All skills
microsoft avatar

/scaffold

@617f8b5
by microsoftmicrosoft/skills3.1k stars
351

Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents

  • 27 files
  • 156.7 KB
  • Updated 2 months ago
  • GitHub

Use this Skill: https://skilld.dev/gh/microsoft/skills/scaffold

This session only. Nothing lands on disk.

referencesself-review-procedure.md

≈586 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Self-Review Procedure — Step 9

Adversarial self-review using a sub-agent to perform L1–L4 review of generated IaC.

Sub-Agent Setup

Use a sub-agent to perform the review. Provide:

  • All generated IaC file contents (every .bicep or .tf file from Step 5)
  • The prepare-plan.json services/naming/deploymentVariables sections
  • The scaffold-manifest.json.files[] list
  • The full content of self-review-checklist.md AND waf-checklist.md verbatim

Sub-Agent Prompt

"Follow the self-review-checklist.md procedures for EACH of L1–L4. Rate each finding as VERIFIED | PLAUSIBLE | FLAGGED. Check: L1 Security (RBAC scope, network rules, managed identity, Key Vault — check contradictions between IaC and plan), L2 Pattern (anti-patterns, missing supporting resources — verify every file in scaffold-manifest.json.files[] exists on disk and is non-empty, FLAGGED if any missing or empty), L3 Hallucination (resource names match prepare-plan.json.naming exactly, API versions are real, SKU names match plan, no invented resource types), L4 WAF (use waf-checklist.md — Reliability, Security, Cost, Ops, Performance per-service checks). Do not fabricate results — check each claim against the actual IaC content provided. Return: { findings: [{ layer: 'L1'|'L2'|'L3'|'L4', claim: '...', rating: 'VERIFIED'|'PLAUSIBLE'|'FLAGGED', detail: '...' }], summary: 'N/N VERIFIED, N PLAUSIBLE, N FLAGGED' }. ≤1000 tokens."

Consume Results

  • If any finding is FLAGGED → fix the IaC, then re-run validation (az bicep build, az deployment sub what-if)
  • If all VERIFIED/PLAUSIBLE → proceed to Step 10
  • Write findings to scaffold-manifest.json.selfReview

⛔ Self-review is COMPLETE after L1–L4. L3 may use mcp_bicep_get_bicep_file_diagnostics, az bicep build, or az deployment sub what-if — all are appropriate for catching errors early. Step 12 remains mandatory regardless of what self-review found — IaC may change between Steps 9–12 (FLAGGED fixes), and Step 12 writes the contractual validationResult to the manifest.

⛔ Halt on critical self-review failures — if any selfReview finding is FLAGGED at L1 (Security) or L3 (Hallucination), do NOT proceed to deploy. Present findings and ask: "Fix / Continue with risks / Cancel".

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at 617f8b5. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago

README badge

README badge for microsoft/skills/scaffold