{"slug":"skill-creator","title":"skill-creator","summary":"Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services. Use when creating new skills or updating existing skills.","platform":"GitHub Copilot","tags":[],"authorName":"Ciza","authorSlug":"ciza","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-08-12T21:05:26.531573Z","repo":{"url":"https://github.com/microsoft/skills","stars":3052,"forks":351,"license":"MIT","updatedAt":"2026-09-24T16:38:17Z"},"bodyHtml":"<hr>\n<h2>name: skill-creator\ndescription: Guide for creating effective skills for AI coding agents working with Azure SDKs and Microsoft Foundry services. Use when creating new skills or updating existing skills.</h2>\n<h1>Skill Creator</h1>\n<p>Guide for creating skills that extend AI agent capabilities, with emphasis on Azure SDKs and Microsoft Foundry.</p>\n<blockquote>\n<p><strong>Required Context:</strong> When creating SDK or API skills, users MUST provide the SDK package name, documentation URL, or repository reference for the skill to be based on.</p>\n</blockquote>\n<h2>About Skills</h2>\n<p>Skills are modular knowledge packages that transform general-purpose agents into specialized experts:</p>\n<ol>\n<li><strong>Procedural knowledge</strong> — Multi-step workflows for specific domains</li>\n<li><strong>SDK expertise</strong> — API patterns, authentication, error handling for Azure services</li>\n<li><strong>Domain context</strong> — Schemas, business logic, company-specific patterns</li>\n<li><strong>Bundled resources</strong> — Scripts, references, templates for complex tasks</li>\n</ol>\n<hr>\n<h2>Core Principles</h2>\n<h3>1. Concise is Key</h3>\n<p>The context window is a shared resource. Challenge each piece: \"Does this justify its token cost?\"</p>\n<p><strong>For domain/procedural skills</strong>: Agents are already capable. Only add what they don't already know.</p>\n<p><strong>For SDK/API skills</strong>: Users MUST provide SDK package name, documentation URL, or repository reference. The skill cannot be created without this context.</p>\n<h3>2. Fresh Documentation First</h3>\n<p><strong>Azure SDKs change constantly.</strong> Skills should instruct agents to verify documentation:</p>\n<pre><code>## Before Implementation\n\nSearch `microsoft-docs` MCP for current API patterns:\n\n- Query: \"[SDK name] [operation] python\"\n- Verify: Parameters match your installed SDK version\n</code></pre>\n<h3>3. Degrees of Freedom</h3>\n<p>Match specificity to implementation constraints. High freedom when approaches vary; low freedom when precise execution is required:</p>\n<table>\n<thead>\n<tr>\n<th>Freedom</th>\n<th>When</th>\n<th>Example</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><strong>High</strong></td>\n<td>Multiple valid approaches</td>\n<td>Text guidelines</td>\n</tr>\n<tr>\n<td><strong>Medium</strong></td>\n<td>Preferred pattern with variation</td>\n<td>Pseudocode</td>\n</tr>\n<tr>\n<td><strong>Low</strong></td>\n<td>Must be exact</td>\n<td>Specific scripts</td>\n</tr>\n</tbody>\n</table>\n<h3>4. Progressive Disclosure</h3>\n<p>Skills load in three levels:</p>\n<ol>\n<li><strong>Metadata</strong> (~100 words) — Always in context</li>\n<li><strong>SKILL.md body</strong> (&lt;5k words) — When skill triggers</li>\n<li><strong>References</strong> (unlimited) — As needed</li>\n</ol>\n<p><strong>Keep SKILL.md under 500 lines.</strong> Split into reference files when approaching this limit.</p>\n<hr>\n<h2>Skill Structure</h2>\n<p><strong>Quick reference:</strong></p>\n<pre><code>skill-name/\n├── SKILL.md (required)\n│   ├── YAML frontmatter (name, description)\n│   └── Markdown instructions\n└── Bundled Resources (optional)\n    ├── scripts/      — Executable code\n    ├── references/   — Documentation loaded as needed\n    └── assets/       — Output resources (templates, images)\n</code></pre>\n<p>For Azure SDK skills, follow the <strong>Skill Section Order</strong> below. For domain skills, use your judgment to organize logically.</p>\n<h3>SKILL.md Essentials</h3>\n<ul>\n<li><strong>Frontmatter</strong>: <code>name</code> and <code>description</code> (description triggers the skill)</li>\n<li><strong>Body</strong>: Keep under 500 lines; split large skills into reference files</li>\n</ul>\n<h3>Bundled Resources (Optional)</h3>\n<table>\n<thead>\n<tr>\n<th>Type</th>\n<th>When to Include</th>\n<th>Examples</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>scripts/</code></td>\n<td>Reused code patterns</td>\n<td>Auth setup, CLI scripts</td>\n</tr>\n<tr>\n<td><code>references/</code></td>\n<td>Feature deep-dives and overflow examples</td>\n<td><code>capabilities.md</code> index, <code>non-hero-scenarios.md</code>, API docs</td>\n</tr>\n<tr>\n<td><code>assets/</code></td>\n<td>Output templates</td>\n<td>Boilerplate code, images</td>\n</tr>\n</tbody>\n</table>\n<hr>\n<h2>Creating Azure SDK Skills</h2>\n<p>When creating skills for Azure SDKs, follow these patterns consistently.</p>\n<h3>Token Budget Guidelines (REQUIRED)</h3>\n<p>Every Azure SDK skill MUST stay within these token limits:</p>\n<table>\n<thead>\n<tr>\n<th>Section</th>\n<th>Target</th>\n<th>Absolute Max</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Installation + Env Vars</td>\n<td>100 tokens</td>\n<td>150</td>\n</tr>\n<tr>\n<td>Authentication &amp; Lifecycle</td>\n<td>200 tokens</td>\n<td>300</td>\n</tr>\n<tr>\n<td>Core Workflow (1 example)</td>\n<td>300 tokens</td>\n<td>400</td>\n</tr>\n<tr>\n<td>Feature Tables</td>\n<td>200 tokens</td>\n<td>300</td>\n</tr>\n<tr>\n<td>Best Practices (6-8 items)</td>\n<td>200 tokens</td>\n<td>250</td>\n</tr>\n<tr>\n<td>References (reference/ links)</td>\n<td>100 tokens</td>\n<td>150</td>\n</tr>\n<tr>\n<td><strong>Total SKILL.md</strong></td>\n<td><strong>~1100 tokens</strong></td>\n<td><strong>~1500 tokens</strong></td>\n</tr>\n</tbody>\n</table>\n<p><strong>Enforcement</strong>:</p>\n<ul>\n<li>Exceeding max limit → refactor into <code>/references/</code> subdirectories</li>\n<li>When approaching 500 lines → move entire sections to reference files</li>\n<li>Annotate with <code>&lt;!-- Token Count: ~XXXX (target: 1100, max: 1500) --&gt;</code> immediately below the skill's H1</li>\n</ul>\n<hr>\n<h3>Reference Extraction Guide (REQUIRED)</h3>\n<p>Decide what goes in SKILL.md vs. <code>/references/</code> using these signals:</p>\n<table>\n<thead>\n<tr>\n<th>Signal</th>\n<th>Move to <code>/references/</code></th>\n<th>Keep in SKILL.md</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Use frequency</td>\n<td>&lt;20% of typical use</td>\n<td>~80%+ of workflows</td>\n</tr>\n<tr>\n<td>Cognitive load</td>\n<td>Advanced patterns, multiple options</td>\n<td>Single happy path</td>\n</tr>\n<tr>\n<td>Example length</td>\n<td>&gt;10 lines, multiple paths</td>\n<td>1-5 lines, single path</td>\n</tr>\n</tbody>\n</table>\n<p><strong>Content extraction rules:</strong></p>\n<ul>\n<li><strong>Batch operations</strong> → <code>/references/batch-operations.md</code></li>\n<li><strong>Error handling</strong> (beyond try-except) → <code>/references/error-handling.md</code></li>\n<li><strong>Performance tuning</strong> → <code>/references/performance.md</code></li>\n<li><strong>Alternative workflows</strong> → <code>/references/workflows-comparison.md</code></li>\n<li><strong>Streaming/events</strong> → <code>/references/streaming.md</code></li>\n<li><strong>Advanced auth</strong> → <code>/references/auth-strategies.md</code></li>\n<li><strong>Tool integration</strong> → <code>/references/tools.md</code></li>\n<li><strong>Breaking changes</strong> → <code>/references/migration.md</code></li>\n</ul>\n<p><strong>Decision:</strong> Keep common case in SKILL.md, move edge cases to <code>/references/</code>.</p>\n<hr>\n<h3>Core Workflow Discipline (REQUIRED)</h3>\n<p>Every Azure SDK skill must clarify which workflow(s) it documents.</p>\n<p><strong>Case 1: Single clear \"core workflow\"</strong> (majority of services)</p>\n<p>If one pattern handles ~80% of use cases:</p>\n<ol>\n<li>Designate it as the core workflow</li>\n<li>Show ONLY this workflow in SKILL.md (one complete, runnable example)</li>\n<li>Defer alternatives to <code>/references/</code>:\n<ul>\n<li>Batch operations → <code>/references/batch-operations.md</code></li>\n<li>Error handling → <code>/references/error-handling.md</code></li>\n<li>Performance tuning → <code>/references/performance.md</code></li>\n<li>Alternative workflows → <code>/references/workflows-comparison.md</code></li>\n</ul>\n</li>\n</ol>\n<p><strong>Example</strong>: Azure Key Vault Secrets (core workflow: retrieve a secret using managed identity). Alternative authentication workflows in <code>/references/</code>: local development with <code>DefaultAzureCredential</code>, workload identity, and service-principal credentials (client secret or certificate).