never

  # A hosted agent in the same project consumes the toolbox by name
  my-agent:
    host: azure.ai.agent
    uses:
      - agent-tools          # depend on the toolbox service
    environmentVariables:
      - name: TOOLBOX_NAME
        value: agent-tools    # agent resolves the MCP endpoint at runtime
azd deploy agent-tools

Requirements & gotchas:

  • Set FOUNDRY_PROJECT_ENDPOINT and AZURE_SUBSCRIPTION_ID in the azd env (after it's created) before azd deploy, or it errors infrastructure has not been provisioned. No azd provision / infra: block is needed.

The agent references the toolbox by name (TOOLBOX_NAME), so the MCP endpoint resolves at runtime — no endpoint string is hard-coded. See use-toolbox-in-hosted-agent.md.


Verify & deploy

After creating the toolbox either way, verify its MCP endpoint end-to-end (bearer token + raw tools/list / tools/call) — see test-endpoint.md.


References

Source: SKILL.md on GitHub

2 warnings3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill provides a comprehensive environment for managing the end-to-end lifecycle of AI agents, models, and infrastructure on Microsoft Foundry. It includes sub-skills for deployment, evaluation, fine-tuning, and troubleshooting. The skill utilizes dynamic code execution and shell command wrappers, which are used within the context of local development and cloud orchestration. All external resources and dependencies originate from trusted organizations and well-known services.

  • Socket3d

    2 alerts: gptSecurity, gptAnomaly

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    36/36 files flagged

Signed by skilld at 04110d9. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.2.26"
}

README badge

README badge for microsoft/skills/microsoft-foundry