[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"skill-azure-kickstart-security-hardening":3,"mdc--lbcb48-key":38,"related-repo-azure-kickstart-security-hardening":277,"related-org-azure-kickstart-security-hardening":378},{"slug":4,"name":4,"fn":5,"description":6,"org":7,"tags":12,"stars":27,"repoUrl":28,"updatedAt":29,"license":30,"forks":31,"topics":32,"repo":33,"sourceUrl":36,"mdContent":37},"kickstart-security-hardening","harden Azure security baselines","Azure security baseline — RBAC, Key Vault, managed identity, network isolation, and Microsoft Defender.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},"azure","Azure (Microsoft)","https:\u002F\u002Fpexgzepcugksgbtrxkhf.supabase.co\u002Fstorage\u002Fv1\u002Fobject\u002Fpublic\u002Forg-logos\u002Fazure.png","Azure",[13,17,18,21,24],{"name":14,"slug":15,"type":16},"Security","security","tag",{"name":11,"slug":8,"type":16},{"name":19,"slug":20,"type":16},"Microsoft Defender","microsoft-defender",{"name":22,"slug":23,"type":16},"Key Vault","key-vault",{"name":25,"slug":26,"type":16},"RBAC","rbac",65,"https:\u002F\u002Fgithub.com\u002FAzure\u002Fvscode-aks-tools","2026-07-12T08:18:12.110796",null,74,[],{"repoUrl":28,"stars":27,"forks":31,"topics":34,"description":35},[],"Visual Studio Code extension for Azure Kubernetes Service","https:\u002F\u002Fgithub.com\u002FAzure\u002Fvscode-aks-tools\u002Ftree\u002FHEAD\u002Fskills\u002Fkickstart-security-hardening","---\nname: kickstart-security-hardening\ndescription: Azure security baseline — RBAC, Key Vault, managed identity, network isolation, and Microsoft Defender.\ndisable-model-invocation: true\n---\n\n# Security Hardening\n\n## Principle of least privilege\n\n- Assign RBAC at the narrowest scope (resource > resource group > subscription > management group).\n- Use built-in roles before creating custom ones.\n- Common roles: `Reader`, `Contributor`, `Owner`, `Key Vault Secrets User`, `Storage Blob Data Reader`.\n- Avoid `Owner` on production subscriptions — use `Contributor` + specific data-plane roles.\n\n## Key Vault best practices\n\n- Soft delete + purge protection: **always on** in production.\n- Restrict access with Key Vault Firewall + private endpoint.\n- Use Managed Identity (not service principal secrets) to read secrets.\n- Rotate secrets every 90 days; use Key Vault references in App Service \u002F AKS.\n- Audit access with diagnostic settings → Log Analytics.\n\n## Encryption\n\n- Storage at rest: enabled by default (AES-256, Microsoft-managed keys).\n- Customer-managed keys (CMK) in Key Vault for compliance requirements.\n- TLS 1.2+ everywhere; disable older protocols.\n- Encryption in transit: HTTPS-only for storage, SQL, App Service.\n\n## Network isolation\n\n- Disable public network access on PaaS services when possible.\n- Use private endpoints for Storage, Key Vault, SQL, ACR.\n- Apply NSGs with default-deny inbound.\n\n## Microsoft Defender for Cloud\n\nEnable Defender plans for:\n- Servers (VM vulnerability scanning)\n- Containers (AKS runtime threat detection)\n- Storage (malware scanning, anomaly detection)\n- Key Vault (unusual access patterns)\n- SQL (SQL injection detection)\n\nSecure Score is your KPI — target 80%+.\n",{"data":39,"body":41},{"name":4,"description":6,"disable-model-invocation":40},true,{"type":42,"children":43},"root",[44,53,60,137,143,179,185,208,214,232,238,244,272],{"type":45,"tag":46,"props":47,"children":49},"element","h1",{"id":48},"security-hardening",[50],{"type":51,"value":52},"text","Security Hardening",{"type":45,"tag":54,"props":55,"children":57},"h2",{"id":56},"principle-of-least-privilege",[58],{"type":51,"value":59},"Principle of least privilege",{"type":45,"tag":61,"props":62,"children":63},"ul",{},[64,70,75,118],{"type":45,"tag":65,"props":66,"children":67},"li",{},[68],{"type":51,"value":69},"Assign RBAC at the narrowest scope (resource > resource group > subscription > management group).",{"type":45,"tag":65,"props":71,"children":72},{},[73],{"type":51,"value":74},"Use built-in roles before creating custom