</p>\n<p><strong>Case 2: Multiple equally-valid \"core workflows\"</strong> (e.g., authentication strategies, deployment targets)</p>\n<p>If no single pattern dominates:</p>\n<ol>\n<li>Include every hero scenario in SKILL.md, even when that means multiple equally valid workflows</li>\n<li>Show one complete, runnable example for each hero scenario in SKILL.md</li>\n<li>Use <code>/references/workflows-comparison.md</code> for trade-offs, secondary variations, and deeper context that would otherwise bloat the main file</li>\n<li>Do NOT treat valid alternatives as \"advanced\" when they are core to real usage — they're equally valid, just different contexts</li>\n</ol>\n<p><strong>Example</strong>: Azure Identity SDK has several hero scenarios. Keep the primary local-development and production-safe credential flows in SKILL.md, then use <code>/references/credential-types.md</code> for deeper comparisons across <code>AzureCliCredential</code>, workload identity, service principal variants, and other secondary credential choices.</p>\n<p><strong>Decision rule</strong>: If you're unsure, ask: \"Would a user choosing the other approach call what I wrote wrong?\" If yes, it's another hero scenario and belongs in SKILL.md. If no, it can be summarized and linked from <code>/references/</code>.</p>\n<hr>\n<h3>Skill Section Order</h3>\n<p>Follow this structure (based on existing Azure SDK skills):</p>\n<ol>\n<li><strong>Title</strong> — <code># SDK Name</code></li>\n<li><strong>Installation</strong> — <code>pip install</code>, <code>npm install</code>, etc.</li>\n<li><strong>Environment Variables</strong> — Required configuration, with an inline comment explaining when it's required. If using <code>DefaultAzureCredential</code> in production, include <code>AZURE_TOKEN_CREDENTIALS</code> (set to <code>prod</code> or <code>&lt;specific_credential&gt;</code>)</li>\n<li><strong>Authentication &amp; Lifecycle</strong> — For Python skills, prefer <code>DefaultAzureCredential</code>: use it as-is for local development, and constrain it for production by setting <code>AZURE_TOKEN_CREDENTIALS</code> to <code>prod</code> (or a specific target credential name). A specific Microsoft Entra Token credential such as <code>ManagedIdentityCredential</code> or <code>WorkloadIdentityCredential</code> may be used directly instead. <strong>For Python skills, this section MUST start with the standard callout block</strong> (see <a href=\"#required-authentication--lifecycle-callout-python\">Required Authentication &amp; Lifecycle Callout (Python)</a> below).</li>\n<li><strong>Core Workflow</strong> — Minimal viable example (per core workflow discipline above)</li>\n<li><strong>Feature Tables</strong> — Clients, methods, tools</li>\n<li><strong>Best Practices</strong> — Numbered list</li>\n<li><strong>Reference Links</strong> — Table linking to <code>/references/*.md</code> (for Azure SDK skills, include <code>capabilities.md</code> + <code>non-hero-scenarios.md</code>)</li>\n</ol>\n<h3>Required Authentication &amp; Lifecycle Callout (Python)</h3>\n<blockquote>\n<p><strong>Scope:</strong> Python skills (<code>-py</code> suffix) only. Other languages may follow their own idioms.</p>\n</blockquote>\n<p>Every Python Azure SDK skill MUST open its <code>## Authentication &amp; Lifecycle</code> section with the following callout block, <strong>verbatim</strong>, before any code samples. This makes the two non-negotiable rules visible to users before they read or copy any client setup code.</p>\n<pre><code>## Authentication &amp; Lifecycle\n\n&gt; **\uD83D\uDD11 Two rules apply to every code sample below:**\n&gt;\n&gt; 1. **Prefer `DefaultAzureCredential` for local development.** It works as-is with Azure CLI / VS Code / Developer CLI. For production, either constrain `DefaultAzureCredential` to production-safe credentials or use a specific credential directly. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.\n&gt;    - Local dev: `DefaultAzureCredential` works as-is.\n&gt;    - Production: set `AZURE_TOKEN_CREDENTIALS=prod` (or `AZURE_TOKEN_CREDENTIALS=&lt;specific_credential&gt;`) to constrain the credential chain to production-safe credentials.\n&gt; 2. **Wrap every client in a context manager** so HTTP transports, sockets, and token caches are released deterministically:\n&gt;    - Sync: `with &lt;Client&gt;(...) as client:`\n&gt;    - Async: `async with &lt;Client&gt;(...) as client:` **and** `async with DefaultAzureCredential() as credential:` (from `azure.identity.aio`)\n&gt;\n&gt; Snippets may abbreviate this setup, but production code should always follow both rules.\n</code></pre>\n<p><strong>Placement rules:</strong></p>\n<ul>\n<li>Insert immediately under the <code>## Authentication &amp; Lifecycle</code> heading, before the first code sample.</li>\n<li>Do not paraphrase or restructure the wording — the consistency across skills is the point.</li>\n<li>If the SDK does not support Entra ID at all (rare — e.g. some legacy speech REST endpoints, websocket APIs that require subscription keys), keep rule #2 (context managers) and replace rule #1 with a single sentence noting the SDK requires API-key auth and explaining why Entra is not yet available.</li>\n<li>If the SDK is async-only (e.g. <code>azure-ai-voicelive</code>), keep both rules but show only the async form in the bullets.</li>\n<li>Skip the callout entirely for non-Azure Python skills with no client lifecycle (e.g. <code>pydantic-models-py</code>).</li>\n</ul>\n<p><strong>Code sample enforcement.</strong> Every client construction in the skill body must demonstrate both rules:</p>\n<ul>\n<li>Show <code>with</code> / <code>async with</code> on every client instantiation in usage examples (not just the auth section).</li>\n<li>Show <code>DefaultAzureCredential</code> in the primary auth example. <strong>Do not delete API-key examples for SDKs where keys are still officially supported</strong> — many existing users (especially in regulated environments still completing their Entra rollout) need a copy-pastable working sample. Demote the keyed snippet into a clearly-labeled <code>### Legacy: API Key (existing keyed deployments)</code> subsection placed <em>after</em> the primary <code>DefaultAzureCredential</code> block in the same <code>## Authentication &amp; Lifecycle</code> section. Include a one-line note that new code should use <code>DefaultAzureCredential</code> and that the keyed path is for existing deployments. Also add the <code>&lt;SERVICE&gt;_KEY</code> env var back to the Environment Variables block with a <code># Only required for the legacy API-key auth path below</code> comment.</li>\n<li>A handful of services have key-specific quirks worth calling out in the Legacy subsection (e.g. <code>azure-ai-translation-text</code> requires a <code>region=</code> parameter when using a key against the global endpoint, because token-credential auth requires a custom subdomain endpoint). Surface these in the demoted block rather than dropping the example.</li>\n<li>For async examples, wrap <code>DefaultAzureCredential</code> from <code>azure.identity.aio</code> in <code>async with credential:</code> alongside the client.</li>\n</ul>\n<h3>Authentication Pattern (All Languages)</h3>\n<p>For local development, use <code>DefaultAzureCredential</code> which supports multiple auth methods. For production, use a specific credential type or configure <code>DefaultAzureCredential</code> with environment variable <code>AZURE_TOKEN_CREDENTIALS</code> set to <code>prod</code> or specify the target credential.</p>\n<p>If configuring a Rust skill, use <code>DeveloperToolsCredential</code> for local development and <code>ManagedIdentityCredential</code> for production. The Rust SDK does not support <code>DefaultAzureCredential</code>, so explicitly use the appropriate credential in each environment.</p>\n<pre><code># Python — note: client is wrapped in `with` for deterministic cleanup\nfrom azure.identity import DefaultAzureCredential, ManagedIdentityCredential\n# Local dev: DefaultAzureCredential works as-is.\ncredential = DefaultAzureCredential()\n# Production alternative: constrain DefaultAzureCredential with AZURE_TOKEN_CREDENTIALS.