Skip to main content
在 Manus 中运行任何 Skill
一键导入
GitHub 仓库

awesome-gbb

awesome-gbb 收录了来自 aiappsgbb 的 40 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
40
Stars
5
更新
2026-07-15
Forks
2
职业覆盖
6 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

foundry-iq
软件开发工程师

Build enterprise RAG with Foundry IQ and Azure AI Search Knowledge Bases using agentic retrieval, multi-hop reasoning, query planning, and citation-backed responses. Distinguishes the stable 2026-04-01 programmatic API from preview portal experiences and preview-only knowledge-source integrations. USE FOR: knowledge base, RAG, agentic retrieval, policy assistant, citations, multi-hop QA, Knowledge Agent, AI Search Knowledge Base, document grounding, semantic retrieval, foundry-iq, knowledge index, hybrid search, vector search, kb-mcp, web iq boundary, serverless knowledge base boundary, purview acl knowledge. DO NOT USE FOR: structured-document extraction (use foundry-doc-vision-speech), standalone Work IQ, Fabric IQ, or Web IQ workloads, MCP server deployment (use foundry-mcp-aca), agent runtime (use foundry-hosted-agents).

2026-07-15
foundry-hosted-agents
软件开发工程师

Deploy + manage Foundry hosted agents — container deploy via unified azure.yaml is GA; source-code --deploy-mode code is still preview. MAF 1.8.0, azd ext install microsoft.foundry, implicit agent access (no default role grant). Read the body for patterns, identity, runtime, rollout, troubleshooting. USE FOR: deploy foundry agent, hosted agent, container agent, azure.yaml, azd ai agent, microsoft.foundry, MAF, FoundryChatClient, ResponsesHostServer, ACR push, batch eval, agent identity, Foundry User role, entra-agent-id, Responses/Invocations protocols, Activity protocol, blue-green deploy, canary rollout, version rollback, traffic routing, version_selector, agent_endpoint, update_details. DO NOT USE FOR: prompt agents (use foundry-prompt-agents), ACA MCP (use foundry-mcp-aca), GHCP coding agent (use ghcp-hosted-agents), Citadel hub/spoke (use citadel-hub-deploy), pilot pipeline (use threadlight-deploy), continuous eval (use foundry-evals), Routines (use foundry-routines), A2A wiring (use foundry-toolbox).

2026-07-15
azd-patterns
网络与计算机系统管理员

Tips and patterns for Azure Developer CLI (azd) workflows, ACA job deployment, and infrastructure scripting conventions. USE FOR: azd hooks, postdeploy, postprovision, ACA job deployment, container app job image update, publish_aca, deploy_job, azure.yaml hooks, cross-platform deployment scripts, uv run, azd env, azd conventions, infra scripts, MCAPS subscription, SecurityControl Ignore tag, resource group tagging, Defender for Cloud noise, Azure Policy auto-remediation, AZURE_TAGS, pilot posture, demo subscription tagging, AcrPull, ImagePullError, JSON array param, BCP186, FetchingKeyVaultSecretFailed, dependsOn rbac, image-pull credential, ACA placeholder image, azd env set triple-escape. DO NOT USE FOR: az login, tenant switching, subscription isolation (use azure-tenant-isolation), Foundry agents (use microsoft-foundry).

2026-07-15
foundry-mcp-aca
软件开发工程师

Deploy custom MCP servers as Azure Container Apps or Azure Functions for use with Foundry hosted agents. Covers Cosmos DB MCPToolKit, Playwright MCP, custom MCP servers, protocol requirements, ACA configuration, and authentication + hardening (ACA built-in auth / Easy Auth, OAuth, managed identity). USE FOR: deploy MCP server, MCP on ACA, Cosmos MCP, Playwright MCP in Foundry, custom MCP server, Azure Functions MCP, MCP ACA deployment, remote MCP endpoint, MCP for hosted agent, connect hosted agent to MCP, secure MCP server, harden MCP server, MCP authentication, MCP OAuth, ACA Easy Auth for MCP. DO NOT USE FOR: deploying the hosted agent itself (use threadlight-deploy), local MCP development (use mcp-config.json directly), general Azure deploy.