ones.",{"type":45,"tag":65,"props":76,"children":77},{},[78,80,87,89,95,96,102,103,109,110,116],{"type":51,"value":79},"Common roles: ",{"type":45,"tag":81,"props":82,"children":84},"code",{"className":83},[],[85],{"type":51,"value":86},"Reader",{"type":51,"value":88},", ",{"type":45,"tag":81,"props":90,"children":92},{"className":91},[],[93],{"type":51,"value":94},"Contributor",{"type":51,"value":88},{"type":45,"tag":81,"props":97,"children":99},{"className":98},[],[100],{"type":51,"value":101},"Owner",{"type":51,"value":88},{"type":45,"tag":81,"props":104,"children":106},{"className":105},[],[107],{"type":51,"value":108},"Key Vault Secrets User",{"type":51,"value":88},{"type":45,"tag":81,"props":111,"children":113},{"className":112},[],[114],{"type":51,"value":115},"Storage Blob Data Reader",{"type":51,"value":117},".",{"type":45,"tag":65,"props":119,"children":120},{},[121,123,128,130,135],{"type":51,"value":122},"Avoid ",{"type":45,"tag":81,"props":124,"children":126},{"className":125},[],[127],{"type":51,"value":101},{"type":51,"value":129}," on production subscriptions — use ",{"type":45,"tag":81,"props":131,"children":133},{"className":132},[],[134],{"type":51,"value":94},{"type":51,"value":136}," + specific data-plane roles.",{"type":45,"tag":54,"props":138,"children":140},{"id":139},"key-vault-best-practices",[141],{"type":51,"value":142},"Key Vault best practices",{"type":45,"tag":61,"props":144,"children":145},{},[146,159,164,169,174],{"type":45,"tag":65,"props":147,"children":148},{},[149,151,157],{"type":51,"value":150},"Soft delete + purge protection: ",{"type":45,"tag":152,"props":153,"children":154},"strong",{},[155],{"type":51,"value":156},"always on",{"type":51,"value":158}," in production.",{"type":45,"tag":65,"props":160,"children":161},{},[162],{"type":51,"value":163},"Restrict access with Key Vault Firewall + private endpoint.",{"type":45,"tag":65,"props":165,"children":166},{},[167],{"type":51,"value":168},"Use Managed Identity (not service principal secrets) to read secrets.",{"type":45,"tag":65,"props":170,"children":171},{},[172],{"type":51,"value":173},"Rotate secrets every 90 days; use Key Vault references in App Service \u002F AKS.",{"type":45,"tag":65,"props":175,"children":176},{},[177],{"type":51,"value":178},"Audit access with diagnostic settings → Log Analytics.",{"type":45,"tag":54,"props":180,"children":182},{"id":181},"encryption",[183],{"type":51,"value":184},"Encryption",{"type":45,"tag":61,"props":186,"children":187},{},[188,193,198,203],{"type":45,"tag":65,"props":189,"children":190},{},[191],{"type":51,"value":192},"Storage at rest: enabled by default (AES-256, Microsoft-managed keys).",{"type":45,"tag":65,"props":194,"children":195},{},[196],{"type":51,"value":197},"Customer-managed keys (CMK) in Key Vault for compliance requirements.",{"type":45,"tag":65,"props":199,"children":200},{},[201],{"type":51,"value":202},"TLS 1.2+ everywhere; disable older protocols.",{"type":45,"tag":65,"props":204,"children":205},{},[206],{"type":51,"value":207},"Encryption in transit: HTTPS-only for storage, SQL, App Service.",{"type":45,"tag":54,"props":209,"children":211},{"id":210},"network-isolation",[212],{"type":51,"value":213},"Network isolation",{"type":45,"tag":61,"props":215,"children":216},{},[217,222,227],{"type":45,"tag":65,"props":218,"children":219},{},[220],{"type":51,"value":221},"Disable public network access on PaaS services when possible.",{"type":45,"tag":65,"props":223,"children":224},{},[225],{"type":51,"value":226},"Use private endpoints for Storage, Key Vault, SQL, ACR.",{"type":45,"tag":65,"props":228,"children":229},{},[230],{"type":51,"value":231},"Apply NSGs with default-deny inbound.",{"type":45,"tag":54,"props":233,"children":235},{"id":234},"microsoft-defender-for-cloud",[236],{"type":51,"value":237},"Microsoft Defender for Cloud",{"type":45,"tag":239,"props":240,"children":241},"p",{},[242],{"type":51,"value":243},"Enable Defender plans for:",{"type":45,"tag":61,"props":245,"children":246},{},[247,252,257,262,267],{"type":45,"tag":65,"props":248,"children":249},{},[250],{"type":51,"value":251},"Servers (VM vulnerability