Skip to content
Back to skills

Azure Resource Lookup Ms

ASecurity

'List, find, and show Azure resources. Answers "list my VMs", "show my

  • 6 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 10, 2026
devopsbashsqlnodekubernetesazuredatabase

Works with

  • cli
  • mcp

Security analysis

A100/100

Scanned September 10, 2026

npx -y skills add JantonioFC/skillsbank --skill azure-resource-lookup-ms --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Azure Resource Lookup Ms?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Azure Resource Lookup Ms
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/jantoniofc-azure-resource-lookup-ms/badge)](https://www.skillsdirectory.com/skills/jantoniofc-azure-resource-lookup-ms)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: azure-resource-lookup-ms
description: 'List, find, and show Azure resources. Answers "list my VMs", "show my
  storage accounts", "list websites",

  "find container apps", "what resources do I have", and similar queries for any Azure
  resource type.

  USE FOR: list resources, list virtual machines, list VMs, list storage accounts,
  lis...'
risk: safe
source: community
license: MIT
---
# Azure Resource Lookup

List, find, and discover Azure resources of any type across subscriptions and resource groups. Use Azure Resource Graph (ARG) for fast, cross-cutting queries when dedicated MCP tools don't cover the resource type.

## When to Use This Skill

Use this skill when the user wants to:
- **List resources** of any type (VMs, web apps, storage accounts, container apps, databases, etc.)
- **Show resources** in a specific subscription or resource group
- Query resources **across multiple subscriptions** or resource types
- Find **orphaned resources** (unattached disks, unused NICs, idle IPs)
- Discover resources **missing required tags** or configurations
- Get a **resource inventory** spanning multiple types
- Find resources in a **specific state** (unhealthy, failed provisioning, stopped)
- Answer "**what resources do I have?**" or "**show me my Azure resources**"

> πŸ’‘ **Tip:** For single-resource-type queries, first check if a dedicated MCP tool can handle it (see routing table below). If none exists, use Azure Resource Graph.

## Quick Reference

| Property | Value |
|----------|-------|
| **Query Language** | KQL (Kusto Query Language subset) |
| **CLI Command** | `az graph query -q "<KQL>" -o table` |
| **Extension** | `az extension add --name resource-graph` |
| **MCP Tool** | `extension_cli_generate` with intent for `az graph query` |
| **Best For** | Cross-subscription queries, orphaned resources, tag audits |

## MCP Tools

| Tool | Purpose | When to Use |
|------|---------|-------------|
| `extension_cli_generate` | Generate `az graph query` commands | Primary tool β€” generate ARG queries from user intent |
| `mcp_azure_mcp_subscription_list` | List available subscriptions | Discover subscription scope before querying |
| `mcp_azure_mcp_group_list` | List resource groups | Narrow query scope |

## Workflow

### Step 1: Check for a Dedicated MCP Tool

For single-resource-type queries, check if a dedicated MCP tool can handle it:

| Resource Type | MCP Tool | Coverage |
|---|---|---|
| Virtual Machines | `compute` | βœ… Full β€” list, details, sizes |
| Storage Accounts | `storage` | βœ… Full β€” accounts, blobs, tables |
| Cosmos DB | `cosmos` | βœ… Full β€” accounts, databases, queries |
| Key Vault | `keyvault` | ⚠️ Partial β€” secrets/keys only, no vault listing |
| SQL Databases | `sql` | ⚠️ Partial β€” requires resource group name |
| Container Registries | `acr` | βœ… Full β€” list registries |
| Kubernetes (AKS) | `aks` | βœ… Full β€” clusters, node pools |
| App Service / Web Apps | `appservice` | ❌ No list command β€” use ARG |
| Container Apps | β€” | ❌ No MCP tool β€” use ARG |
| Event Hubs | `eventhubs` | βœ… Full β€” namespaces, hubs |
| Service Bus | `servicebus` | βœ… Full β€” queues, topics |

If a dedicated tool is available with full coverage, use it. Otherwise proceed to Step 2.

### Step 2: Generate the ARG Query

Use `extension_cli_generate` to build the `az graph query` command:

```yaml
mcp_azure_mcp_extension_cli_generate
  intent: "query Azure Resource Graph to <user's request>"
  cli-type: "az"
```

See [Azure Resource Graph Query Patterns](references/azure-resource-graph.md) for common KQL patterns.

### Step 3: Execute and Format Results

Run the generated command. Use `--query` (JMESPath) to shape output:

```bash
az graph query -q "<KQL>" --query "data[].{name:name, type:type, rg:resourceGroup}" -o table
```

Use `--first N` to limit results. Use `--subscriptions` to scope.

## Error Handling

| Error | Cause | Fix |
|-------|-------|-----|
| `resource-graph extension not found` | Extension not installed | `az extension add --name resource-graph` |
| `AuthorizationFailed` | No read access to subscription | Check RBAC β€” need Reader role |
| `BadRequest` on query | Invalid KQL syntax | Verify table/column names; use `=~` for case-insensitive type matching |
| Empty results | No matching resources or wrong scope | Check `--subscriptions` flag; verify resource type spelling |

## Constraints

- βœ… **Always** use `=~` for case-insensitive type matching (types are lowercase)
- βœ… **Always** scope queries with `--subscriptions` or `--first` for large tenants
- βœ… **Prefer** dedicated MCP tools for single-resource-type queries
- ❌ **Never** use ARG for real-time monitoring (data has slight delay)
- ❌ **Never** attempt mutations through ARG (read-only)

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…