2026-07-15
ghcp-hosted-agents
软件开发工程师

Deploy Foundry hosted agents using GitHub Copilot SDK (GHCP) with BYOK authentication and Invocations protocol. Alternative to MAF (Agent + FoundryChatClient + ResponsesHostServer). Use when you need streaming SSE output, progressive skill discovery, or long tool loops (>120s) that hit Foundry gateway timeout with Responses protocol. USE FOR: ghcp sdk, copilot sdk, github copilot agent, CopilotClient, InvocationAgentServerHost, BYOK, bring your own key, invocations protocol, SSE streaming agent, long running agent, send_and_wait timeout, ghcp hosted agent, copilot client foundry. DO NOT USE FOR: MAF agents (use foundry-hosted-agents), prompt agents, declarative agents, general Azure deploy.

2026-07-15
foundry-toolbox
软件开发工程师

Use Microsoft Foundry Toolbox GA to manage versioned multi-tool bundles behind a single MCP endpoint and connect them to hosted agents. Covers stable AIProjectClient.toolboxes CRUD, Toolbox-specific SDK models, agent_framework_foundry_hosting.FoundryToolbox, authentication, immutable-version promotion and rollback, the azd ai toolbox declarative path, and preview Tool Search. Distinguishes the GA Toolbox core from preview A2A, Work IQ, Fabric IQ, Browser Automation, Reminder, skills, and Tool Search; explains that azure_ai_search wraps an index, not a Foundry IQ knowledge base. USE FOR: foundry toolbox, toolbox MCP endpoint, AIProjectClient toolboxes, FoundryToolbox, toolbox version promote, multi-tool MCP endpoint, ToolboxSearchPreviewToolboxTool, kind toolbox, host azure.ai.toolbox, toolbox.yaml. DO NOT USE FOR: building MCP servers (use foundry-mcp-aca), KB-only RAG (use foundry-iq), generic hosted-agent runtime (use foundry-hosted-agents), cross-resource models (use foundry-cross-resource).

2026-07-14
citadel-spoke-onboarding
软件开发工程师

Onboard a Foundry project as a spoke into an AI Citadel Governance Hub. Covers Access Contracts, APIM connections, product policies, JWT auth. USE FOR: citadel spoke onboarding, access contract, connect foundry to citadel, APIM connection, bring your own ai gateway, govern agent, citadel JWT auth, citadel product policy, unified ai api, citadel AGT, vnet-isolated citadel spoke, foundry-vnet-deploy spoke onboarding. DO NOT USE FOR: deploying the Citadel hub itself, APIM infrastructure, hub networking, hub provisioning, hub sizing, llm backend onboarding, deploying model backends, apim backend pools, hub policy fragment deployment, spoke-side VNet/peering creation (use foundry-vnet-deploy).

2026-07-13
foundry-doc-vision-speech
软件开发工程师

Add vision (gpt-5.4 family), Document Intelligence v4, and Azure Speech (STT/TTS) capabilities to a Foundry hosted agent. Covers tool contracts, Bicep modules, runtime client code, and model selection for vision workloads. USE FOR: vision tool, image analysis, damage photo analysis, blueprint annotation, document extraction, structured doc parsing, OCR, voice intake, FNOL voice claim, STT, TTS, gpt-5.4-mini vision, gpt-5.4 vision, Document Intelligence prebuilt, custom doc model, Azure Speech, transcription. DO NOT USE FOR: deploying the agent itself (use threadlight-deploy), MCP server deployment (use foundry-mcp-aca), Foundry IQ knowledge retrieval (use foundry-iq), real-time voice / Voice Live (use foundry-voice-live).

2026-07-13
foundry-skill-catalog
软件开发工程师

Centrally store and distribute instruction-only `SKILL.md` files via the Foundry **Skills** REST API (`{project}/skills`) — and consume them at runtime from MAF agents through a custom `SkillsSource` adapter. Hosted agents only (no Prompt agents). Covers the JSON vs ZIP modes (JSON mode is **write-only** — body never returned), the mandatory `Foundry-Features: Skills=V1Preview` header, the unquoted-frontmatter HTTP 500 trap, `allow_preview=True`, and the verified-working `FoundrySkillsSource(SkillsSource)` for `agent_framework.SkillsProvider`. USE FOR: foundry skills, central skill store, client.beta.skills, has_blob, create_from_package, Foundry-Features Skills V1Preview, FoundrySkillsSource, SkillsProvider with Foundry, skills:import, skills:download. DO NOT USE FOR: awesome-gbb skill authoring (this very repo), Foundry tools (use foundry-toolbox), file-system SkillsProvider wiring (use foundry-hosted-agents § Skill Loading), generic hosted-agent runtime.