scanning)",{"type":45,"tag":65,"props":253,"children":254},{},[255],{"type":51,"value":256},"Containers (AKS runtime threat detection)",{"type":45,"tag":65,"props":258,"children":259},{},[260],{"type":51,"value":261},"Storage (malware scanning, anomaly detection)",{"type":45,"tag":65,"props":263,"children":264},{},[265],{"type":51,"value":266},"Key Vault (unusual access patterns)",{"type":45,"tag":65,"props":268,"children":269},{},[270],{"type":51,"value":271},"SQL (SQL injection detection)",{"type":45,"tag":239,"props":273,"children":274},{},[275],{"type":51,"value":276},"Secure Score is your KPI — target 80%+.",{"items":278,"total":377},[279,293,308,323,339,352,365],{"slug":280,"name":280,"fn":281,"description":282,"org":283,"tags":284,"stars":27,"repoUrl":28,"updatedAt":292},"kickstart-acr-integration","integrate Azure Container Registry with AKS","ACR integration for AKS Automatic. Teaches attaching an ACR, image reference conventions (digest pinning, no :latest), and pull-secret-free authentication via the managed identity.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[285,286,289],{"name":11,"slug":8,"type":16},{"name":287,"slug":288,"type":16},"Containers","containers",{"name":290,"slug":291,"type":16},"Deployment","deployment","2026-07-12T08:18:05.091337",{"slug":294,"name":294,"fn":295,"description":296,"org":297,"tags":298,"stars":27,"repoUrl":28,"updatedAt":307},"kickstart-bicep-authoring","author idiomatic Azure Bicep templates","Writing idiomatic, safe, and reviewable Bicep templates for Azure resources.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[299,300,303,304],{"name":11,"slug":8,"type":16},{"name":301,"slug":302,"type":16},"Bicep","bicep",{"name":290,"slug":291,"type":16},{"name":305,"slug":306,"type":16},"Infrastructure as Code","infrastructure-as-code","2026-07-12T08:18:02.601998",{"slug":309,"name":309,"fn":310,"description":311,"org":312,"tags":313,"stars":27,"repoUrl":28,"updatedAt":322},"kickstart-cluster-status","monitor AKS cluster provisioning status","Non-blocking cluster status peek — run at the end of Phases 3, 4, 5 to check AKS provisioning progress without hanging.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[314,315,316,319],{"name":11,"slug":8,"type":16},{"name":290,"slug":291,"type":16},{"name":317,"slug":318,"type":16},"Kubernetes","kubernetes",{"name":320,"slug":321,"type":16},"Monitoring","monitoring","2026-07-12T08:18:01.355249",{"slug":324,"name":324,"fn":325,"description":326,"org":327,"tags":328,"stars":27,"repoUrl":28,"updatedAt":338},"kickstart-collaborator-voice","define agent voice and interaction patterns","Voice, tone, and interaction patterns for Kickstart agents.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[329,332,335],{"name":330,"slug":331,"type":16},"Agents","agents",{"name":333,"slug":334,"type":16},"Branding","branding",{"name":336,"slug":337,"type":16},"Communications","communications","2026-07-12T08:18:09.636172",{"slug":340,"name":340,"fn":341,"description":342,"org":343,"tags":344,"stars":27,"repoUrl":28,"updatedAt":351},"kickstart-configure-infra","configure Azure infrastructure for AKS clusters","Configure Infrastructure phase playbook — launch the dedicated Kickstart cluster-setup view, which collects and creates the Azure resources (subscription, resource group, AKS Automatic cluster, ACR) and hands the results back to the chat.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[345,346,347,350],{"name":11,"slug":8,"type":16},{"name":290,"slug":291,"type":16},{"name":348,"slug":349,"type":16},"Infrastructure","infrastructure",{"name":317,"slug":318,"type":16},"2026-07-12T08:18:03.828624",{"slug":353,"name":353,"fn":354,"description":355,"org":356,"tags":357,"stars":27,"repoUrl":28,"updatedAt":364},"kickstart-deploy","deploy applications with Azure CLI and kubectl","Deploy phase playbook — build, push, apply with Azure CLI and kubectl.