CtrlK
BlogDocsLog inGet started
Tessl Logo

azure-enterprise-infra-planner

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

71

Quality

89%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-engineered skill body: a gated 7-phase pipeline with hard validation gates and feedback loops, concrete commands and artifact paths, and a clean progressive-disclosure structure into a verified reference bundle. The two 4-scores reflect minor duplication (tools listed twice, pipeline described in both prose and mermaid) and commands named rather than fully invoked in the body.

DimensionReasoningScore

Conciseness

The body is dense and assumes Claude's competence — tables for tools, errors, and artifacts, with no explanations of basic Azure concepts. Minor trimmable redundancy keeps it below the score-5 anchor: MCP tool names appear in both the Quick Reference and MCP Tools tables, and the 7-phase pipeline is narrated in prose ("Every phase advances only after its gate passes...") then re-depicted in the mermaid diagram.

4 / 5

Actionability

Mostly executable guidance: concrete commands ("az bicep build", "terraform validate", "checkov"), exact artifact paths ("<project-root>/.azure/infrastructure-plan.json", "infra/main.bicep"), a named status lifecycle, and a per-error fix table. It is not copy-paste-ready throughout (full command invocations, flags, and per-phase steps live in workflow.md and references/), so it fits the score-4 anchor rather than score 5.

4 / 5

Workflow Clarity

The 7-phase gated pipeline is clearly sequenced with explicit validation checkpoints and feedback loops: "Every phase advances only after its gate passes", VAL --errors--> P6 regeneration loop, P5 --no--> P4 approval loop, "Phase 6 is a hardened, self-verifying gate" requiring shown command output, and Phase 7's "explicit, risk-acknowledged deploy confirmation". This destructive-capable skill has validation everywhere, matching the top anchor including the checklist-driven completion self-check.

5 / 5

Progressive Disclosure

SKILL.md is a genuine overview that defers detail to well-signaled, one-level-deep references — workflow.md, schema.md, waf-checklist.md, referenced-workload.md, and the resources/ and constraints/ indexes — all of which exist in the bundle, and phases/ files are reached via workflow.md's phase table. Nothing that belongs in a reference is inlined; navigation is easy via the Quick Reference table.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: concrete capabilities, an explicit WHEN clause with seven natural trigger phrases, and active disambiguation against the adjacent azure-prepare skill. The only weakness is trigger-term coverage that misses a handful of natural synonyms (unhyphenated "hub and spoke", "IaC", Terraform-as-trigger).

DimensionReasoningScore

Specificity

Quotes multiple specific concrete actions — "Architect and provision enterprise Azure infrastructure from workload descriptions", "planning networking, identity, security, compliance, and multi-resource topologies", "Generates Bicep or Terraform directly (no azd)" — with comprehensive domain coverage. This matches the top anchor (multiple specific concrete actions) rather than the score-4 anchor, which would require noticeable coverage gaps; none are apparent for this domain.

5 / 5

Completeness

Explicitly answers both questions: what ("Architect and provision enterprise Azure infrastructure... Generates Bicep or Terraform directly") and when ("WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', ..." with seven concrete trigger phrases). This matches the score-5 anchor exactly; the score-4 anchor applies only when the 'when' is present but less explicit.

5 / 5

Trigger Term Quality

The WHEN clause offers seven natural user phrasings ("plan Azure infrastructure", "architect Azure landing zone", "design hub-spoke network", "plan multi-region DR topology", "set up VNets firewalls and private endpoints"), which is good coverage. It falls short of the score-5 anchor's comprehensive synonym coverage — natural variants such as "hub and spoke" (unhyphenated), "IaC", "Terraform" as a trigger, or "Azure landing zone" abbreviations are absent.

4 / 5

Distinctiveness Conflict Risk

Clear enterprise-infra-planning niche with distinct triggers (landing zone, hub-spoke, multi-region DR, subscription-scope Bicep) and explicit disambiguation from the nearest neighbor — "PREFER azure-prepare FOR app-centric workflows" and "(no azd)". Minimal conflict risk, matching the score-5 anchor.

5 / 5

Total

19

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

relative_links

Relative link issues: 2 deeper-than-1-level

Warning

referenced_paths_exist

Referenced path issues: 2 deeper-than-1-level

Warning

Total

14

/

16

Passed

Repository
microsoft/azure-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.