2026-07-13
paygo-ptu-cost-analyzer
软件开发工程师

Headless Azure OpenAI PAYGO-vs-PTU cost analysis and sizing report. Wraps the analysis library of aiappsgbb/ptu-paygo-mix (NOT its Streamlit UI). Supports CSV token-usage input and Log Analytics queries via vendored KQL against `AzureMetrics`. Produces a markdown report, JSON data, and charts. Bundles a synthetic-data generator for offline demos. USE FOR: ptu sizing, paygo vs ptu, provisioned throughput unit recommendation, AOAI capacity planning, TPM percentile report, spillover cost estimate, log analytics token query, AzureMetrics PTU, CSV-based PTU sizing, headless cost report, paygo-ptu-cost-analyzer. DO NOT USE FOR: capacity reservation purchase workflow, deploying the upstream Streamlit UI (use the upstream repo), real-time TPM monitoring (use azure-monitor-query directly), pricing for non-Azure-OpenAI services.

2026-07-13
foundry-cross-resource
软件开发工程师

Cross-resource model invocation in Microsoft Foundry via an Azure APIM AI Gateway, using the `connectionName/deploymentName` model string. Covers ApiKey and ProjectManagedIdentity (PMI) auth paths, multiple invocation patterns, APIM inbound policy, connection ARM/REST schema, and the metadata-stringification quirk. Read the full skill body for auth wiring and policy XML — do not configure from this summary alone. USE FOR: connectionName/deploymentName, cross-resource model access, AI Gateway, APIM connection, ApiManagement connection, remote model invocation, Foundry gateway, use models from another Foundry project, APIM AI gateway setup, Foundry Agent Service gateway, model gateway connection, remote deployment, ProjectManagedIdentity APIM, AI Foundry APIM ApiKey. DO NOT USE FOR: single-resource model calls (use the project's own AzureOpenAI/AIServices connection), Azure tenant isolation (use azure-tenant-isolation), Foundry project creation, APIM creation from scratch.

2026-07-07
foundry-prompt-agents
软件开发工程师

Create and manage Foundry prompt agents — declarative agents that combine a model, instructions, and tools without containers or custom code. Covers azure-ai-projects SDK (PromptAgentDefinition), tool wiring (web search, code interpreter, file search, MCP, OpenAPI, Fabric IQ, Work IQ, Tool Search, Skill Reference, Guardrail, A2A, Browser Automation), conversations API, versioning, structured inputs, and publishing as agent applications. USE FOR: prompt agent, declarative agent, PromptAgentDefinition, azure-ai-projects, agent tools, WebSearchTool, CodeInterpreterTool, FileSearchTool, MCPTool, OpenApiTool, FabricIQTool, WorkIQTool, ToolSearchTool, SkillReferenceTool, GuardrailTool, A2ATool, BrowserAutomationTool, conversations API, structured inputs, publish agent, Foundry Agent Service. DO NOT USE FOR: hosted container agents (use foundry-hosted-agents), MAF agent framework, MCP server deployment (use foundry-mcp-aca), agent evaluation (use foundry-evals), Knowledge Base / retrieval (use foundry-iq).

2026-07-04
foundry-teams-bot
软件开发工程师

Connect a Microsoft Foundry Hosted Agent to Microsoft Teams — generate the bot code, Bicep infrastructure, Teams manifest, and ACA deployment. Uses Azure Bot Service with UAMI auth and the microsoft-agents-* SDK. USE FOR: connect agent to Teams, Teams bot, Teams integration, expose agent in Teams, Teams channel, sideload Teams app, add Teams to Foundry agent, chat with agent in Teams. DO NOT USE FOR: designing the agent (use threadlight-design), deploying the hosted agent itself (use threadlight-deploy), general Bot Framework development.

2026-07-04
foundry-caphost-lifecycle
网络与计算机系统管理员

Day-2 lifecycle of Microsoft Foundry capability hosts — the operational layer on top of MS Learn's create-only guidance. Covers idempotent create (REST 2025-06-01), inspect/GET, delete, **soft-delete + purge of the parent Cognitive Services account** (the only op that releases the `serviceAssociationLink` on the agent subnet), redeploy guard for `Subnet already in use`, concurrent-op retry, idempotency rules, and soft-delete recovery (48h window). USE FOR: capability host lifecycle, caphost delete, caphost purge, soft-delete recover, serviceAssociationLink release, Subnet already in use, caphost idempotency, caphost 409 concurrent op, redeploy after teardown, az cognitiveservices account purge. DO NOT USE FOR: greenfield BYO-VNet Foundry deploy (use foundry-vnet-deploy), azd-template Foundry deploy (use threadlight-deploy or foundry-hosted-agents), spoke onboarding (use citadel-spoke-onboarding), tenant isolation (use azure-tenant-isolation).