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[358,359,362,363],{"name":11,"slug":8,"type":16},{"name":360,"slug":361,"type":16},"CLI","cli",{"name":290,"slug":291,"type":16},{"name":317,"slug":318,"type":16},"2026-07-12T08:17:52.254389",{"slug":366,"name":366,"fn":367,"description":368,"org":369,"tags":370,"stars":27,"repoUrl":28,"updatedAt":376},"kickstart-design","propose target architecture on AKS","Design phase playbook — propose target architecture on AKS Automatic.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[371,374,375],{"name":372,"slug":373,"type":16},"Architecture","architecture",{"name":11,"slug":8,"type":16},{"name":290,"slug":291,"type":16},"2026-07-12T08:17:50.938775",19,{"items":379,"total":554},[380,399,414,433,448,463,476,491,502,516,529,542],{"slug":381,"name":381,"fn":382,"description":383,"org":384,"tags":385,"stars":396,"repoUrl":397,"updatedAt":398},"azure-arg-external-evaluation-policy-author","author and test Azure Resource Graph policies","Use when the user wants to author, design, or test an Azure Policy that queries Azure Resource Graph (ARG) at request-time — i.e. a policy whose deny\u002Faudit decision depends on data from elsewhere in the subscription (sibling\u002Fparent resource state, RG-wide invariants, multi-hop relationships, etc.). Formally called Azure Policy External Evaluation; sometimes referred to colloquially as \"Invoke\". Drives an iterative KQL co-design loop against the user's real subscription via `az graph query`, then emits a policy definition, assignment, `.http` test flow, and an `EXPLANATION.md` companion. Read-only; never provisions anything.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[386,387,390,393],{"name":11,"slug":8,"type":16},{"name":388,"slug":389,"type":16},"Compliance","compliance",{"name":391,"slug":392,"type":16},"Governance","governance",{"name":394,"slug":395,"type":16},"Policy","policy",1686,"https:\u002F\u002Fgithub.com\u002FAzure\u002Fazure-policy","2026-07-12T08:17:48.378432",{"slug":400,"name":400,"fn":401,"description":402,"org":403,"tags":404,"stars":411,"repoUrl":412,"updatedAt":413},"azure-blueprints-migration","migrate Azure Blueprints to Template Specs","Use when a user needs to migrate off Azure Blueprints (definitions and\u002For assignments) to Template Specs and Deployment Stacks before the January 31, 2027 retirement. Covers inventory, export, conversion to Bicep, policy decoupling, Template Spec publishing, Deployment Stack deployment with deny-settings, validation, and cutover.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[405,406,407,408],{"name":11,"slug":8,"type":16},{"name":290,"slug":291,"type":16},{"name":305,"slug":306,"type":16},{"name":409,"slug":410,"type":16},"Migration","migration",260,"https:\u002F\u002Fgithub.com\u002FAzure\u002Fazure-blueprints","2026-07-12T08:17:49.646405",{"slug":415,"name":415,"fn":416,"description":417,"org":418,"tags":419,"stars":430,"repoUrl":431,"updatedAt":432},"apiview-feedback-resolution","resolve APIView feedback on Azure SDKs","Analyze and resolve APIView review feedback on Azure SDK PRs. **UTILITY SKILL**. USE FOR: APIView comments, API review feedback, SDK API surface changes. DO NOT USE FOR: general code review, non-APIView feedback. INVOKES: azure-sdk-mcp:azsdk_apiview_get_comments, azure-sdk-mcp:azsdk_typespec_customized_code_update.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[420,423,424,427],{"name":421,"slug":422,"type":16},"API Development","api-development",{"name":11,"slug":8,"type":16},{"name":425,"slug":426,"type":16},"Code Review","code-review",{"name":428,"slug":429,"type":16},"Documentation","documentation",133,"https:\u002F\u002Fgithub.com\u002FAzure\u002Fazure-sdk-tools","2026-07-12T08:17:43.350876",{"slug":434,"name":434,"fn":435,"description":436,"org":437,"tags":438,"stars":430,"repoUrl":431,"updatedAt":447},"azsdk-common-live-and-recorded-tests","deploy resources and run Azure SDK tests","Deploy test resources and run Azure SDK tests in live, record, or playback mode. WHEN: \"run live tests\", \"run recorded tests\", \"deploy test resources\", \"record tests\", \"run tests in record mode\", \"clean up test resources\", \"run tests against live resources\". DO NOT USE FOR: writing new tests, authoring Bicep templates, playback-only test runs without resource deployment. INVOKES: azure-sdk-mcp:azsdk_package_run_tests.