\n# credential = DefaultAzureCredential(require_envvar=True)\n# Or use a specific credential directly in production:\n# See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes\n# credential = ManagedIdentityCredential()\nwith ServiceClient(endpoint, credential) as client:\n    client.do_thing()\n</code></pre>\n<pre><code>// C#\nusing Azure.Identity;\n\n// Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=&lt;specific_credential&gt;\nvar credential = new DefaultAzureCredential(\n    DefaultAzureCredential.DefaultEnvironmentVariableName\n);\n// Or use a specific credential directly in production:\n// See https://learn.microsoft.com/dotnet/api/overview/azure/identity-readme?view=azure-dotnet#credential-classes\n// var credential = new ManagedIdentityCredential();\nvar client = new ServiceClient(new Uri(endpoint), credential);\n</code></pre>\n<pre><code>// Java\nimport com.azure.identity.AzureIdentityEnvVars;\nimport com.azure.identity.DefaultAzureCredentialBuilder;\nimport com.azure.identity.ManagedIdentityCredential;\nimport com.azure.identity.ManagedIdentityCredentialBuilder;\n\n// Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=&lt;specific_credential&gt;\nTokenCredential credential = new DefaultAzureCredentialBuilder()\n    .requireEnvVars(AzureIdentityEnvVars.AZURE_TOKEN_CREDENTIALS)\n    .build();\n// Or use a specific credential directly in production:\n// See https://learn.microsoft.com/java/api/overview/azure/identity-readme?view=azure-java-stable#credential-classes\n// TokenCredential credential = new ManagedIdentityCredentialBuilder().build();\nServiceClient client = new ServiceClientBuilder()\n    .endpoint(endpoint)\n    .credential(credential)\n    .buildClient();\n</code></pre>\n<pre><code>// TypeScript\nimport {\n  DefaultAzureCredential,\n  ManagedIdentityCredential,\n} from \"@azure/identity\";\n// Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=&lt;specific_credential&gt;\nconst credential = new DefaultAzureCredential({\n  requiredEnvVars: [\"AZURE_TOKEN_CREDENTIALS\"],\n});\n// Or use a specific credential directly in production:\n// See https://learn.microsoft.com/javascript/api/overview/azure/identity-readme?view=azure-node-latest#credential-classes\n// const credential = new ManagedIdentityCredential();\nconst client = new ServiceClient(endpoint, credential);\n</code></pre>\n<pre><code>// Go\nimport (\n  \"context\"\n\n  \"github.com/Azure/azure-sdk-for-go/sdk/azidentity\"\n  \"github.com/Azure/azure-sdk-for-go/sdk/storage/azblob\"\n)\n\nctx := context.Background()\n\n// Local dev: DefaultAzureCredential. Production: set AZURE_TOKEN_CREDENTIALS=prod or AZURE_TOKEN_CREDENTIALS=&lt;specific_credential&gt;\ncred, err := azidentity.NewDefaultAzureCredential(nil)\nif err != nil {\n  panic(err)\n}\n\n// Or use a specific credential directly in production:\n// cred, err := azidentity.NewManagedIdentityCredential(nil)\n\nclient, err := azblob.NewClient(\"https://&lt;account&gt;.blob.core.windows.net/\", cred, nil)\nif err != nil {\n  panic(err)\n}\n\n_ = client\n_ = ctx\n</code></pre>\n<pre><code>// Rust\nuse azure_identity::DeveloperToolsCredential;\nuse azure_storage_blob::BlobServiceClient;\n\nlet credential = DeveloperToolsCredential::new(); // Local dev\nlet client = BlobServiceClient::new(\n    \"https://&lt;account&gt;.blob.core.windows.net/\",\n    credential,\n    None,\n)?;\n</code></pre>\n<p><strong>Never hardcode credentials. Use environment variables.</strong></p>\n<h3>Anti-Patterns: What NOT to Do (REQUIRED Reading)</h3>\n<p><strong>These patterns cause bloat and inefficiency. Every skill author must review this section before writing.</strong></p>\n<h4>Anti-Pattern 1: \"Exhaustive API Reference\"</h4>\n<ul>\n<li>❌ <strong>Don't</strong>: List all 50 SDK methods in a feature table with code samples for every variant</li>\n<li>✅ <strong>Do</strong>: Show 3-5 core methods in a table; link to official Azure API reference for exhaustive list</li>\n<li><strong>Token cost</strong>: Listing all methods + examples = 400-600 tokens wasted</li>\n<li><strong>User impact</strong>: Overwhelming cognitive load; users don't know what to use</li>\n</ul>\n<h4>Anti-Pattern 2: \"Multiple Ways to Solve One Problem\"</h4>\n<ul>\n<li>❌ <strong>Don't</strong>: \"Here's approach A, B, C, and D to paginate results\" in the main body</li>\n<li>✅ <strong>Do</strong>: \"Use <code>ItemPaged</code> for sync pagination\" (primary example); link alternatives to <code>/references/</code></li>\n<li><strong>Token cost</strong>: Each alternate approach = 50-100 tokens; 5 approaches = skill becomes inefficient</li>\n<li><strong>User impact</strong>: Decision paralysis; users re-read everything</li>\n</ul>\n<h4>Anti-Pattern 3: \"Beginner + Intermediate + Advanced in One Skill\"</h4>\n<ul>\n<li>❌ <strong>Don't</strong>: Skill that goes from \"what is a client?\" to \"custom retry policies\" to \"circuit breaker patterns\"</li>\n<li>✅ <strong>Do</strong>: Core workflow covers 80% use case; advanced patterns in <code>/references/</code></li>\n<li><strong>Token cost</strong>: Every skill level adds 200-300 tokens; three levels = 600-900 extra tokens</li>\n<li><strong>User impact</strong>: Experts bored, beginners overwhelmed; nobody gets what they need</li>\n</ul>\n<h4>Anti-Pattern 4: \"Restating Official Documentation\"</h4>\n<ul>\n<li>❌ <strong>Don't</strong>: \"The CosmosClient constructor takes an endpoint (string) and credential (TokenCredential). The endpoint identifies the Azure Cosmos resource...\"</li>\n<li>✅ <strong>Do</strong>: Show code: <code>client = CosmosClient(endpoint, credential)</code>. Link to official docs: <code>microsoft-docs</code> MCP.</li>\n<li><strong>Token cost</strong>: Verbose explanation = 50-100 tokens per parameter; large APIs waste 300+ tokens</li>\n<li><strong>User impact</strong>: Redundant; official docs are authoritative, skill should show usage not repeat them</li>\n</ul>\n<h4>Anti-Pattern 5: \"Verbose Explanation When Example Suffices\"</h4>\n<ul>\n<li>❌ <strong>Don't</strong>: \"To create a client, you first instantiate the class using the constructor, passing the endpoint and credential parameters. The endpoint is a string that identifies your resource...\"</li>\n<li>✅ <strong>Do</strong>: Show code immediately: <code>with CosmosClient(endpoint, credential) as client:</code></li>\n</ul>\n<hr>\n<h3>Efficiency Validation (REQUIRED - Phase 2)</h3>\n<p><strong>During authoring, validate skill efficiency manually, then run the Vally eval if the skill has one under <code>tests/scenarios/&lt;skill-name&gt;/vally/</code>.</strong></p>\n<p><strong>1. Measure token count:</strong></p>\n<p>Use a token counter or model playground to measure each section. Compare to the Token Budget Guidelines targets above. If any section exceeds max, move content to <code>/references/</code>.</p>\n<p><strong>2. Run anti-pattern checklist:</strong></p>\n<ul>\n<li><input disabled=\"disabled\" type=\"checkbox\"> No exhaustive API reference (show 3-5 core methods, not 50)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> No multiple solutions to one problem in SKILL.md</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> No beginner+intermediate+advanced mixed</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> No restating official docs (code first, link to microsoft-docs)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> No verbose prose (examples first, minimal text)</li>\n</ul>\n<p><strong>3. Example count audit:</strong></p>\n<ul>\n<li><input disabled=\"disabled\" type=\"checkbox\"> 1 complete example per hero scenario / core workflow documented in SKILL.md. For Python SDKs that support both sync and async, the paired sync + async examples for the same workflow count as one workflow, not two.</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Feature table includes 3-5 core methods (not comprehensive API)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Max 1 example per best practice bullet</li>\n</ul>\n<p><strong>4. Frontmatter validation:</strong></p>\n<ul>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <code>name</code> matches <code>.github/skills/&lt;name&gt;/SKILL.md</code></li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <code>description</code> includes trigger keywords</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <code>description</code> is concise (~200 chars is a good target; schema max is 1,024 chars)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> If included, optional <code>benchmark_tokens_*</code> and <code>benchmark_quality_*</code> metadata fields are flat strings under <code>metadata</code></li>\n</ul>\n<p><strong>4b. Authentication guidance validation</strong> (critical for all credentials):</p>\n<ul>\n<li><input disabled=\"disabled\" type=\"checkbox\"> If skill uses Azure Identity credentials, verify guidance against the current official credential docs for that language/package (Microsoft Learn where available; otherwise the upstream SDK repo or package docs)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> For Python skills, development guidance may recommend <code>DefaultAzureCredential</code> (supports multiple dev credential types)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> For Python skills, production guidance: <code>DefaultAzureCredential</code> alone (unconstrained) is not sufficient; require either <code>AZURE_TOKEN_CREDENTIALS=prod</code> (or a specific target credential) to constrain the chain, or a specific credential (e.g., <code>ManagedIdentityCredential</code>) used directly</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> For Rust skills, development/production guidance reflects the actual supported credentials (<code>DeveloperToolsCredential</code> for local dev; a specific production credential such as <code>ManagedIdentityCredential</code> for production)</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Link to <code>/references/auth-strategies.md</code> or official docs for production credential selection</li>\n</ul>\n<p><strong>4c. Run Vally lint/eval (if the skill has a spec under <code>tests/scenarios/&lt;skill-name&gt;/vally/</code>):</strong></p>\n<pre><code># If the eval spec uses the shared Rust custom grader plugin, build it first.