2026-07-04
foundry-memory
软件开发工程师

Use Azure AI Foundry Memory Store for persistent agent memory across sessions: user profiles, chat summaries, procedural memory, semantic memory retrieval, hosted-agent memory tool wiring, scope isolation via x-memory-user-id / {{$userId}}, and azure-ai-projects patterns across Python, C#, and TypeScript. USE FOR: foundry memory, memory store, user profile, chat summary, procedural memory, cross-session memory, persistent memory, agent memory, remember user preferences, conversation history, semantic memory retrieval, memory CRUD, memory TTL, azd memory commands, azure-ai-projects memory, replace Mem0. DO NOT USE FOR: RAG/knowledge retrieval (use foundry-iq), document grounding, vector search over documents.

2026-07-03
foundry-observability
网络与计算机系统管理员

End-to-end observability for Azure AI pilots — App Insights + Log Analytics + OpenTelemetry across hosted agents, ACA MCP servers, ACA jobs, bot service, workspace UIs. Closes the silent telemetry gap where `azd up` returns 0 but **zero traces ever reach App Insights**. Covers Bicep modules, Foundry account-level telemetry connection, ACA-side instrumentation, `Monitoring Metrics Publisher` RBAC, and KQL diagnostic queries. Read the full skill body for the 3-layer wiring sequence — do not instrument from this summary alone. USE FOR: app insights, application insights, OpenTelemetry, OTel, configure_azure_monitor, agent traces missing, no telemetry, blank appin, log analytics, KQL, observability, trace MCP, silent cron, Monitoring Metrics Publisher RBAC, AppInsights connection foundry, account-level appin, AppIn PUT 400, credentials null, silent injection, server_error telemetry. DO NOT USE FOR: continuous eval (foundry-evals), pre-deploy gates (threadlight-safe-check), Foundry IQ monitoring (foundry-iq).

2026-07-03
foundry-routines
网络与计算机系统管理员

Schedule and dispatch Foundry agent invocations via Routines — declarative automation rules that fire on cron (schedule trigger) or at a specific time (timer trigger). Wraps azure-ai-projects 2.2.0+ `client.beta.routines` (create_or_update, dispatch, enable/disable, list/get/list_runs, delete), both action types (`invoke_agent_responses_api`, `invoke_agent_invocations_api`), YAML routine manifests, the `Foundry-Features: Routines=V1Preview` REST header, and regional preview availability. USE FOR: routines, scheduled agent, timer trigger, recurring trigger, cron schedule, agent automation, run history, dispatch_async, Foundry-Features header, RoutineDispatchPayload, azd ai routine. DO NOT USE FOR: multi-step orchestration or multi-agent coordination (use workflows), branching/approval logic (use workflows), in-cluster cron outside Foundry (use Azure Functions / Logic Apps), agent runtime (use foundry-prompt-agents or foundry-hosted-agents).

2026-07-03
azure-resource-diagnostics
网络与计算机系统管理员

Audit Azure diagnostic-settings coverage at resource-group scope. For each resource in the RG (optionally filtered by target_resource_types — ARM types or snake_case logical kinds like storage_account), queries Microsoft.Insights/diagnosticSettings and reports whether ANY destination is configured (Log Analytics, Event Hubs, or Storage). Flags no-diagnostic-settings resources. Wraps azure-mgmt-monitor + azure-mgmt-resource with a never-raising probe() returning structured findings; RG-list denial returns confidence 0.0 with probe_error rather than raising. Writes manifest JSON to out/<finding-id>.json and returns the equivalent dict. CLI: python -m azure_resource_diagnostics --sub <sub-id> --rg <rg>. USE FOR: diagnostic settings audit, log routing coverage, no-diagnostic-settings detection, Foundry RG diagnostics, OBS-106 self-verify. DO NOT USE FOR: creating diagnostic settings, log-category policy authoring, querying the logs themselves, or metric-alert coverage (use azure-monitor-alert-baseline).