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[439,440,441,444],{"name":11,"slug":8,"type":16},{"name":290,"slug":291,"type":16},{"name":442,"slug":443,"type":16},"SDK","sdk",{"name":445,"slug":446,"type":16},"Testing","testing","2026-07-12T08:17:44.718943",{"slug":449,"name":449,"fn":450,"description":451,"org":452,"tags":453,"stars":430,"repoUrl":431,"updatedAt":462},"azsdk-common-prepare-release-plan","manage Azure SDK release plan work items","Create, get, update, abandon, and link SDK PRs to release plan work items for Azure SDK releases. **UTILITY SKILL**. USE FOR: \"create release plan\", \"get release plan\", \"update release plan\", \"update API spec in release plan\", \"update SDK details in release plan\", \"abandon release plan\", \"link SDK PR to plan\", \"namespace approval\", \"check release plan status\". DO NOT USE FOR: SDK code generation, pipeline troubleshooting, API review feedback. INVOKES: azure-sdk-mcp:azsdk_create_release_plan, azure-sdk-mcp:azsdk_get_release_plan, azure-sdk-mcp:azsdk_get_release_plan_for_spec_pr, azure-sdk-mcp:azsdk_update_release_plan, azure-sdk-mcp:azsdk_update_api_spec_pull_request_in_release_plan, azure-sdk-mcp:azsdk_update_sdk_details_in_release_plan, azure-sdk-mcp:azsdk_abandon_release_plan, azure-sdk-mcp:azsdk_link_sdk_pull_request_to_release_plan, azure-sdk-mcp:azsdk_link_namespace_approval_issue.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[454,455,458,461],{"name":11,"slug":8,"type":16},{"name":456,"slug":457,"type":16},"GitHub","github",{"name":459,"slug":460,"type":16},"Project Management","project-management",{"name":442,"slug":443,"type":16},"2026-07-12T08:17:38.345387",{"slug":464,"name":464,"fn":465,"description":466,"org":467,"tags":468,"stars":430,"repoUrl":431,"updatedAt":475},"azsdk-common-sdk-release","release Azure SDK packages","Check release readiness and trigger the release pipeline for Azure SDK packages. **UTILITY SKILL**. USE FOR: \"release SDK\", \"trigger release\", \"check release readiness\", \"release pipeline\", \"publish package\", \"ship SDK\". DO NOT USE FOR: SDK development, code generation, pipeline debugging, release plan creation. INVOKES: azure-sdk-mcp:azsdk_release_sdk.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[469,470,473,474],{"name":11,"slug":8,"type":16},{"name":471,"slug":472,"type":16},"CI\u002FCD","ci-cd",{"name":290,"slug":291,"type":16},{"name":442,"slug":443,"type":16},"2026-07-12T08:17:34.27607",{"slug":477,"name":477,"fn":478,"description":479,"org":480,"tags":481,"stars":430,"repoUrl":431,"updatedAt":490},"azure-typespec-author","author and modify Azure TypeSpec API specifications","Authors and modifies Azure TypeSpec (.tsp) API specifications. USE FOR: any TypeSpec\u002Ftsp change — api versions (add, bump, preview, stable, promote), resources, operations, models, properties, decorators, visibility, constraints, breaking changes, LRO, suppressions, operationId, spread model. Covers ARM resource-manager and data-plane services. DO NOT USE FOR: SDK generation, releasing SDK packages, or single MCP tool calls. INVOKES: azure-sdk-mcp:azsdk_typespec_generate_authoring_plan, azure-sdk-mcp:azsdk_run_typespec_validation.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[482,483,484,487],{"name":421,"slug":422,"type":16},{"name":11,"slug":8,"type":16},{"name":485,"slug":486,"type":16},"OpenAPI","openapi",{"name":488,"slug":489,"type":16},"Technical Writing","technical-writing","2026-07-12T08:17:39.603232",{"slug":492,"name":492,"fn":493,"description":494,"org":495,"tags":496,"stars":430,"repoUrl":431,"updatedAt":501},"generate-sdk-locally","generate and test Azure SDKs locally","Generate, build, and test Azure SDKs locally from TypeSpec with automatic customization. WHEN: \"generate SDK locally\", \"build SDK\", \"run SDK tests\", \"run CI checks\", \"validate package\", \"run checks\", \"update changelog\", \"fix SDK build errors\", \"fix breaking changes\", \"resolve SDK generation errors\", \"customize TypeSpec\", \"rename SDK client\", \"rename SDK model\", \"hide operation from SDK\", \"fix analyzer errors\", \"resolve customization drift\", \"create subclient\", \"update metadata\", \"update version\". DO NOT USE FOR: publishing to package registries, CI pipeline configuration, API design review. INVOKES: azsdk_verify_setup, azsdk_package_generate_code, azsdk_package_build_code, azsdk_package_run_check, azsdk_package_run_tests, azsdk_customized_code_update, azsdk_package_update_changelog_content, azsdk_package_update_metadata, azsdk_package_update_version.