All skills
aktsmm avatar

/microsoft-graph-gateway

@848fd9b
by yamapanaktsmm/agent-skills26 stars
4

Route Microsoft Graph work in this workspace. Use when users want to read or write Outlook mail, calendar events, contacts, OneDrive or SharePoint files, Teams, Planner, To Do, users, groups, directory data, or arbitrary Microsoft Graph endpoints from VS Code. Prefer WorkIQ for common read scenarios. Use Microsoft Graph for write actions and gap-read scenarios that need exact Graph properties, filters, permissions, or endpoints.

Use this Skill: https://skilld.dev/gh/aktsmm/agent-skills/microsoft-graph-gateway

This session only. Nothing lands on disk.

referencesraw-execution-contract.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Raw Execution Contract

This document defines the generic Graph executor that preserves full reach across Microsoft Graph.

Purpose

  • Reach arbitrary Microsoft Graph endpoints without waiting for a curated tool.
  • Keep a stable execution contract even if the backend substrate changes.
  • Preserve enough structure for routing, confirmation, auditing, and future UI work.

Input Shape

The raw executor should collect the following logical fields before execution.

Field Required Description
method Yes GET, POST, PATCH, or PUT in the first implementation
path Yes Relative Graph path such as /me/messages or /users/{id}/calendar/events
apiVersion No v1.0 by default, beta only when justified
query No Structured query options such as $select, $filter, $expand, $top, $orderby
headers No Explicit headers such as Prefer or ConsistencyLevel
body No JSON payload for write operations
permissionProfile Yes Named profile chosen from the permission catalog
intentSummary Yes Short plain-language description of what the call is meant to do
isWrite Yes Derived from method and semantic action

Output Shape

The raw executor should normalize its result to the following logical shape.

Field Description
statusCode HTTP status code
requestSummary Method, version, and path summary
responseBody Parsed JSON body or raw content summary
nextAction Suggested follow-up such as pagination, consent, retry, or none
warnings Throttling, beta usage, broad permission use, large response, or unsupported semantics

Execution Rules

  1. Default to v1.0.
  2. Use beta only when the required feature does not exist in v1.0.
  3. Treat POST, PATCH, and PUT as writes.
  4. Reject DELETE in the first implementation.
  5. Require an explicit permission profile before execution.
  6. Encourage $select for entity reads when practical.
  7. Respect Retry-After and surface throttling guidance.
  8. Preserve the exact path and query semantics instead of silently rewriting them.

Confirmation Rules For Raw Writes

Before a raw write executes, the confirmation summary should include:

  1. the target resource path
  2. the action in plain language
  3. the important body fields being changed or created
  4. whether beta is in use
  5. whether the permission profile is broader than usual

Why This Matters

  • Curated tools will never cover the full Graph surface.
  • The raw executor is what makes the gateway truly "all reachable" instead of just "many convenience commands."

Current Script Mapping

Source: SKILL.md on GitHub

1 alert4mo3 checks · Risk HIGH
  • Gen Agent Trust Hub4mo

    The skill acts as a gateway for Microsoft Graph, providing tools to read and write data across Microsoft 365. It includes functionality to download and execute an external runner tool from a third-party GitHub repository. While the skill implements some safety measures like write confirmation summaries and blocking delete operations, the practice of downloading and running external code at runtime from non-verified sources presents a significant security risk.

  • Socket4mo

    1 alert: gptAnomaly

  • Snyk4mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 848fd9b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 19 hours ago.

Activeupdated 3 months ago
user-invocable
true
metadata
{
  "author": "yamapan (https://github.com/aktsmm)"
}
Other metadata
argument-hint
Describe the Graph task, target resource, and any draft payload, endpoint, or constraints

README badge

README badge for aktsmm/agent-skills/microsoft-graph-gateway