\n(cd tests/scenarios/_shared/vally/grader-plugins/rust-cargo-build-failure &amp;&amp; npm install &amp;&amp; npm run build)\n\nvally lint --eval-spec tests/scenarios/&lt;skill-name&gt;/vally/eval.yaml \\\n  --grader-plugin tests/scenarios/_shared/vally/grader-plugins/rust-cargo-build-failure \\\n  --strict\n\nvally eval --eval-spec tests/scenarios/&lt;skill-name&gt;/vally/eval.yaml \\\n  --grader-plugin tests/scenarios/_shared/vally/grader-plugins/rust-cargo-build-failure\n</code></pre>\n<ul>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <code>vally lint</code> passes with no errors</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> <code>vally eval</code> passes (no error-severity findings) when <code>COPILOT_TOKEN</code> is available; otherwise lint-only is acceptable, matching the <a href=\"../../workflows/vally-evaluation.yml\"><code>Vally Evaluation</code></a> workflow behavior</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Skills without a <code>vally/</code> spec skip this step — it is optional per skill, not required for every skill</li>\n</ul>\n<p><strong>5. Spot check:</strong></p>\n<ul>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Can a user copy the core workflow and run it immediately?</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Do all examples follow best practices (context managers, appropriate credentials)?</li>\n<li><input disabled=\"disabled\" type=\"checkbox\"> Are all environment variables documented?</li>\n</ul>\n<p><strong>Output:</strong> After validation, annotate the skill header with measured token count:</p>\n<pre><code># Azure Service SDK\n\n&lt;!-- Token Count: ~1180 (target: 1100, max: 1500) --&gt;\n</code></pre>\n<hr>\n<h3>Standard Verb Patterns</h3>\n<p>Azure SDKs use consistent verbs across all languages:</p>\n<table>\n<thead>\n<tr>\n<th>Verb</th>\n<th>Behavior</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>create</code></td>\n<td>Create new; fail if exists</td>\n</tr>\n<tr>\n<td><code>upsert</code></td>\n<td>Create or update</td>\n</tr>\n<tr>\n<td><code>get</code></td>\n<td>Retrieve; error if missing</td>\n</tr>\n<tr>\n<td><code>list</code></td>\n<td>Return collection</td>\n</tr>\n<tr>\n<td><code>delete</code></td>\n<td>Succeed even if missing</td>\n</tr>\n<tr>\n<td><code>begin</code></td>\n<td>Start long-running operation</td>\n</tr>\n</tbody>\n</table>\n<h3>Language-Specific Patterns</h3>\n<p>See <code>references/azure-sdk-patterns.md</code> for detailed patterns including:</p>\n<ul>\n<li><strong>Python</strong>: <code>ItemPaged</code>, <code>LROPoller</code>, context managers, Sphinx docstrings. When the SDK provides both sync and async clients, present both forms as first-class options; do not express a preference for either. When the SDK is sync-only or async-only, document the available mode only. Do not mix sync and async within a single code example. Always show <code>with</code> / <code>async with</code> context managers.</li>\n<li><strong>.NET</strong>: <code>Response&lt;T&gt;</code>, <code>Pageable&lt;T&gt;</code>, <code>Operation&lt;T&gt;</code>, mocking support</li>\n<li><strong>Java</strong>: Builder pattern, <code>PagedIterable</code>/<code>PagedFlux</code>, Reactor types</li>\n<li><strong>TypeScript</strong>: <code>PagedAsyncIterableIterator</code>, <code>AbortSignal</code>, browser considerations</li>\n<li><strong>Go</strong>: <code>context.Context</code> as first arg, <code>runtime.Pager[T]</code> via <code>New*Pager()</code> + <code>More()/NextPage(ctx)</code>, <code>runtime.Poller[T]</code> via <code>Begin*</code> + <code>PollUntilDone(ctx, nil)</code>, <code>to.Ptr(...)</code> helpers, and typed <code>*azcore.ResponseError</code></li>\n<li><strong>Rust</strong>: Installation via <code>cargo add</code>, dependency rule for <code>azure_core</code>, <code>Response&lt;T&gt;</code>, <code>Pager&lt;T&gt;</code>, <code>RequestContent::from()</code>, <code>.into_model()</code>, explicit credential types, RBAC roles for Entra ID authentication</li>\n</ul>\n<h3>Required Best Practices in Every Skill (User-Facing)</h3>\n<h4>Python, .NET, Java, TypeScript, and Go languages</h4>\n<p><strong>These two rules are not just authoring conventions for the skill itself — they MUST be explicitly written into every generated skill's <code>## Best Practices</code> section so end users who follow the skill apply them in their own code.</strong></p>\n<p>Add both items verbatim (adapted only for language/SDK specifics) as the <strong>first two items</strong> of the Best Practices list. Do not assume users will infer them from examples.</p>\n<p><strong>Standard wording (Python; adapt for other languages):</strong></p>\n<pre><code>1. **Do not mix sync and async clients in the same call path.** Use either `azure.xxx` sync clients or `azure.xxx.aio` async clients within a single call path — do not combine both.\n2. **Always use context managers for clients and async credentials.** Wrap every client in `with Client(...) as client:` (sync) or `async with Client(...) as client:` (async). For async `DefaultAzureCredential` from `azure.identity.aio`, also use `async with credential:` so tokens and transports are cleaned up.\n3. **Use `DefaultAzureCredential`** for code that runs locally. For code that runs in Azure, either constrain `DefaultAzureCredential` with `AZURE_TOKEN_CREDENTIALS=prod` (or a specific target credential) or use a specific token credential directly (e.g. `ManagedIdentityCredential`, `WorkloadIdentityCredential`).\n</code></pre>\n<p><strong>Variants to apply when the SDK shape differs:</strong></p>\n<table>\n<thead>\n<tr>\n<th>Skill type</th>\n<th>Adjust item #1 to</th>\n<th>Adjust item #2 to</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Async-only SDK (e.g. voicelive)</td>\n<td>\"This SDK is async-only; use the <code>.aio</code> namespace throughout.\"</td>\n<td>keep standard</td>\n</tr>\n<tr>\n<td>Framework guidance that is async-oriented (for example some agent frameworks)</td>\n<td>\"Use the framework's documented async patterns where required, but do not claim async is globally preferred for Azure Python SDKs.\"</td>\n<td>keep standard</td>\n</tr>\n<tr>\n<td>Provider-pattern (OpenTelemetry exporters/distro)</td>\n<td>keep standard</td>\n<td>\"Call <code>provider.shutdown()</code> / <code>flush()</code> at process exit to flush telemetry — providers are not context managers.\"</td>\n</tr>\n<tr>\n<td>REST-over-httpx skills</td>\n<td>keep standard</td>\n<td>\"Use <code>with httpx.Client(...) as client:</code> (sync) or <code>async with httpx.AsyncClient(...) as client:</code> (async) so connections pool and close deterministically.\"</td>\n</tr>\n<tr>\n<td>Identity skill</td>\n<td>keep standard</td>\n<td>\"Use credentials as context managers (<code>with DefaultAzureCredential() as credential:</code>) when they own token caches / HTTP transports you want cleaned up; for async, use <code>async with</code> on credentials from <code>azure.identity.aio</code>.\"</td>\n</tr>\n<tr>\n<td>FastAPI (non-Azure)</td>\n<td>\"Pick <code>def</code> or <code>async def</code> per endpoint based on whether you call async I/O; do not mix sync and blocking calls in one handler.\"</td>\n<td>\"Manage long-lived resources (DB pools, HTTP clients) in <code>lifespan</code> and inject via <code>Depends</code>; use <code>with</code>/<code>async with</code> for per-request resources.\"</td>\n</tr>\n<tr>\n<td>Pure model/schema skill (no I/O, e.g. pydantic)</td>\n<td><strong>skip both</strong> — not applicable</td>\n<td><strong>skip</strong></td>\n</tr>\n</tbody>\n</table>\n<p><strong>Enforcement in code examples.</strong> Every code example inside the skill must itself obey both rules, so the skill demonstrates what it prescribes:</p>\n<ul>\n<li>Do not interleave sync and async calls within a single example. When the SDK provides both sync and async clients, show each mode in its own complete, self-contained example — a <code>### Sync</code> subsection and an <code>### Async</code> subsection — giving both equal prominence. When the SDK is sync-only or async-only, show only the available mode.</li>\n<li>Every client instantiation in every example must be wrapped in <code>with</code> / <code>async with</code>. The only permitted exception is the mandatory Authentication snippet (which illustrates the credential + client construction pattern) and framework lifespan patterns where a client is owned by the app (e.g. FastAPI <code>lifespan</code>).