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[497,498,499,500],{"name":11,"slug":8,"type":16},{"name":471,"slug":472,"type":16},{"name":442,"slug":443,"type":16},{"name":445,"slug":446,"type":16},"2026-07-12T08:17:37.08523",{"slug":503,"name":503,"fn":504,"description":505,"org":506,"tags":507,"stars":430,"repoUrl":431,"updatedAt":515},"markdown-token-optimizer","optimize markdown files for token efficiency","Analyze markdown files for token efficiency and reduce context-window bloat. **UTILITY SKILL**. DO NOT USE FOR: code optimization, general file editing, non-markdown files. TRIGGERS: optimize markdown, reduce tokens, token count, token bloat, too many tokens, make concise, shrink file, file too large, optimize for AI, token efficiency, verbose markdown, reduce file size. INVOKES: waza CLI.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[508,511,514],{"name":509,"slug":510,"type":16},"LLM","llm",{"name":512,"slug":513,"type":16},"Performance","performance",{"name":488,"slug":489,"type":16},"2026-07-12T08:17:42.080413",{"slug":517,"name":517,"fn":518,"description":519,"org":520,"tags":521,"stars":430,"repoUrl":431,"updatedAt":528},"pipeline-troubleshooting","troubleshoot Azure SDK CI pipelines","Diagnose and resolve failures in Azure SDK CI and generation pipelines. **UTILITY SKILL**. USE FOR: \"pipeline failed\", \"build failure\", \"CI check failing\", \"SDK generation error\", \"reproduce pipeline locally\", \"debug SDK pipeline\". DO NOT USE FOR: local build issues without pipeline context, API design review, SDK publishing. INVOKES: azure-sdk-mcp:azsdk_analyze_pipeline, azure-sdk-mcp:azsdk_package_build_code, azure-sdk-mcp:azsdk_package_run_check.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[522,523,524,527],{"name":11,"slug":8,"type":16},{"name":471,"slug":472,"type":16},{"name":525,"slug":526,"type":16},"Debugging","debugging",{"name":442,"slug":443,"type":16},"2026-07-12T08:17:40.821512",{"slug":530,"name":530,"fn":531,"description":532,"org":533,"tags":534,"stars":430,"repoUrl":431,"updatedAt":541},"sensei","improve skill frontmatter compliance","**WORKFLOW SKILL** — Iteratively improve skill frontmatter compliance using the Ralph loop pattern. WHEN: \"run sensei\", \"sensei help\", \"improve skill\", \"fix frontmatter\", \"skill compliance\", \"frontmatter audit\", \"score skill\", \"check skill tokens\". INVOKES: token counting tools, test runners, git commands. FOR SINGLE OPERATIONS: use token CLI directly for counts\u002Fchecks.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[535,536,537,540],{"name":11,"slug":8,"type":16},{"name":388,"slug":389,"type":16},{"name":538,"slug":539,"type":16},"Process Optimization","process-optimization",{"name":488,"slug":489,"type":16},"2026-07-12T08:17:32.970921",{"slug":543,"name":543,"fn":544,"description":545,"org":546,"tags":547,"stars":430,"repoUrl":431,"updatedAt":553},"skill-authoring","author agent skills for agentskills.io","Write Agent Skills that comply with the agentskills.io specification. WHEN: \"create a skill\", \"new skill\", \"write a skill\", \"skill template\", \"skill structure\", \"review skill\", \"skill PR\", \"skill compliance\", \"SKILL.md format\", \"skill frontmatter\", \"skill best practices\". DO NOT USE FOR: improving existing skills (use sensei), general documentation. INVOKES: waza CLI.",{"slug":8,"name":9,"logoUrl":10,"githubOrg":11},[548,549,552],{"name":428,"slug":429,"type":16},{"name":550,"slug":551,"type":16},"Plugin Development","plugin-development",{"name":488,"slug":489,"type":16},"2026-07-12T08:17:35.873862",109]