# Correct. Deployable. Quietly expensive.

> Copilot writes the convenient Azure, not yours.

- **Format:** short video, 9 steps, ~51 seconds
- **Topic:** An Azure Copilot Skill for Bicep — why Copilot writes correct but insecure and expensive infrastructure by default, and how a SKILL.md with security and cost rules makes it write private, keyless, tagged, cheap resources in the editor, before Azure Policy or the bill.
- **Author:** Suthahar Jegatheesan (MSDEVBUILD)
- **Category:** GitHub Copilot · copilot
- **Published:** 2026-02-22
- **Tags:** githubcopilot, azure, bicep, infrastructureascode, finops, cloudsecurity, devops, msdevbuild
- **Canonical URL:** https://blog.msdevbuild.com/shorts/copilot-skill-azure-bicep-guardrails/

---
## What you'll learn

- Why Copilot leaves public access on and keys in the output
- How a Skill makes the secure, cheap choice the default
- Where a Skill sits next to Azure Policy and Resource Graph

## Understand it one step at a time

### 1. Provision storage

A developer asks Copilot for a storage account in the test environment.

### 2. The convenient default

Public network access on, a key in the output, no diagnostics, no tags.

### 3. Four months later

A P1v3 plan copied from prod has been running in test all along.

### 4. Write the baseline Skill

Security floor and cost ceiling, once, in .github/skills/azure-service-baseline.

### 5. Security rules

Managed Identity over keys, secrets in Key Vault, public access disabled.

### 6. Cost rules

Cheap tiers by default outside prod. Premium needs a written reason.

### 7. Same prompt, again

The Skill loads. Private, keyless, logged, tagged, cheap.

### 8. The last gate stays quiet

Policy and the weekly Resource Graph query rarely fire, because the first gate held.

### 9. Guardrails in the editor

Security floor and cost ceiling in a Skill, with Policy and Resource Graph behind it.

---

## The takeaway

**Guardrails, not generated code.**

The cheapest cost fix is the one Copilot never suggests in the first place.