2026-07-03
azure-backup-readiness
软件开发工程师

Audit Azure backup coverage at resource-group scope. Checks BOTH Recovery Services Vaults (RSV, azure-mgmt-recoveryservices) AND Backup Vaults (DataProtection, azure-mgmt-dataprotection). For each vault found, counts protected items (azure-mgmt-recoveryservicesbackup). Flags no-vaults-in-rg, vault-empty (vault present but no protected items), and vault-list-denied (RBAC missing). Wraps the three SDKs with a never-raising probe() returning structured findings. Partial-denial (one vault class works, other doesn't) returns confidence in (0,1). Writes manifest JSON to out/<finding-id>.json and returns equivalent dict. CLI: python -m azure_backup_readiness --sub <sub-id> --rg <rg>. USE FOR: backup readiness audit, RSV audit, Backup Vault audit, vault-empty detection, no-vaults-in-RG, Foundry RG backup posture, spoke backup posture, BAK-401 self-verify. DO NOT USE FOR: creating vaults, running on-demand backups, restoring, or backup policy authoring; use Azure Backup CLI/Portal workflows instead.

2026-07-03
foundry-voice-live
软件开发工程师

Build real-time voice agents on Azure AI Foundry Voice Live (GA 2026-04-10). Four-rung migration ladder: Azure OpenAI Realtime → Voice Live → Voice Live + Foundry Agent → native azure-ai-voicelive SDK. Covers semantic VAD, AEC, Neural HD voices, agent routing triplet, TTFA/TTFT benchmark, Gradio + FastRTC UI, plus 2026-04-10 GA deltas: proactive turn control, MCP tools mid-turn, OpenTelemetry via diagnostic settings, auto-truncate. USE FOR: voice live, realtime voice, voice agent, speech to speech, semantic VAD, Neural HD voices, FastRTC, Gradio voice, TTFA, gpt-realtime, byo wss, voice avatar, azure-ai-voicelive, voice live sdk, voice live mcp, mcp mid-turn, voice live proactive turn, voice live auto-truncate, voice live otel. DO NOT USE FOR: batch STT/TTS (use foundry-doc-vision-speech), non-voice agents (use foundry-hosted-agents / foundry-prompt-agents), App Insights ingestion (use foundry-observability), authoring an MCP server (use foundry-mcp-aca or ui-widget-developer).

2026-07-03
foundry-agt
其他计算机职业

Wrap the Microsoft Agent Governance Toolkit (AGT) around Foundry hosted agents, MCP servers, and Citadel spokes. Adds deterministic policy enforcement, capability allow/deny, hash-chained audit, and OWASP ASI 2026 coverage via in-process MAF middleware (8-12 µs/eval verified on Windows + Py 3.13 + AGT 3.7.0) or ACA sidecar. Ships 3 starter policies (default / HITL gate / PII deny), working create_governance_middleware snippet, ACA sidecar Bicep, and field-tested Known Issues (rogue detection setup). USE FOR: agent governance, AGT, agent-governance-toolkit, policy enforcement, capability guard, audit trail, OWASP ASI 2026, MAF middleware, MCP scanner, PromptDefense, Citadel adapter, agt verify, agt doctor, agt red-team, acs policy, guardrail decision, agt vs guardrailtool. DO NOT USE FOR: Foundry agent deployment (use foundry-hosted-agents), Citadel hub setup (use citadel-spoke-onboarding), App Insights wiring (use foundry-observability), eval scoring (use foundry-evals).

2026-07-03
foundry-vnet-deploy
软件开发工程师

Deploy Azure AI Foundry with **Agent Setup inside a private VNet** — the `15-private-network-standard-agent-setup` Bicep reference architecture. Supports new/existing VNets, resource reuse (CosmosDB / Storage / AI Search / private DNS zones), hosted-agent RBAC, App Insights, and spoke-side peering + APIM-DNS-zone link to a Citadel hub VNet. Read the full skill body for the guided interview, retry logic, and subnet sizing — do not deploy from this summary. USE FOR: foundry private vnet, network-secured foundry, agent injection, capability host, citadel hub peering, vnet-isolated citadel spoke, apim private dns zone link, central dns at scale, hub-spoke private dns, InvalidPrivateDnsZoneIds. DO NOT USE FOR: azd-based deploys (use threadlight-deploy or foundry-hosted-agents), public-network Foundry, APIM cross-resource (use foundry-cross-resource), tenant isolation (use azure-tenant-isolation), Citadel app-layer onboarding (use citadel-spoke-onboarding for APIM products + Foundry connection).