</li>\n<li>When async credentials from <code>azure.identity.aio</code> appear in an example, wrap them in <code>async with credential:</code> alongside the client.</li>\n</ul>\n<h4>Rust Language</h4>\n<p><strong>These rules MUST be explicitly written into every Rust skill's <code>## Best Practices</code> section as the first items:</strong></p>\n<ol>\n<li><p><strong>Use <code>cargo add</code> to manage dependencies, never edit <code>Cargo.toml</code> directly.</strong> Always use <code>cargo add &lt;crate&gt;</code> or <code>cargo remove &lt;crate&gt;</code> instead of manually modifying the manifest file. Official crates are published on crates.io and should be added via cargo.</p>\n</li>\n<li><p><strong>Add <code>azure_core</code> to <code>Cargo.toml</code> only when you import <code>azure_core</code> types directly.</strong> If your code imports types like <code>azure_core::http::Url</code>, <code>azure_core::http::RequestContent</code>, or <code>azure_core::error::ErrorKind</code>, explicitly add <code>azure_core</code> to your dependencies. If you only use types re-exported by service crates (e.g., via <code>use azure_storage_blob::BlobClient</code>), a direct <code>azure_core</code> dependency is optional.</p>\n</li>\n<li><p><strong>Use <code>DeveloperToolsCredential</code> for local development and <code>ManagedIdentityCredential</code> for production.</strong> The Rust SDK does not support <code>DefaultAzureCredential</code>, so explicitly use the appropriate credential in each environment.</p>\n</li>\n<li><p><strong>Use <code>RequestContent::from()</code> to wrap upload data.</strong> When uploading data (e.g., blobs), wrap the content in <code>RequestContent::from(your_data)</code> to ensure proper handling by the SDK.</p>\n</li>\n<li><p><strong>Assign appropriate RBAC roles for Entra ID auth.</strong> For production authentication using Entra ID, ensure the identity has the necessary RBAC role assigned (e.g., \"Storage Blob Data Contributor\" for blob write access).</p>\n</li>\n<li><p><strong>Always verify package versions using crates.io.</strong> Before using a package, check its version on <a href=\"https://crates.io/\">crates.io</a> to ensure you are using a stable and supported release.</p>\n</li>\n<li><p><strong>Future-proof <code>#[non_exhaustive]</code> model structs and enums.</strong> Azure Rust SDK request/response models are frequently <code>#[non_exhaustive]</code>. For <strong>externally constructible</strong> structs that also derive <code>Default</code>, end the initializer with <code>..Default::default()</code> (even if every currently known field is set), suppressing the lint locally with <code>#[allow(clippy::needless_update)]</code> when needed. For <strong>truly <code>#[non_exhaustive]</code></strong> structs (where Rust forbids external struct literals, producing E0639), use the provided constructor or builder, or construct a default value first and then mutate the fields you need. When matching an SDK enum, include a wildcard (<code>_</code>) arm so future service-added variants do not break the match. If a skill documents model construction, its code examples MUST demonstrate this pattern. See <code>references/azure-sdk-patterns.md</code> (Model Types) for the full example.</p>\n</li>\n</ol>\n<h3>Example Effective Skills (Benchmark Only Structure-Compliant Skills)</h3>\n<p><strong>Only benchmark Azure SDK skills that already use the required <code>references/</code> layout</strong> (<code>references/capabilities.md</code> plus <code>references/non-hero-scenarios.md</code>). Older skills that predate that structure can still be useful for style ideas, but do not mirror them directly until they are brought into compliance.</p>\n<p><strong>A valid benchmark skill should</strong>:</p>\n<ol>\n<li>Stay at or under the 1,500-token absolute max (see Token Budget Guidelines above)</li>\n<li>Cover the hero workflow (CRUD or primary operations), not every feature variant</li>\n<li>Show 1-2 examples per concept, not 3-5</li>\n<li>Use tables for API summary (credential types, RBAC roles, client hierarchy)</li>\n<li>Link to official docs via <code>microsoft-docs</code> MCP instead of duplicating</li>\n<li>Move advanced patterns to <code>/references/</code></li>\n<li>Include <code>references/capabilities.md</code> and <code>references/non-hero-scenarios.md</code></li>\n</ol>\n<p><strong>Before writing your skill</strong>: Apply the checklist above directly, then mirror only the structure patterns that fit your use case.</p>\n<hr>\n<h3>Handling Deprecated or Rebranded SDKs</h3>\n<p>When an Azure SDK has been deprecated or rebranded, update skills to guide users toward the current package while maintaining backward compatibility:</p>\n<p><strong>1. Add a migration notice at the top of the skill:</strong></p>\n<pre><code>&gt; **⚠️ MIGRATION NOTICE**: The [Old Service Name] has been rebranded to **[New Service Name]**. While the package `old-package-name` remains available for compatibility, **new projects should use `new-package-name`** which provides the latest features and updates.\n&gt;\n&gt; **For new projects**: Use the `new-package-name` package instead.\n&gt;\n&gt; **This skill remains valid** for existing projects using `old-package-name`, but be aware you're using the legacy package name. The API patterns shown here are compatible with both packages.\n</code></pre>\n<p><strong>2. Show both installation options:</strong></p>\n<pre><code>## Installation\n\n### Legacy Package (Old Name)\n\n\\`\\`\\`xml\n&lt;dependency&gt;\n&lt;groupId&gt;com.azure&lt;/groupId&gt;\n&lt;artifactId&gt;azure-old-package&lt;/artifactId&gt;\n&lt;version&gt;4.2.0&lt;/version&gt;\n&lt;/dependency&gt;\n\\`\\`\\`\n\n### Recommended Package (New Name)\n\n**For new projects, use the rebranded package:**\n\n\\`\\`\\`xml\n&lt;dependency&gt;\n&lt;groupId&gt;com.azure&lt;/groupId&gt;\n&lt;artifactId&gt;azure-new-package&lt;/artifactId&gt;\n&lt;version&gt;1.0.0&lt;/version&gt;\n&lt;/dependency&gt;\n\\`\\`\\`\n\n&gt; **Note**: The API patterns in this skill apply to both packages. Replace package names and imports as needed when using `azure-new-package`.\n</code></pre>\n<p><strong>3. When to create a new skill vs. update existing:</strong></p>\n<ul>\n<li><strong>Update existing skill</strong> if the API is largely compatible (same or similar class/method names)</li>\n<li><strong>Create new skill + migration guide</strong> if the API changed significantly (use <code>references/migration.md</code>)</li>\n<li><strong>Always cross-reference</strong> between old and new skills</li>\n</ul>\n<p><strong>Examples:</strong></p>\n<ul>\n<li><code>azure-ai-formrecognizer-java</code> → <code>azure-ai-documentintelligence</code> (rebranded service)</li>\n<li><code>azure-communication-callingserver-java</code> → <code>azure-communication-callautomation</code> (deprecated, with migration guide)</li>\n</ul>\n<h3>Example: Azure SDK Skill Structure</h3>\n<pre><code>---\nname: skill-creator\ndescription: |\n  Azure AI Example SDK for Python. Use for [specific service features].\n  Triggers: \"example service\", \"create example\", \"list examples\".\n---\n\n# Azure AI Example SDK\n\n## Installation\n\n\\`\\`\\`bash\npip install azure-ai-example\n\\`\\`\\`\n\n## Environment Variables\n\n\\`\\`\\`bash\nAZURE_EXAMPLE_ENDPOINT=https://&lt;resource&gt;.example.azure.com\nAZURE_TOKEN_CREDENTIALS=prod # Required only if DefaultAzureCredential is used in production\n\\`\\`\\`\n\n## Authentication &amp; Lifecycle\n\n&gt; **\uD83D\uDD11 Two rules apply to every code sample below:**\n&gt;\n&gt; 1. **Prefer `DefaultAzureCredential` for local development.** It works as-is with Azure CLI / VS Code / Developer CLI. For production, either constrain `DefaultAzureCredential` to production-safe credentials or use a specific credential directly. Avoid connection strings, account/API keys — they bypass Entra audit and rotation.\n&gt;    - Local dev: `DefaultAzureCredential` works as-is.\n&gt;    - Production: set `AZURE_TOKEN_CREDENTIALS=prod` (or `AZURE_TOKEN_CREDENTIALS=&lt;specific_credential&gt;`) to constrain the credential chain to production-safe credentials.\n&gt; 2. **Wrap every client in a context manager** so HTTP transports, sockets, and token caches are released deterministically:\n&gt;    - Sync: `with &lt;Client&gt;(...) as client:`\n&gt;    - Async: `async with &lt;Client&gt;(...) as client:` **and** `async with DefaultAzureCredential() as credential:` (from `azure.identity.aio`)\n&gt;\n&gt; Snippets may abbreviate this setup, but production code should always follow both rules.\n\n\\`\\`\\`python\nfrom azure.identity import DefaultAzureCredential, ManagedIdentityCredential\nfrom azure.ai.example import ExampleClient\n\n# Local dev: DefaultAzureCredential works as-is.