azure-deploy-02bedf — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited azure-deploy-02bedf (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE
>
PREREQUISITE: The azure-validate skill MUST be invoked and completed with status Validated BEFORE executing this skill.⛔ STOP — PREREQUISITE CHECK REQUIRED Before proceeding, verify BOTH prerequisites are met:
>
1. azure-prepare was invoked and completed →.azure/plan.mdexists 2. azure-validate was invoked and passed → plan status =Validated
>
If EITHER is missing, STOP IMMEDIATELY: - No plan? → Invoke azure-prepare skill first - Status not Validated? → Invoke azure-validate skill first>
⛔ DO NOT MANUALLY UPDATE THE PLAN STATUS
>
You are FORBIDDEN from changing the plan status to Validated yourself. Only the azure-validate skill is authorized to set this status after running actual validation checks. If you update the status without running validation, deployments will fail.>
DO NOT ASSUME the app is ready. DO NOT SKIP validation to save time. Skipping steps causes deployment failures. The complete workflow ensures success:
>
azure-prepare→azure-validate→azure-deploy
Activate this skill when user wants to:
azd up, azd deploy, or az deployment on a prepared projectScope: This skill executes deployments. It does not create applications, generate infrastructure code, or scaffold projects. For those tasks, use azure-prepare.
APIM / AI Gateway: Use this skill to deploy applications whose APIM/AI gateway infrastructure was already created during azure-prepare. For creating or changing APIM resources, see APIM deployment guide. For AI governance policies, invoke azure-aigateway skill.
.azure/plan.md must exist with status Validatedazd up, azd deploy, terraform apply, and az deployment commands. These commands are run through this skill's error recovery and verification pipeline.| # | Action | Reference |
|---|---|---|
| 1 | Check Plan — Read .azure/plan.md, verify status = Validated AND Validation Proof section is populated | .azure/plan.md |
| 2 | Pre-Deploy Checklist — MUST complete ALL steps | Pre-Deploy Checklist |
| 3 | Load Recipe — Based on recipe.type in .azure/plan.md | recipes/README.md |
| 4 | Execute Deploy — Follow recipe steps | Recipe README |
| 5 | Post-Deploy — Configure SQL managed identity and apply EF migrations if applicable | Post-Deployment |
| 6 | Handle Errors — See recipe's errors.md | — |
| 7 | Verify Success — Confirm deployment completed and endpoints are accessible | Verification |
⛔ VALIDATION PROOF CHECK
>
When checking the plan, verify the Validation Proof section (Section 7) contains actual validation results with commands run and timestamps. If this section is empty, validation was bypassed — invoke azure-validate skill first.
| Tool | Purpose |
|---|---|
mcp_azure_mcp_subscription_list | List available subscriptions |
mcp_azure_mcp_group_list | List resource groups in subscription |
mcp_azure_mcp_azd | Execute AZD commands |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.