All skills
aktsmm avatar

/microsoft-graph-gateway

@848fd9b
by yamapanaktsmm/agent-skills26 stars
4

Route Microsoft Graph work in this workspace. Use when users want to read or write Outlook mail, calendar events, contacts, OneDrive or SharePoint files, Teams, Planner, To Do, users, groups, directory data, or arbitrary Microsoft Graph endpoints from VS Code. Prefer WorkIQ for common read scenarios. Use Microsoft Graph for write actions and gap-read scenarios that need exact Graph properties, filters, permissions, or endpoints.

Use this Skill: https://skilld.dev/gh/aktsmm/agent-skills/microsoft-graph-gateway

This session only. Nothing lands on disk.

referencespermission-profiles.md

≈928 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Permission Profiles

This catalog defines initial permission profiles for interactive delegated use.

Design Rules

  • Default to delegated permissions.
  • Use least privilege first.
  • Do not mix application permissions into the same interactive profile.
  • If a request needs more privilege than the current profile, surface that escalation explicitly.

Initial Profiles

Profile Typical Areas Typical Delegated Scopes Notes
mail-read-basic inbox checks, light summaries Mail.Read Common read fallback when WorkIQ is insufficient
mail-write send, reply, move, update mail Mail.ReadWrite, Mail.Send Needed for most mail mutation flows
calendar-read-basic event lookups, availability checks Calendars.Read Common meeting and event reads
calendar-write create, update, or respond to events Calendars.ReadWrite Use for scheduling, updates, and accept or decline workflows
contacts-basic contact lookup and update Contacts.Read, Contacts.ReadWrite Split later if needed
files-read-basic OneDrive and simple file reads Files.Read Escalate only when user intent truly needs broader file reach
files-write upload, update, move personal files Files.ReadWrite Personal or signed-in user scope first
sharepoint-read-broad site, drive, or document reads beyond personal scope Sites.Read.All, optionally Files.Read.All Higher-risk profile; call out explicitly
sharepoint-write-broad site-level file mutation Sites.ReadWrite.All, optionally Files.ReadWrite.All Higher-risk profile; require stronger explanation
directory-read users, groups, apps, devices resource-specific least privilege based on endpoint Often tenant-sensitive; avoid broad fallback guesses
planner-tasks-write Planner, To Do, tasks endpoint-specific least privilege Keep separate because support patterns vary

Escalation Guidance

  • If the requested operation crosses from user-owned data into tenant-wide or site-wide data, call out the escalation before execution.
  • If the operation needs a broad directory or SharePoint scope, say so explicitly in the confirmation summary.
  • If the exact least-privileged scope is unclear, perform metadata lookup before attempting execution.

Future Split

This first version intentionally keeps the profile catalog compact. Split profiles further only when:

  • user-owned and tenant-wide operations frequently diverge
  • consent friction becomes high
  • the same profile is being used for too many unrelated operations

Source: SKILL.md on GitHub

1 alert4mo3 checks · Risk HIGH
  • Gen Agent Trust Hub4mo

    The skill acts as a gateway for Microsoft Graph, providing tools to read and write data across Microsoft 365. It includes functionality to download and execute an external runner tool from a third-party GitHub repository. While the skill implements some safety measures like write confirmation summaries and blocking delete operations, the practice of downloading and running external code at runtime from non-verified sources presents a significant security risk.

  • Socket4mo

    1 alert: gptAnomaly

  • Snyk4mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 848fd9b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 18 hours ago.

Activeupdated 3 months ago
user-invocable
true
metadata
{
  "author": "yamapan (https://github.com/aktsmm)"
}
Other metadata
argument-hint
Describe the Graph task, target resource, and any draft payload, endpoint, or constraints

README badge

README badge for aktsmm/agent-skills/microsoft-graph-gateway