- Policy EmulatorConventions and patterns for creating gateway emulator policy handlers in the Azure API Management policy toolkit. Use this skill when creating or modifying handler classes in src/Testing/Emulator/Policies/.Azure/azure-api-management-policy-toolkit95
- Policy Emulator TestingConventions and patterns for writing gateway emulator policy handler tests in the Azure API Management policy toolkit. Use this skill when creating or modifying test files in test/Test.Testing/Emulator/Policies/.Azure/azure-api-management-policy-toolkit95
- Policy TestingConventions and patterns for writing policy compilation tests in the Azure API Management policy toolkit. Use this skill when creating or modifying test files in test/Test.Core/Compiling/.Azure/azure-api-management-policy-toolkit95
- New ReleaseSkill for releasing a new Helm chart version for the Azure API Management Self-Hosted Gateway, optionally with a new container image version. Handles Chart.yaml updates, helm-docs regeneration, chart packaging, repo indexing, PR creation, and draft GitHub release preparation.Azure/api-management-self-hosted-gateway90
- Update Kubernetes ImagesUpdate pinned Kind node images used by the Helm chart CI workflows.Azure/api-management-self-hosted-gateway90
- Ccp Deployto StandaloneBuild a prometheus-collector CCP test image, deploy it to an AKS standalone, and validate metric scraping and ingestion into Azure Monitor.Azure/prometheus-collector88
- Ccp Update ProdimageBump the CCP prometheus-collector image tag across toggle file, featureflag readers, and regenerate helm fixtures in aks-rp. Use when "update promcollector image tag", "bump prometheus-collector CCP tag", or "ccp update-prodimage".Azure/prometheus-collector88
- Compare Cluster ManifestsCompare helm manifests between two AKS clusters running azure-monitor-metrics addon and generate a detailed diff report. Use when "compare manifests between clusters", "diff cluster deployments", "what changed between clusters", or "compare helm releases".Azure/prometheus-collector88
- Create Release Version PrCreate a prometheus-collector version bump and release notes PR by reviewing every commit merged to main since the previous version bump PR. Use when "create a release PR", "create version bump PR", "prepare release notes", "cut a prometheus-collector release", or "make a PR likeAzure/prometheus-collector88
- Generate Typespec SdkGenerate and safely replace a modeless synchronous Azure IoT Python SDK from a local or GitHub TypeSpec source.Azure/azure-iot-cli-extension88
- Release Aks Rp AddonExecute the AKS RP addon release for azure-monitor-metrics — update image tags, chart templates, versioning schemes, manifests, snapshots, and release notes. Use when "release new image to AKS RP", "update aks-rp image tags", "bump metrics addon version", "do an AKS RP release", or "monthly release for prometheus-collector". Also handles updating RELEASENOTES.md in this repo.Azure/prometheus-collector88
- Upgrade Kube State MetricsUpgrade the kube-state-metrics (KSM) image shipped with the azure-monitor-metrics addon to the latest Microsoft-built (dalec) version, verify it against MCR, and generate the PR changelog. Use when "upgrade kube-state-metrics", "bump KSM version", "update kube-state-metrics image tag", "new kube-state-metrics release", or "upgrade ksm to <version>".Azure/prometheus-collector88
- Validate Release Ready Image CidevValidate a prometheus-collector release image after version bump PR deploys to CI dev clusters, ensuring it's ready for production. Covers both the automated CI pipeline flow and manual validation steps. Use when "validate release image", "check CI test results", "debug testkube failures", or "is this image ready to release".Azure/prometheus-collector88
- Validate Release Ready Image CiprodValidate a prometheus-collector release image on the CI prod cluster (ci-prod-aks-mac-weu), ensuring it's healthy and ready for production. Manual validation only — no build pipeline checks. Use when "validate prod image", "check ci-prod cluster", "verify prod deployment", or "is the prod image healthy".Azure/prometheus-collector88
- Typespec Go Add Spector TestAdds a Spector mock API test for the typespec-go emitter. Use when given a Spector case link (http-specs or azure-http-specs) to generate the Go client, add it to tspcompile.js, write `*_client_test.go` tests, and validate them against the Spector mock server.Azure/autorest.go79
- Typespec Go Bump And ReleaseUpgrade tsp toolset dependencies for the @azure-tools/typespec-go package in Azure/autorest.go repo. Use when user wants to bump, update, or upgrade the TypeSpec toolset dependencies (e.g., @typespec/compiler, @typespec/http, @azure-tools/typespec-client-generator-core, @azure-tools/azure-http-specs), create a release PR, or publish a new version of typespec-go.Azure/autorest.go79