\ncredential = DefaultAzureCredential()\n\n# Production alternative: constrain DefaultAzureCredential with AZURE_TOKEN_CREDENTIALS.\n# credential = DefaultAzureCredential(require_envvar=True)\n\n# Or use a specific credential directly in production:\n\n# See https://learn.microsoft.com/python/api/overview/azure/identity-readme?view=azure-python#credential-classes\n\n# credential = ManagedIdentityCredential()\n\nwith ExampleClient(\nendpoint=os.environ[\"AZURE_EXAMPLE_ENDPOINT\"],\ncredential=credential,\n) as client:\nitem = client.get_item(\"example\")\n\\`\\`\\`\n\n## Core Workflow\n\n\\`\\`\\`python\nwith ExampleClient(endpoint=endpoint, credential=credential) as client: # Create\nitem = client.create_item(name=\"example\", data={...})\n\n    # List (pagination handled automatically)\n    for item in client.list_items():\n        print(item.name)\n\n    # Long-running operation\n    poller = client.begin_process(item.id)\n    result = poller.result()\n\n    # Cleanup\n    client.delete_item(item.id)\n\n\\`\\`\\`\n\n## Reference Files\n\n| File                                                                 | Contents                                               |\n| -------------------------------------------------------------------- | ------------------------------------------------------ |\n| [references/capabilities.md](references/capabilities.md)             | Capability index (hero coverage + links to deep-dives) |\n| [references/non-hero-scenarios.md](references/non-hero-scenarios.md) | Concrete non-hero examples                             |\n| [references/tools.md](references/tools.md)                           | Tool integrations                                      |\n| [references/streaming.md](references/streaming.md)                   | Event streaming patterns                               |\n</code></pre>\n<hr>\n<h2>Skill Creation Process</h2>\n<ol>\n<li><strong>Gather SDK Context</strong> — User provides SDK/API reference (REQUIRED)</li>\n<li><strong>Understand</strong> — Research SDK patterns from official docs</li>\n<li><strong>Plan</strong> — Identify reusable resources and product area category</li>\n<li><strong>Create</strong> — Write SKILL.md in <code>.github/skills/&lt;skill-name&gt;/</code></li>\n<li><strong>Categorize</strong> — Create symlink in <code>skills/&lt;language&gt;/&lt;category&gt;/</code></li>\n<li><strong>Test</strong> — Create acceptance criteria and test scenarios</li>\n<li><strong>Document</strong> — Update README.md skill catalog</li>\n<li><strong>Iterate</strong> — Refine based on real usage</li>\n</ol>\n<h3>Step 1: Gather SDK Context (REQUIRED)</h3>\n<p><strong>Before creating any SDK skill, the user MUST provide:</strong></p>\n<table>\n<thead>\n<tr>\n<th>Required</th>\n<th>Example</th>\n<th>Purpose</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><strong>SDK Package</strong></td>\n<td><code>azure-ai-agents</code>, <code>Azure.AI.OpenAI</code>, <code>azblob</code></td>\n<td>Identifies the exact SDK</td>\n</tr>\n<tr>\n<td><strong>Documentation URL</strong></td>\n<td><code>https://learn.microsoft.com/en-us/azure/ai-services/...</code></td>\n<td>Primary source of truth</td>\n</tr>\n<tr>\n<td><strong>Repository</strong> (optional)</td>\n<td><code>Azure/azure-sdk-for-python</code>, <code>Azure/azure-sdk-for-go</code></td>\n<td>For code patterns</td>\n</tr>\n</tbody>\n</table>\n<p><strong>Prompt the user if not provided:</strong></p>\n<pre><code>To create this skill, I need:\n1. The SDK package name (e.g., azure-ai-projects)\n2. The Microsoft Learn documentation URL or GitHub repo\n3. The target language (py/dotnet/ts/java/go)\n</code></pre>\n<p><strong>Search official docs first:</strong></p>\n<pre><code># Use microsoft-docs MCP to get current API patterns\n# Query: \"[SDK name] [operation] [language]\"\n# Verify: Parameters match the latest SDK version\n</code></pre>\n<h3>Step 2: Understand the Skill</h3>\n<p>Gather concrete examples:</p>\n<ul>\n<li>\"What SDK operations should this skill cover?\"</li>\n<li>\"What triggers should activate this skill?\"</li>\n<li>\"What errors do developers commonly encounter?\"</li>\n</ul>\n<table>\n<thead>\n<tr>\n<th>Example Task</th>\n<th>Reusable Resource</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Same auth code each time</td>\n<td>Code example in SKILL.md</td>\n</tr>\n<tr>\n<td>Complex streaming patterns</td>\n<td><code>references/streaming.md</code></td>\n</tr>\n<tr>\n<td>Tool configurations</td>\n<td><code>references/tools.md</code></td>\n</tr>\n<tr>\n<td>Error handling patterns</td>\n<td><code>references/error-handling.md</code></td>\n</tr>\n</tbody>\n</table>\n<h3>Step 3: Plan Product Area Category</h3>\n<p>Skills are organized by <strong>language</strong> and <strong>product area</strong> in the <code>skills/</code> directory via symlinks.</p>\n<p><strong>Product Area Categories:</strong></p>\n<table>\n<thead>\n<tr>\n<th>Category</th>\n<th>Description</th>\n<th>Examples</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>foundry</code></td>\n<td>AI Foundry, agents, projects, inference</td>\n<td><code>azure-ai-agents-py</code>, <code>azure-ai-projects-py</code></td>\n</tr>\n<tr>\n<td><code>data</code></td>\n<td>Storage, Cosmos DB, Tables, Data Lake</td>\n<td><code>azure-cosmos-py</code>, <code>azure-storage-blob-py</code></td>\n</tr>\n<tr>\n<td><code>messaging</code></td>\n<td>Event Hubs, Service Bus, Event Grid</td>\n<td><code>azure-eventhub-py</code>, <code>azure-servicebus-py</code></td>\n</tr>\n<tr>\n<td><code>monitoring</code></td>\n<td>OpenTelemetry, App Insights, Query</td>\n<td><code>azure-monitor-opentelemetry-py</code></td>\n</tr>\n<tr>\n<td><code>identity</code></td>\n<td>Authentication, DefaultAzureCredential</td>\n<td><code>azure-identity-py</code></td>\n</tr>\n<tr>\n<td><code>security</code></td>\n<td>Key Vault, secrets, keys, certificates</td>\n<td><code>azure-keyvault-py</code></td>\n</tr>\n<tr>\n<td><code>integration</code></td>\n<td>API Management, App Configuration</td>\n<td><code>azure-appconfiguration-py</code></td>\n</tr>\n<tr>\n<td><code>compute</code></td>\n<td>Batch, ML compute</td>\n<td><code>azure-compute-batch-java</code></td>\n</tr>\n<tr>\n<td><code>container</code></td>\n<td>Container Registry, ACR</td>\n<td><code>azure-containerregistry-py</code></td>\n</tr>\n</tbody>\n</table>\n<p><strong>Determine the category</strong> based on:</p>\n<ol>\n<li>Azure service family (Storage → <code>data</code>, Event Hubs → <code>messaging</code>)</li>\n<li>Primary use case (AI agents → <code>foundry</code>)</li>\n<li>Existing skills in the same service area</li>\n</ol>\n<h3>Step 4: Create the Skill</h3>\n<p><strong>Location:</strong> <code>.github/skills/&lt;skill-name&gt;/SKILL.md</code></p>\n<p><strong>Naming convention:</strong></p>\n<ul>\n<li><code>azure-&lt;service&gt;-&lt;subservice&gt;-&lt;language&gt;</code></li>\n<li>Examples: <code>azure-ai-agents-py</code>, <code>azure-cosmos-java</code>, <code>azure-storage-blob-ts</code>, <code>azure-storage-blob-go</code></li>\n<li>For Go skills in documentation prose, use the short package name (for example <code>azblob</code>).</li>\n<li>Use the full module import path only in code/import examples (for example <code>github.com/Azure/azure-sdk-for-go/sdk/storage/azblob</code>).</li>\n</ul>\n<p><strong>For Azure SDK skills:</strong></p>\n<ol>\n<li>Search <code>microsoft-docs</code> MCP for current API patterns</li>\n<li>Verify against installed SDK version</li>\n<li>Follow the section order above</li>\n<li>Include cleanup code in examples</li>\n<li>Add feature comparison tables</li>\n</ol>\n<p><strong>Write bundled resources first</strong>, then SKILL.md.</p>\n<p><strong>Quality assurance before finalizing:</strong></p>\n<ol>\n<li>Measure section token counts as you write (use model playground token counter)</li>\n<li>Compare to Token Budget Guidelines targets</li>\n<li>Validate against anti-patterns checklist (see Anti-Patterns section)</li>\n<li>Extract to <code>/references/</code> if section exceeds max tokens</li>\n<li>Run Efficiency Validation checklist, including <code>vally lint</code>/<code>vally eval</code> if the skill has a spec (see Efficiency Validation)</li>\n<li>Optionally add <code>benchmark_tokens_*</code> and <code>benchmark_quality_*</code> fields under the frontmatter's <code>metadata</code> mapping (flat string values)</li>\n<li>Add token count comment to skill header for future maintenance</li>\n</ol>\n<p><strong>Frontmatter (Enhanced with Benchmarking Metadata):</strong></p>\n<pre><code>---\nname: azure-service-py\ndescription: |\n  Azure Service SDK for Python. Use for [specific features].\n  Triggers: \"service name\", \"create resource\", \"specific operation\".