All skills
aktsmm avatar

/microsoft-graph-gateway

@848fd9b
by yamapanaktsmm/agent-skills26 stars
4

Route Microsoft Graph work in this workspace. Use when users want to read or write Outlook mail, calendar events, contacts, OneDrive or SharePoint files, Teams, Planner, To Do, users, groups, directory data, or arbitrary Microsoft Graph endpoints from VS Code. Prefer WorkIQ for common read scenarios. Use Microsoft Graph for write actions and gap-read scenarios that need exact Graph properties, filters, permissions, or endpoints.

Use this Skill: https://skilld.dev/gh/aktsmm/agent-skills/microsoft-graph-gateway

This session only. Nothing lands on disk.

referencescurated-tools-first-wave.md

≈922 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Curated Tools First Wave

This document defines the first convenience tools that sit above the raw Graph executor.

Goal

  • Cover high-frequency productivity actions with short, predictable language.
  • Keep the list intentionally small so the gateway does not explode into hundreds of brittle wrappers.
  • Preserve the raw executor as the escape hatch for everything else.

First-Wave Tool Set

Tool Purpose Notes
list-messages Read recent messages with minimal projection Prefer WorkIQ first for simple inbox reads
get-message Read a specific message in detail Use Graph when exact properties or body content matter
send-message Send a new email Write confirmation required
reply-message Reply or reply-all Write confirmation required
list-events Read upcoming events Prefer WorkIQ first for simple schedule reads
create-event Create a meeting or appointment Write confirmation required
update-event Reschedule or modify an event Write confirmation required
accept-event Accept a meeting request Write confirmation required
decline-event Decline a meeting request Write confirmation required
tentative-event Tentatively accept a meeting request Write confirmation required
check-availability Inspect free/busy windows Usually Graph directly
search-files Search OneDrive or SharePoint files Prefer WorkIQ first for broad discovery
get-file Read or download a file reference Decide later whether content stays inline or external
upload-file Upload or replace content Write confirmation required
list-contacts Read contacts Convenience wrapper over common contact views
get-user-or-group Read directory targets by exact identifier Helps avoid broad raw directory calls for common cases
raw-graph-call Escape hatch for arbitrary Graph execution Always available for unsupported surfaces

Not In The First Wave

  • full Teams surface
  • Planner plan and task management wrappers
  • To Do wrappers
  • lifecycle and webhook orchestration
  • broad SharePoint administration wrappers
  • delete wrappers

These should remain raw-Graph-first until stable usage patterns emerge.

Meeting responses are now important enough to treat as first-wave conveniences because they are common, semantically stable, and easy to confirm safely.

Selection Criteria

A workflow belongs in the first wave only if it is:

  1. common
  2. high-value
  3. semantically stable
  4. easy to confirm safely
  5. likely to benefit from shorter language than a raw endpoint call

Naming Principle

  • Use action-oriented names.
  • Prefer resource-neutral verbs only when the scope is obvious.
  • Avoid adding multiple aliases for the same underlying action.

Source: SKILL.md on GitHub

1 alert4mo3 checks · Risk HIGH
  • Gen Agent Trust Hub4mo

    The skill acts as a gateway for Microsoft Graph, providing tools to read and write data across Microsoft 365. It includes functionality to download and execute an external runner tool from a third-party GitHub repository. While the skill implements some safety measures like write confirmation summaries and blocking delete operations, the practice of downloading and running external code at runtime from non-verified sources presents a significant security risk.

  • Socket4mo

    1 alert: gptAnomaly

  • Snyk4mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 848fd9b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
user-invocable
true
metadata
{
  "author": "yamapan (https://github.com/aktsmm)"
}
Other metadata
argument-hint
Describe the Graph task, target resource, and any draft payload, endpoint, or constraints

README badge

README badge for aktsmm/agent-skills/microsoft-graph-gateway