Each Python file contains one repository-owned public function mapped by
.x/x.yml. Custom skills own Azure CLI target inference, regression policy,
AAZ source routing, and the CLI-to-Extensions handoff. Authentication,
sensitive-data checks, repository scoping, and narrow GitHub mutations remain
in the approved base primitives. Repository directory discovery resolves roots
and branches from central trusted configuration rather than repository-supplied
arguments. Markdown files are never executable.