2026-07-02
gbb-humanizer
技术写作员

Remove signs of AI-generated writing from prose. Targets 29 patterns from Wikipedia's "Signs of AI writing" (em-dash overuse, rule-of-three, significance inflation, AI vocabulary, copula avoidance, false ranges, sycophantic openers, signposting, filler). Ships Microsoft GBB voice samples (seller pitch + technical blog) and density-preserving guardrails so domain lists and code blocks survive. Read the full skill body for the multi-pass procedure and pattern catalog. USE FOR: humanize prose, remove AI-isms, polish overview.html, polish demo script, polish speaker notes, AI tells, ChatGPT cadence, em dash overuse, rule of three, voice calibration, GBB seller voice, Cowork prose polish, threadlight overview polish, gbb-pptx speaker notes polish, sound less AI. DO NOT USE FOR: code, agent system prompts (directive style intentional), SKILL.md frontmatter, tables / KPI cards / code blocks, SME verbatim quotes, structured data.

2026-07-02
foundry-cost-monitoring
软件开发工程师

Continuous Foundry token-cost monitoring, chargeback, budget alerts, and FinOps automation. Joins gen_ai.usage spans emitted by foundry-observability with the Azure Retail Prices API to compute per-agent / per-project / per-tenant cost projection. Wires Cost Management budgets + Action Groups, and uses Foundry's project-tag attribution (preview) for chargeback. USE FOR: foundry cost monitoring, token cost dashboard, FinOps Foundry, project-level chargeback, project tag cost attribution, Azure retail prices API, gen_ai.usage cost KQL, budget alert Foundry, Action Group cost webhook, token cost anomaly detection, OTel vs Cost Management reconciliation, per-agent / per-tenant token spend. DO NOT USE FOR: one-shot PTU vs PAYGO sizing (use paygo-ptu-cost-analyzer); emitting cost telemetry from agent code (use foundry-observability); gateway-only chargeback via x-app-id (use citadel-spoke-onboarding); fine-tuning cost estimates.

2026-06-29
foundry-network-runbook
网络与计算机系统管理员

Operational runbook for diagnosing Microsoft Foundry **network-layer** failures after a deploy succeeds — DNS, VNet peering, NSG / Azure Firewall denies, RBAC scope, capability host subnet exhaustion, agent NIC / MI provisioning, project-connection status. USE FOR: foundry network 503, InvalidPrivateDnsZoneIds at deploy, Subnet already in use by capability host, agent inference 503, inference timeout no response, private endpoint not resolving, Resolve-DnsName returns public IP from spoke, NSG deny Foundry agent subnet, AzureFirewall deny Foundry, 403 Managed Identity Operator, hosted agent NIC provisioning 403, VNet peering Disconnected, project connection red in portal, APIM private DNS not linked, SAL stale. DO NOT USE FOR: telemetry (use foundry-observability); Day-0 deploy (use foundry-vnet-deploy); Day-2 caphost lifecycle / purge (use foundry-caphost-lifecycle); APIM / cross-region (use foundry-cross-resource); Citadel JWT 403 (use citadel-spoke-onboarding); SDK; quota; cost.

2026-06-26
ghcp-cli-config
软件开发工程师

Bootstrap GitHub Copilot CLI for GBB workflows: 6 recommended MCP servers (mslearn, Azure, Playwright, context7, tavily, mem0), settings.json baseline (model, sessionSync, allowedUrls, trustedFolders), work-iq plugin family for Microsoft staff, autoApprove guardrails, and a fresh-machine bootstrap procedure the agent can execute. USE FOR: copilot cli setup, fresh machine setup, configure ghcp cli, add ms learn mcp, add azure mcp, add playwright mcp, mcp-config.json, settings.json, sessionSync, allowedUrls, trustedFolders, autoApprove, permissions-config.json, copilot cli plugins, install workiq, extraKnownMarketplaces, ghcp first time, copilot cli onboarding, recommended copilot cli config, gbb engineer setup. DO NOT USE FOR: authoring new skills (use skill-creator), Azure tenant isolation (use azure-tenant-isolation), keyboard shortcuts and slash commands (runtime, not config), Cursor or Claude Code config (different runtimes).