\nmetadata:\n  benchmark_tokens_estimated: \"1180\"\n  benchmark_tokens_target: \"1100\"\n  benchmark_tokens_max: \"1500\"\n  benchmark_quality_single_core_workflow: \"true\"\n  benchmark_quality_examples_focused: \"true\"\n  benchmark_quality_no_prose_bloat: \"true\"\n  benchmark_quality_anti_patterns_checked: \"true\"\n---\n</code></pre>\n<p><strong>Metadata fields:</strong> (all values are strings, per the Agent Skills <code>metadata</code> spec — string keys mapped to string values)</p>\n<ul>\n<li><code>benchmark_tokens_estimated</code> — Actual measured token count</li>\n<li><code>benchmark_tokens_target</code> — Target efficiency (typically 1100)</li>\n<li><code>benchmark_tokens_max</code> — Absolute ceiling (1500; split if exceeded)</li>\n<li><code>benchmark_quality_*</code> — Individual anti-pattern checks, each a <code>\"true\"</code>/<code>\"false\"</code> string (e.g., <code>benchmark_quality_single_core_workflow</code>)</li>\n</ul>\n<h3>Step 5: Categorize with Symlinks</h3>\n<p>After creating the skill in <code>.github/skills/</code>, create a symlink in the appropriate category:</p>\n<pre><code># Pattern: skills/&lt;language&gt;/&lt;category&gt;/&lt;short-name&gt; -&gt; ../../../.github/skills/&lt;full-skill-name&gt;\n\n# Example for azure-ai-agents-py in python/foundry:\ncd skills/python/foundry\nln -s ../../../.github/skills/azure-ai-agents-py agents\n\n# Example for azure-cosmos-db-py in python/data:\ncd skills/python/data\nln -s ../../../.github/skills/azure-cosmos-db-py cosmos-db\n\n# Example for azure-storage-blob-go in go/data:\ncd skills/go/data\nln -s ../../../.github/skills/azure-storage-blob-go blob\n</code></pre>\n<p><strong>Symlink naming:</strong></p>\n<ul>\n<li>Use short, descriptive names (e.g., <code>agents</code>, <code>cosmos</code>, <code>blob</code>)</li>\n<li>Remove the <code>azure-</code> prefix and language suffix</li>\n<li>Match existing patterns in the category</li>\n</ul>\n<p><strong>Verify the symlink:</strong></p>\n<pre><code>ls -la skills/python/foundry/agents\n# Should show: agents -&gt; ../../../.github/skills/azure-ai-agents-py\n</code></pre>\n<h3>Step 6: Create Tests</h3>\n<p><strong>Every skill MUST have acceptance criteria and test scenarios.</strong></p>\n<h4>6.1 Create Acceptance Criteria</h4>\n<p><strong>Location:</strong> <code>tests/scenarios/&lt;skill-name&gt;/acceptance-criteria.md</code></p>\n<blockquote>\n<p>Keep acceptance criteria in the <code>tests/</code> tree (never beside <code>SKILL.md</code> inside the skill folder).</p>\n</blockquote>\n<p><strong>Source materials</strong> (in priority order):</p>\n<ol>\n<li>Official Microsoft Learn docs (via <code>microsoft-docs</code> MCP)</li>\n<li>SDK source code from the repository</li>\n<li>Existing reference files in the skill</li>\n</ol>\n<p><strong>Format:</strong></p>\n<pre><code># Acceptance Criteria: &lt;skill-name&gt;\n\n**SDK**: `package-name`\n**Repository**: https://github.com/Azure/azure-sdk-for-&lt;language&gt;\n**Purpose**: Skill testing acceptance criteria\n\n---\n\n## 1. Correct Import Patterns\n\n### 1.1 Client Imports\n\n#### ✅ CORRECT: Main Client\n\n\\`\\`\\`python\nfrom azure.ai.mymodule import MyClient\nfrom azure.identity import DefaultAzureCredential\n\\`\\`\\`\n\n#### ❌ INCORRECT: Wrong Module Path\n\n\\`\\`\\`python\nfrom azure.ai.mymodule.models import MyClient # Wrong - Client is not in models\n\\`\\`\\`\n\n## 2. Authentication Patterns\n\n#### ✅ CORRECT: DefaultAzureCredential + context manager\n\n\\`\\`\\`python\ncredential = DefaultAzureCredential()\nwith MyClient(endpoint, credential) as client:\nclient.do_thing()\n\\`\\`\\`\n\n#### ❌ INCORRECT: Hardcoded Credentials\n\n\\`\\`\\`python\nclient = MyClient(endpoint, api_key=\"hardcoded\") # Security risk\n\\`\\`\\`\n\n#### ❌ INCORRECT: Connection string / account key when Entra is supported\n\n\\`\\`\\`python\nclient = MyClient.from_connection_string(os.environ[\"CONNECTION_STRING\"]) # Bypasses Entra audit/rotation\n\\`\\`\\`\n\n#### ❌ INCORRECT: Bare client without context manager\n\n\\`\\`\\`python\nclient = MyClient(endpoint, credential) # Leaks HTTP transport on exception / interpreter exit\nclient.do_thing()\n\\`\\`\\`\n</code></pre>\n<p><strong>Critical patterns to document:</strong></p>\n<ul>\n<li>Import paths (these vary significantly between Azure SDKs)</li>\n<li>Authentication patterns</li>\n<li>Client initialization</li>\n<li>Async variants (<code>.aio</code> modules)</li>\n<li>Common anti-patterns</li>\n</ul>\n<h4>6.2 Create Test Scenarios</h4>\n<p><strong>Location:</strong> <code>tests/scenarios/&lt;skill-name&gt;/scenarios.yaml</code></p>\n<pre><code>config:\n  model: gpt-4\n  max_tokens: 2000\n  temperature: 0.3\n\nscenarios:\n  - name: basic_client_creation\n    prompt: |\n      Create a basic example using the Azure SDK.\n      Include proper authentication and client initialization.\n    expected_patterns:\n      - \"DefaultAzureCredential\"\n      - \"MyClient\"\n      - \"with MyClient\" # enforce context manager\n    forbidden_patterns:\n      - \"api_key=\"\n      - \"hardcoded\"\n      - \"from_connection_string\" # prefer Entra over connection strings\n    tags:\n      - basic\n      - authentication\n    mock_response: |\n      import os\n      from azure.identity import DefaultAzureCredential\n      from azure.ai.mymodule import MyClient\n\n      credential = DefaultAzureCredential()\n      with MyClient(\n          endpoint=os.environ[\"AZURE_ENDPOINT\"],\n          credential=credential,\n      ) as client:\n          # ... rest of working example\n          pass\n</code></pre>\n<p><strong>Scenario design principles:</strong></p>\n<ul>\n<li>Each scenario tests ONE specific pattern or feature</li>\n<li><code>expected_patterns</code> — patterns that MUST appear</li>\n<li><code>forbidden_patterns</code> — common mistakes that must NOT appear</li>\n<li><code>mock_response</code> — complete, working code that passes all checks</li>\n<li><code>tags</code> — for filtering (<code>basic</code>, <code>async</code>, <code>streaming</code>, <code>tools</code>)</li>\n</ul>\n<h4>6.3 Run Tests</h4>\n<pre><code>cd tests\npnpm install\n\n# Check skill is discovered\npnpm harness --list\n\n# Run in mock mode (fast, deterministic)\npnpm harness &lt;skill-name&gt; --mock --verbose\n\n# Run with Ralph Loop (iterative improvement)\npnpm harness &lt;skill-name&gt; --ralph --mock --max-iterations 5 --threshold 85\n</code></pre>\n<p><strong>Success criteria:</strong></p>\n<ul>\n<li>All scenarios pass (100% pass rate)</li>\n<li>No false positives (mock responses always pass)</li>\n<li>Patterns catch real mistakes</li>\n</ul>\n<h3>Step 7: Update Documentation</h3>\n<p>After creating the skill:</p>\n<ol>\n<li><p><strong>Update README.md</strong> — Add the skill to the appropriate language section in the Skill Catalog</p>\n<ul>\n<li>Update total skill count (line ~73: <code>&gt; N skills in...</code>)</li>\n<li>Update Skill Explorer link count (line ~15: <code>Browse all N skills</code>)</li>\n<li>Update language count table (lines ~77-83)</li>\n<li>Update language section count (e.g., <code>&gt; N skills • suffix: -py</code>)</li>\n<li>Update category count (e.g., <code>&lt;summary&gt;&lt;strong&gt;Foundry &amp; AI&lt;/strong&gt; (N skills)&lt;/summary&gt;</code>)</li>\n<li>Add skill row in alphabetical order within its category</li>\n<li>Update test coverage summary (line ~622: <code>**N skills with N test scenarios**</code>)</li>\n<li>Update test coverage table — update skill count, scenario count, and top skills for the language</li>\n</ul>\n</li>\n<li><p><strong>Regenerate GitHub Pages data</strong> — Run the extraction script and rebuild the docs site from one scoped directory change</p>\n<pre><code>(cd docs-site &amp;&amp; npx tsx scripts/extract-skills.ts &amp;&amp; npm run build)\n</code></pre>\n<p>This updates <code>docs-site/src/data/skills.json</code> which feeds the Astro-based docs site, then rebuilds the site into <code>docs/</code>, which is served by GitHub Pages.</p>\n</li>\n<li><p><strong>Verify AGENTS.md</strong> — Ensure the skill count is accurate</p>\n</li>\n</ol>\n<hr>\n<h3>Step 8: Regenerate Existing Skills from Latest SDK Sources</h3>\n<p>Use this workflow when an existing skill has stale examples, outdated API signatures,\nor changed package guidance.