- Kickstart Acr IntegrationACR integration for AKS Automatic. Teaches attaching an ACR, image reference conventions (digest pinning, no :latest), and pull-secret-free authentication via the managed identity.Azure/vscode-aks-tools65
- Kickstart Bicep AuthoringWriting idiomatic, safe, and reviewable Bicep templates for Azure resources.Azure/vscode-aks-tools65
- Kickstart Cluster StatusNon-blocking cluster status peek — run at the end of Phases 3, 4, 5 to check AKS provisioning progress without hanging.Azure/vscode-aks-tools65
- Kickstart Collaborator VoiceVoice, tone, and interaction patterns for Kickstart agents.Azure/vscode-aks-tools65
- Kickstart Configure InfraConfigure Infrastructure phase playbook — launch the dedicated Kickstart cluster-setup view, which collects and creates the Azure resources (subscription, resource group, AKS Automatic cluster, ACR) and hands the results back to the chat.Azure/vscode-aks-tools65
- Kickstart DeployDeploy phase playbook — build, push, apply with Azure CLI and kubectl.Azure/vscode-aks-tools65
- Kickstart DesignDesign phase playbook — propose target architecture on AKS Automatic.Azure/vscode-aks-tools65
- Kickstart DiscoverDiscovery phase playbook — collect application details.Azure/vscode-aks-tools65
- Kickstart File GenerationRules for batching write_file calls efficiently. Prevents chatty incremental file writes and ensures the artifact store is updated atomically per logical unit of work.Azure/vscode-aks-tools65
- Kickstart GenerateGeneration phase playbook — create all deployment artifacts.Azure/vscode-aks-tools65
- Kickstart Github Pr ConventionsPull request conventions for trunk-based development and AKS deployment repos.Azure/vscode-aks-tools65
- Kickstart HandoffPre-deploy check playbook — verify cluster, ACR, permissions, and tooling before deployment.Azure/vscode-aks-tools65
- Kickstart Phase AccelerationRules for when agents may skip confirmations, condense phases, or proceed autonomously. Prevents unnecessary friction when context is sufficient to proceed confidently.Azure/vscode-aks-tools65
- Kickstart Pim ActivationPIM (Privileged Identity Management) eligible role activation. Checks for activatable roles via az rest and guides the user through portal-based activation when they hit 403 errors on role assignments.Azure/vscode-aks-tools65
- Kickstart ReviewReview phase playbook — validate all generated deployment artifacts.Azure/vscode-aks-tools65
- Kickstart Safeguard ChecklistAKS deployment safeguard rules checklist for validating Kubernetes manifests.Azure/vscode-aks-tools65
- Kickstart SamplesSample repository profiles for quick-start onboarding.Azure/vscode-aks-tools65
- Kickstart Security HardeningAzure security baseline — RBAC, Key Vault, managed identity, network isolation, and Microsoft Defender.Azure/vscode-aks-tools65
- Kickstart Workload IdentityWorkload Identity is mandatory for AKS Automatic. Covers managed identity setup, federated credentials, service account annotation, and Entra ID RBAC integration.Azure/vscode-aks-tools65
- Vscode Aks Tools Release PrPrepare a release PR for the Azure/vscode-aks-tools VS Code extension. Bumps version in package.json and package-lock.json, creates a new What's New doc, updates SUMMARY.md / release.md / README.md / releasing.md, and removes stale prior-release files. WHEN: 'make a release PR', 'release vscode-aks-tools', 'bump extension version', 'create publish-x.y.z branch', 'prepare release notes for aks tools', 'what's new file for next release'. DO NOT USE FOR: actually publishing to the marketplace (thatAzure/vscode-aks-tools65
- Avm Tf AzapiUse for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and ignore_body_changes.Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf ClassificationsUse this skill whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module / GitHub repo / Terraform Registry entry. Covers the three module classes, the criteria that separate them ("single resource only" vs "opinionated multi-resource solution" vs "shared logic"), the naming conventions per class (`avm-res-`, `avm-ptn-`, `avm-utl-`), and the corresponding GitHub repo name (`terraform-azAzure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf CodestyleUse for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf ConftestUse whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory. Covers current policy identifiers, example-local exception placement, package names, and managed policy validation. Trigger on "conftest", "rego", "APRL", "AVMSEC", "policy failure", "policy exception", "deny_", and "avm check policy".Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf DocumentationUse for AVM Terraform generated README content, _header.md, _footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf InterfacesUse for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf LifecycleUse this skill whenever an Azure Verified Module (AVM) is being proposed, approved, published, handed over to a new owner, orphaned, or deprecated — and whenever a contributor is choosing a version number for a Terraform AVM module release. Covers the four lifecycle stages (Proposed, Available, Orphaned, Deprecated), the 0.x.y pre-GA versioning rule that applies to ALL AVM modules right now, and the support obligations that come with module ownership. Trigger this skill on phrases like "propose Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf MigrationUse for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification compliance.Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf ProcessUse for the AVM Terraform contribution process from module proposal and repository setup through implementation, Avm.Authoring validation, pull request review, and release.Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf SubmodulesUse for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parent_id, resource_types, retry, timeouts, ignore_body_changes, outputs, files, and tests.Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf TelemetryUse this skill whenever an Azure Verified Module (AVM) for Terraform needs to wire up, debug, or explain telemetry — the `main.telemetry.tf` file with `modtm_telemetry` + `random_uuid.telemetry` + `data.azapi_client_config.telemetry` + `data.modtm_module_source.telemetry`, the `enable_telemetry` consumer-facing variable (which MUST default to `true` per SFR4), the `modtm` provider's role in shipping anonymous deployment counts to Application Insights, and the AzAPI request-header telemetry that Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf TestingUse for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.Azure/terraform-azurerm-avm-ptn-aks-production44
- Avm Tf TflintUse whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation. Covers the current canonical avm_* rules and the Avm.Authoring override merge process. Trigger on "tflint", "lint failure", "disable rule", "ignore rule", "rule override", "avm.tflint", "severity", and any AVM TFLint rule identifier.Azure/terraform-azurerm-avm-ptn-aks-production44
- DesignDesign rules and conventions for the API Center Portal. Use when editing detail pages, card components, badges, layout, navigation, sidebars, or headers. Covers badge styling, metadata placement, page navigation patterns, and layout alignment.Azure/APICenter-Portal-Starter43
- Ca ReleaseRelease workflow for containerization-assist (CA). Use when: cutting a new release, bumping patch/minor/major version, updating CHANGELOG.md for a release, preparing a release branch, syncing version across package.json and server.json, releasing CA, tagging a version, publishing a new version of containerization-assist.Azure/containerization-assist41
- Fix DockerfileValidate and remediate an existing Dockerfile against security, performance, and best-practice rules. Use AFTER a Dockerfile exists (either user-authored or produced by generate-dockerfile) and BEFORE building or pushing the image. Triggers include "fix my Dockerfile", "is this Dockerfile secure", "validate Dockerfile", "check Dockerfile for issues", "audit Dockerfile", or any container build flow that needs a sanity check.Azure/containerization-assist41
- Generate DockerfileGenerate or enhance a Dockerfile for a containerized application using curated base-image recommendations and security best practices. Use AFTER analyze-repo (or after the user has told you the language/framework). Triggers include "generate a Dockerfile", "containerize this", "write Dockerfile for X", or when running aks-loop and no Dockerfile yet exists. If a Dockerfile already exists, this skill enhances it in place.Azure/containerization-assist41
- Generate K8s ManifestsGenerate production-ready Kubernetes manifests (Deployment, Service, ConfigMap, Secret, ServiceAccount, optional HPA) for a containerized application. Use AFTER a Dockerfile exists and has been validated by fix-dockerfile. Triggers include "generate kubernetes manifests", "deploy this to k8s", "write k8s yaml", "create deployment yaml", or when running aks-loop and image is built. Writes manifests directly to the target directory.Azure/containerization-assist41
- Unbounded Agent Qemu Vm E2eUse this skill to perform unbounded-agent E2E run with qemu VM from local dev env.Azure/unbounded41
- Agentic WorkflowsRoute gh-aw workflow design/create/debug/upgrade requests to the right prompts.Azure/ARO-HCP39
- Agt E2e EncryptionKars AGT E2E encryption skill — how the Signal Protocol inter-agent messaging works, how to debug it, and what was patched.Azure/kars39
- Agt GovernanceBehavioral governance for OpenClaw agents via AGT — tool-level policy, inter-agent trust, audit logging.Azure/kars39
- Bootstrap Api VersionBootstrap a new ARM API version by copying the latest version, wiring it into the frontend, SDK, tests, and integration fixtures. Invoke with the new version string (e.g. "2027-03-15-preview").Azure/ARO-HCP39
- Foundry AgentsQuery and inspect Foundry prompt agents and invoke Foundry tools via the Responses API. OpenClaw is the orchestrator — Foundry provides managed AI services.Azure/kars39