2026-06-26
foundry-evals
软件质量保证分析师与测试员

Evaluate Foundry hosted agents using the two-phase invoke+score pattern and Foundry built-in evaluators. Covers sequential invocation, cold-start handling, dataset creation, evaluator configuration, RBAC for eval judges, result interpretation, and cross-refs to community evaluator frameworks (foundry-assert) and eval-driven prompt optimization loops (foundry-agent-optimizer). USE FOR: evaluate agent post-deploy, score grounding quality, measure tool_selection, detect dataset drift, write custom grader, check URL citations, validate eval RBAC, day-1 smoke test, continuous eval loop, pre-merge eval gate, Foundry Evals SDK setup, evaluator framework, eval-driven optimization, ASSERT evaluators. DO NOT USE FOR: deploying agents (use threadlight-deploy), designing processes (use threadlight-design), unit testing code, reimplementing evaluator framework (use foundry-assert), writing your own optimizer loop (use foundry-agent-optimizer).

2026-06-18
azure-sre-agent
网络与计算机系统管理员

Adopt Azure SRE Agent (Microsoft.App/agents) in GBB engagements without rebuilding what Microsoft already ships. Thin wrapper around the official microsoft/sre-agent toolchain and Azure/sre-agent-plugins marketplace. Adds 3 GBB recipes (Citadel-routed model traffic, Foundry hosted-agent ops, Threadlight pilot handover), 2 GBB plugins (Citadel APIM, Foundry hosted-agent), pre-flight runbook, and a data-plane helper so other awesome-gbb skills post into a customer's SRE Agent via HTTP triggers. USE FOR: azure sre agent, sre.azure.com, sreagent-templates, sre agent recipe, sre agent plugin, subagent, agentmemory upload, http trigger, Microsoft.App agents Bicep, azuresre.ai, azuresre.dev, citadel-routed sre agent, threadlight handover, sre agent preflight, DeploymentNotFound. DO NOT USE FOR: in-process agent policy (foundry-agt), OTel emit (foundry-observability), APIM gateway provisioning (citadel-hub-deploy), hosted-agent build (foundry-hosted-agents), MCP on ACA (foundry-mcp-aca).

2026-06-18
azure-monitor-alert-baseline
软件开发工程师

Probes Azure Monitor metric alert rules in a resource-group scope against one of three published baselines (foundry_pilot, spoke_minimum, production), returning a spec §4.3.1 sibling-skill dict with finding_id "SRE-104", observations, remediation hints, confidence, and never raises. USE FOR: threadlight SRE-104 sibling-skill flip, alert baseline audit before pilot handover, alert rule drift detection in a Foundry RG, observability readiness probe, post-deploy alert configuration check, threshold tightness validation against published baselines, baselined alert rule audit, monitoring baseline check. DO NOT USE FOR: creating or updating alert rules — use az monitor metrics alert create instead; DO NOT USE FOR: App Insights traces or logs — use foundry-observability; DO NOT USE FOR: Azure Service Health alerts — different API surface; DO NOT USE FOR: log alerts (Log Analytics scheduled query rules) — metric alerts only.

2026-06-12
foundry-rbac-audit
信息安全分析师

Probes Azure RBAC role assignments at a resource-group scope for privilege-escalation risks (Owner, User Access Administrator, RBAC Administrator). Returns a spec §4.3.1 sibling-skill dict with finding_id "IAM-101", observations, remediation hints, confidence, and never raises. USE FOR: threadlight IAM-101 sibling-skill flip, rbac audit on a Foundry-adjacent resource group, least privilege review before spoke onboarding, over-privileged detection after team offboarding, role assignment audit for spoke security probe, scheduled CI security check on a Foundry project RG. DO NOT USE FOR: granting or revoking roles — use az role assignment create/delete instead; DO NOT USE FOR: Foundry-internal agent identity or per-agent-instance MI RBAC — use foundry-agt; DO NOT USE FOR: hub-side Citadel security checks — use citadel-spoke-onboarding probe_hub_contract.