</p>\n<ol>\n<li><strong>Identify canonical source files first</strong></li>\n</ol>\n<p>For Azure SDK language skills, use official upstream source docs and examples as the source of truth:</p>\n<ul>\n<li>Go: <code>https://github.com/Azure/azure-sdk-for-go/tree/main/sdk/&lt;service&gt;/&lt;module&gt;/README.md</code></li>\n<li>Go examples: <code>https://github.com/Azure/azure-sdk-for-go/tree/main/sdk/&lt;service&gt;/&lt;module&gt;/</code></li>\n<li>Rust: <code>https://github.com/Azure/azure-sdk-for-rust/tree/main/sdk/&lt;service&gt;/&lt;crate&gt;/README.md</code></li>\n<li>Rust examples: <code>https://github.com/Azure/azure-sdk-for-rust/tree/main/sdk/&lt;service&gt;/&lt;crate&gt;/examples/</code></li>\n<li>.NET/Java/Python/TS/Go: use current Microsoft Learn package docs + official SDK repos</li>\n</ul>\n<ol start=\"2\">\n<li><strong>Refresh skill content surgically</strong></li>\n</ol>\n<ul>\n<li>Update code snippets to match current constructor/method signatures</li>\n<li>Keep crate/package names aligned with official publisher guidance</li>\n<li>Preserve skill structure/frontmatter unless intentionally changing behavior</li>\n<li>Update \"Best Practices\" and \"Reference Links\" when upstream recommendations change</li>\n<li>For Rust, if code uses <code>azure_core</code> types/imports directly, ensure <code>azure_core</code> is present in <code>Cargo.toml</code>; if only service-crate re-exports are used, direct <code>azure_core</code> dependency is optional</li>\n</ul>\n<h3>API Surface Parity Gate (required for every regenerated skill)</h3>\n<p>Use the language-specific authoritative source as the contract for every snippet in the regenerated skill:</p>\n<ul>\n<li><strong>Python, .NET, Java, TypeScript, Go</strong>: Treat the current Microsoft Learn API reference as the contract.</li>\n<li><strong>Rust</strong>: Treat the official SDK repository (<code>https://github.com/Azure/azure-sdk-for-rust</code>) and crates.io documentation as the contract; Rust packages do not have Learn API-reference pages.</li>\n</ul>\n<p>Before finalizing any regenerated skill:</p>\n<ol>\n<li>Identify each SDK type/method shown in snippets (clients, operation groups, model constructors, enum members, long-running methods like <code>begin_*</code>).</li>\n<li>Verify each symbol and signature against the authoritative source for that language/package (see above).</li>\n<li>If the authoritative source shows a different shape (for example nested <code>properties=...</code> models, renamed methods, <code>begin_*</code> LRO methods), update the snippet to match.</li>\n<li>Re-check imports so model/client modules match the authoritative source exactly.</li>\n<li>Do not keep compatibility shortcuts that contradict authoritative examples in primary snippets.</li>\n</ol>\n<h3>Scenario Coverage Gate (required for every regenerated skill, all languages)</h3>\n<p>Regeneration is not complete when snippets compile — it is complete when the skill demonstrates real usage breadth.</p>\n<p>Before finalizing any regenerated skill:</p>\n<ol>\n<li>Identify <strong>hero scenarios</strong> from the current authoritative docs/samples for that SDK (Microsoft Learn where available; otherwise the upstream SDK repo and package documentation).</li>\n<li>Ensure each hero scenario is represented in the skill with copy-pastable snippets (or an explicit link to a bundled reference file when too large).</li>\n<li>Add/refresh test scenarios so hero flows are validated by harness patterns.</li>\n<li>Add at least <strong>one important non-hero scenario</strong> (for example: update/patch, delete/cleanup, export/import, advanced auth mode, paging/filtering, retries/error handling, or LRO monitoring) when supported by the SDK. For Python SDKs that support both sync and async clients, present both forms with equal priority; do not treat either as universally preferred.</li>\n<li>For Azure SDK skills, structure <code>references/</code> as:\n<ul>\n<li><code>references/capabilities.md</code> as a concise index that records each hero scenario and where it is covered (<code>SKILL.md</code> or a bundled reference), plus links to deeper non-hero references, with no historical/migration narration.</li>\n<li><code>references/non-hero-scenarios.md</code> for concrete non-hero examples that are intentionally kept out of the main <code>SKILL.md</code>.</li>\n<li>Additional <code>references/*.md</code> files for specialized deep-dives (operation groups, tools, evaluator matrices, etc.).</li>\n</ul>\n</li>\n<li>If the SDK has broad operation-group coverage (common in management SDKs), include an operation-group table and explicitly call out which groups are covered in snippets vs. referenced only.</li>\n<li>Never claim \"full API surface\" unless the skill genuinely demonstrates all major operation groups; otherwise state that the skill is optimized for hero workflows plus selected secondary scenarios.</li>\n</ol>\n<h3>Regeneration Workflow Step 3: Validate Regenerated Skill Behavior</h3>\n<pre><code>(cd tests &amp;&amp; pnpm harness &lt;skill-name&gt; --mock --verbose)\n</code></pre>\n<p>If the skill has a Vally scenario, run that eval as well (locally or in CI) before finalizing.</p>\n<p><strong>Rust regeneration gate (required for Rust skills):</strong></p>\n<p>When regenerating any Rust skill, verify the generated <code>## Best Practices</code> section contains these exact first two rules:</p>\n<ol>\n<li><code>Use cargo add to manage dependencies, never edit Cargo.toml directly</code></li>\n<li><code>Add azure_core only when importing azure_core types directly</code></li>\n</ol>\n<p>Use a content check before finalizing:</p>\n<pre><code>rg -n \"Use `cargo add` to manage dependencies, never edit `Cargo.toml` directly|Add `azure_core` only when importing `azure_core` types directly\" .github/plugins/azure-sdk-rust/skills/**/SKILL.md\n</code></pre>\n<p>The regeneration is not complete unless both lines are present in each affected Rust skill.</p>\n<h3>Regeneration Workflow Step 4: Regenerate Docs Artifacts After Refresh</h3>\n<pre><code>(cd docs-site &amp;&amp; npx tsx scripts/extract-skills.ts &amp;&amp; npm run build)\n</code></pre>\n<h3>Regeneration Workflow Step 5: Record What Changed</h3>\n<p>In the PR/commit notes, include:</p>\n<ul>\n<li>Which upstream docs/examples were used</li>\n<li>Which snippets/signatures were corrected</li>\n<li>Which tests/evals were run and their outcomes</li>\n</ul>\n<h4>Python plugin batch recipe: <code>azure-sdk-python</code></h4>\n<p>Use this when the request is \"regenerate all Python skills under azure-sdk-python.\"</p>\n<ol>\n<li><strong>Scope the exact targets first</strong></li>\n</ol>\n<pre><code># Canonical source of truth for Python plugin skills\nls .github/plugins/azure-sdk-python/skills/*/SKILL.md\n</code></pre>\n<ul>\n<li>Treat <code>.github/plugins/azure-sdk-python/skills/</code> as canonical.</li>\n<li>Keep <code>.github/skills/&lt;name&gt;</code> links in sync after edits (symlink check/fix step below).</li>\n</ul>\n<ol start=\"2\">\n<li><strong>For each skill, refresh from authoritative sources</strong></li>\n</ol>\n<ul>\n<li>Always use <code>microsoft-docs</code> MCP first for current Microsoft Learn API guidance.</li>\n<li>Verify the installed package version with <code>pip show &lt;package&gt;</code>, then inspect the installed package or official API reference to verify every symbol and signature used in snippets.</li>\n<li>For Azure SDK skills, prefer package overview + official SDK repo examples.</li>\n<li>For non-Azure Python skills in this plugin (for example <code>fastapi-router-py</code>, <code>pydantic-models-py</code>), keep language-specific best-practice variants and skip Azure-specific auth callouts when lifecycle/auth is not applicable.</li>\n</ul>\n<ol start=\"3\">\n<li><strong>Apply Python enforcement rules consistently</strong></li>\n</ol>\n<ul>\n<li>Keep the standard section order for Azure SDK Python skills.</li>\n<li>Ensure <code>## Authentication &amp; Lifecycle</code> starts with the required callout block (verbatim) when applicable.</li>\n<li>Ensure every client example uses <code>with</code> / <code>async with</code> lifecycle patterns.</li>\n<li>Ensure `## Best</li>\n</ul>\n","files":[{"path":"references/azure-sdk-patterns.md","sizeBytes":32551,"isText":true},{"path":"references/output-patterns.md","sizeBytes":4176,"isText":true},{"path":"references/workflows.md","sizeBytes":3196,"isText":true},{"path":"scripts/init_skill.py","sizeBytes":10863,"isText":true},{"path":"scripts/package_skill.py","sizeBytes":3288,"isText":true},{"path":"scripts/quick_validate.py","sizeBytes":3523,"isText":true},{"path":"SKILL.md","sizeBytes":68147,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"notes-only","suspicious":0,"notes":4,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-08-12T21:53:01.18379Z","sha256":"0755F0B4DDC2D87194CA0E6F7E6A446C45177530483793AD40C8216074E98565","sizeBytes":41283},"review":null,"source":{"repositoryUrl":"https://github.com/microsoft/skills","path":".github/skills/skill-creator","license":"MIT","commit":"23d0dac5f83f268166a17f0bc7dc6c73dc348a33","subtreeSha":"4A31DFB0B157C9808262C589AE3B11445D1EF07E9AE9F01373567BB1D21AECCE","lastSyncedAt":"2026-09-25T06:48:53.330584Z"},"reviewedAt":"2026-08-12T22:00:21.5869Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/microsoft/skills/tree/main/.github/skills/skill-creator"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install microsoft-skills@llmmart"},{"target":"git","command":"git clone https://github.com/microsoft/skills.git"}]}