All skills
aktsmm avatar

/microsoft-graph-gateway

@848fd9b
by yamapanaktsmm/agent-skills26 stars
4

Route Microsoft Graph work in this workspace. Use when users want to read or write Outlook mail, calendar events, contacts, OneDrive or SharePoint files, Teams, Planner, To Do, users, groups, directory data, or arbitrary Microsoft Graph endpoints from VS Code. Prefer WorkIQ for common read scenarios. Use Microsoft Graph for write actions and gap-read scenarios that need exact Graph properties, filters, permissions, or endpoints.

Use this Skill: https://skilld.dev/gh/aktsmm/agent-skills/microsoft-graph-gateway

This session only. Nothing lands on disk.

referencesprerequisites.md

≈554 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Prerequisites

Keep prerequisites short and explicit.

Required

  1. VS Code with GitHub Copilot Chat agent mode enabled
  2. PowerShell 7 or later for the current scaffold
  3. Network access to Microsoft Graph and Microsoft Entra sign-in endpoints
  4. A Microsoft Graph execution substrate such as merill/msgraph
  5. A signed-in Microsoft account with consent for the required delegated scopes
  6. For live write tests, the current tenant and client app must allow the required write scopes such as Mail.Send and Calendars.ReadWrite

Recommended

  1. msgraph available on PATH, or GRAPH_GATEWAY_RUNNER set
  2. A workspace-local runner install if you do not want to depend on global tools
  3. WorkIQ available for common read routing

Current Platform Note

  • Windows is supported through the PowerShell scripts directly.
  • macOS and Linux are supported through the pwsh-backed .sh wrappers in scripts/.
  • The current scaffold is cross-platform at the entrypoint level, but live behavior still depends on the installed runner and auth flow.

Light Setup Checklist

  1. Run the scaffold smoke test
  2. Install or point to a runner
  3. Check runner status
  4. Sign in to Graph
  5. Perform a read test before a write test

Write Test Note

  • A successful delegated sign-in does not guarantee write access.
  • Live mail and calendar writes can still fail with 403 ErrorAccessDenied if the current client app or tenant policy does not allow the requested write scopes.
  • If that happens, use a custom Entra ID app registration or a tenant-approved client configuration for live write validation.

Admin Approval Note

  • If the sign-in screen says that administrator approval is required for Microsoft Graph Command Line Tools, the tenant is blocking consent for the current client app.
  • In that case, re-signing alone is not enough.
  • Use one of these paths:
    • ask a tenant admin to approve the app and required delegated scopes
    • switch the runner to a tenant-approved custom app registration
  • Use New-GraphGatewayAppConfig.ps1 or custom-app.env.example to prepare the environment for a custom app quickly.

Source: SKILL.md on GitHub

1 alert4mo3 checks · Risk HIGH
  • Gen Agent Trust Hub4mo

    The skill acts as a gateway for Microsoft Graph, providing tools to read and write data across Microsoft 365. It includes functionality to download and execute an external runner tool from a third-party GitHub repository. While the skill implements some safety measures like write confirmation summaries and blocking delete operations, the practice of downloading and running external code at runtime from non-verified sources presents a significant security risk.

  • Socket4mo

    1 alert: gptAnomaly

  • Snyk4mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 848fd9b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 months ago
user-invocable
true
metadata
{
  "author": "yamapan (https://github.com/aktsmm)"
}
Other metadata
argument-hint
Describe the Graph task, target resource, and any draft payload, endpoint, or constraints

README badge

README badge for aktsmm/agent-skills/microsoft-graph-gateway