2026-06-12
azure-tenant-isolation
软件开发工程师

Multi-tenant Azure CLI and AZD isolation for concurrent terminal sessions. Index-file driven, bare `az` CLI commands only — no wrapper scripts, no PowerShell modules. Mandatory two-layer guard: per-tenant `AZURE_CONFIG_DIR` is the foundation, and `az account show` assertion is the extra gate that verifies tenant + subscription before destructive operations. USE FOR: az login, azd up, azd deploy, az account set, Azure subscription, Azure tenant, AZURE_CONFIG_DIR, AZD_CONFIG_DIR, multi-tenant, switch tenant, deploy to Azure, Bicep deploy, az deployment, azd auth, ChainedTokenCredential, Azure identity, verify subscription, confirm tenant, tenant index, prevent cross-tenant deployment. DO NOT USE FOR: provisioning Azure resources (use azd-patterns), deploying Foundry agents (use foundry-hosted-agents), deploying Citadel gateway (use citadel-hub-deploy).

2026-05-30
auto-demo-producer
软件开发工程师

Produce narrated video demos of web applications automatically. Uses Playwright for browser recording, edge-tts for narration, and ffmpeg for assembly. USE FOR: create demo video, record demo, auto demo, video demo, narrated walkthrough, product demo, screen recording with voiceover, demo producer, make a demo video, record a walkthrough, create a screencast with narration, auto-generate demo. DO NOT USE FOR: editing existing videos, live streaming, webcam recording.

2026-05-27
gbb-pptx
软件开发工程师

Generate professional PowerPoint (PPTX) presentations using python-pptx (the AI Apps GBB dark/light pitch-deck generator). USE FOR: create PowerPoint, generate PPTX, make slide deck, build presentation, convert markdown to slides, pitch deck, report as PPTX, create slides, gbb-pptx, gbb deck, dark-themed deck. DO NOT USE FOR: editing existing PPTX files (use the upstream `pptx` skill), PDF generation, Google Slides.

2026-05-27
ip-catalog
软件开发工程师

Discover AI Apps GBB IP catalog via MCP server. Search, list, filter, and inspect IPs (intellectual property assets) including metadata, thumbnails, and READMEs. USE FOR: find IP, search demos, list IPs, catalog, what demos are available, find solutions by service/pattern, get IP details, browse catalog, discover assets. DO NOT USE FOR: creating IPs, deploying apps, managing repos.

2026-05-27
citadel-hub-deploy
软件开发工程师

Deploy the **AI Citadel Governance Hub** (Layer 1) — APIM AI Gateway, Microsoft Foundry control plane, telemetry, 4 LLM APIs (Azure OpenAI, OpenAI Realtime, Universal LLM, Unified AI), private endpoints, access contracts. Wraps `Azure-Samples/ai-hub-gateway-solution-accelerator` branch `citadel-v1` (azd template) at a pinned commit. Ships 3 profiles (pilot-quickstart, enterprise-baseline, vnet-isolated-spoke-aware) plus tenant-isolated workflow. USE FOR: deploy citadel hub, citadel governance hub, apim ai gateway, ai-hub-gateway-solution-accelerator, citadel-v1, llm backend pool, unified ai api, universal llm api, openai realtime api, citadel access contract, multi-region foundry hub, BYO vnet hub, BYO log analytics, foundry network injection, managed redis semantic cache. DO NOT USE FOR: connecting a spoke to a hub (use citadel-spoke- onboarding), in-process governance (use foundry-agt), single-resource Foundry (use foundry-vnet-deploy or microsoft-foundry), tenant isolation (use azure-tenant-isolation).

2026-05-26
apim-throttle-expert
软件开发工程师

Diagnose 429 responses from the AI Citadel APIM gateway — identify which rate-limit policy tripped (per-product quota, per-named-value rate-limit-by-key, or backend pool TPM exhaustion).

2026-05-20
jwt-403-debug-expert
软件开发工程师

Diagnose 401/403 responses at the AI Citadel APIM gateway — decode JWT claims, verify Access Contract scope grants, and validate Foundry managed-identity token audience.

2026-05-20
byok-401-debug-expert
软件开发工程师

Diagnose the silent BYOK 401 that Foundry hosted agents emit when "Foundry User" RBAC is assigned at PROJECT scope but missing at the underlying CognitiveServices ACCOUNT scope. Encodes the exact fix command.

2026-05-20
hosted-agent-deploy-expert
软件开发工程师

Investigate failed Microsoft Foundry hosted-agent deployments — MAF SDK breaking changes, ACR push, ACA rollout, BYOK provisioning, and the azd ai agent extension's known envelope and RBAC quirks.

2026-05-20
quota-throttle-expert
软件开发工程师

Diagnose AOAI deployment TPM exhaustion behind Foundry hosted agents — pull capacity vs utilization, identify burst patterns, recommend scale-up or PTU migration.

2026-05-20