返回 Skill 列表
extension
分类: 开发与工程无需 API Key

azure-resource-lookup

列出、查找并显示Azure资源。回答诸如“列出我的虚拟机”、“显示我的存储账户”、“列出网站”、“查找容器应用”、“我有哪些资源”等类似查询,适用于任何类型的Azure资源。用途包括:列出资源、列出虚拟机、列出VM、列出存储账户、列出网站、列出Web应用、列出容器应用、显示资源、查找资源、我有哪些资源、列出资源组中的资源、列出订阅中的资源、按标签查找资源、查找孤立资源、资源清单、按类型计数资源、跨订阅资源查询、Azure资源图、资源发现、列出容器注册表、列出SQL服务器、列出密钥保管库、显示资源组、列出应用程序服务、跨订阅查找资源、查找未附加的磁盘、标签分析。不要用于:部署资源(使用azure-deploy)、创建或修改资源、成本优化(使用azure-cost-optimization)、编写应用程序代码、非Azure云。

person作者: jakexiaohubgithub

Azure Resource Lookup

List, find, and discover Azure resources of any type across subscriptions and resource groups. Use Azure Resource Graph (ARG) for fast, cross-cutting queries when dedicated MCP tools don't cover the resource type.

When to Use This Skill

Use this skill when the user wants to:

  • List resources of any type (VMs, web apps, storage accounts, container apps, databases, etc.)
  • Show resources in a specific subscription or resource group
  • Query resources across multiple subscriptions or resource types
  • Find orphaned resources (unattached disks, unused NICs, idle IPs)
  • Discover resources missing required tags or configurations
  • Get a resource inventory spanning multiple types
  • Find resources in a specific state (unhealthy, failed provisioning, stopped)
  • Answer "what resources do I have?" or "show me my Azure resources"

💡 Tip: For single-resource-type queries, first check if a dedicated MCP tool can handle it (see routing table below). If none exists, use Azure Resource Graph.

Quick Reference

| Property | Value | |----------|-------| | Query Language | KQL (Kusto Query Language subset) | | CLI Command | az graph query -q "<KQL>" -o table | | Extension | az extension add --name resource-graph | | MCP Tool | extension_cli_generate with intent for az graph query | | Best For | Cross-subscription queries, orphaned resources, tag audits |

MCP Tools

| Tool | Purpose | When to Use | |------|---------|-------------| | extension_cli_generate | Generate az graph query commands | Primary tool — generate ARG queries from user intent | | mcp_azure_mcp_subscription_list | List available subscriptions | Discover subscription scope before querying | | mcp_azure_mcp_group_list | List resource groups | Narrow query scope |

Workflow

Step 1: Check for a Dedicated MCP Tool

For single-resource-type queries, check if a dedicated MCP tool can handle it:

| Resource Type | MCP Tool | Coverage | |---|---|---| | Virtual Machines | compute | ✅ Full — list, details, sizes | | Storage Accounts | storage | ✅ Full — accounts, blobs, tables | | Cosmos DB | cosmos | ✅ Full — accounts, databases, queries | | Key Vault | keyvault | ⚠️ Partial — secrets/keys only, no vault listing | | SQL Databases | sql | ⚠️ Partial — requires resource group name | | Container Registries | acr | ✅ Full — list registries | | Kubernetes (AKS) | aks | ✅ Full — clusters, node pools | | App Service / Web Apps | appservice | ❌ No list command — use ARG | | Container Apps | — | ❌ No MCP tool — use ARG | | Event Hubs | eventhubs | ✅ Full — namespaces, hubs | | Service Bus | servicebus | ✅ Full — queues, topics |

If a dedicated tool is available with full coverage, use it. Otherwise proceed to Step 2.

Step 2: Generate the ARG Query

Use extension_cli_generate to build the az graph query command:

mcp_azure_mcp_extension_cli_generate
  intent: "query Azure Resource Graph to <user's request>"
  cli-type: "az"

See Azure Resource Graph Query Patterns for common KQL patterns.

Step 3: Execute and Format Results

Run the generated command. Use --query (JMESPath) to shape output:

az graph query -q "<KQL>" --query "data[].{name:name, type:type, rg:resourceGroup}" -o table

Use --first N to limit results. Use --subscriptions to scope.

Error Handling

| Error | Cause | Fix | |-------|-------|-----| | resource-graph extension not found | Extension not installed | az extension add --name resource-graph | | AuthorizationFailed | No read access to subscription | Check RBAC — need Reader role | | BadRequest on query | Invalid KQL syntax | Verify table/column names; use =~ for case-insensitive type matching | | Empty results | No matching resources or wrong scope | Check --subscriptions flag; verify resource type spelling |

Constraints

  • Always use =~ for case-insensitive type matching (types are lowercase)
  • Always scope queries with --subscriptions or --first for large tenants
  • Prefer dedicated MCP tools for single-resource-type queries
  • Never use ARG for real-time monitoring (data has slight delay)
  • Never attempt mutations through ARG (read-only)