All skills
aktsmm avatar

/microsoft-graph-gateway

@848fd9b
by yamapanaktsmm/agent-skills26 stars
4

Route Microsoft Graph work in this workspace. Use when users want to read or write Outlook mail, calendar events, contacts, OneDrive or SharePoint files, Teams, Planner, To Do, users, groups, directory data, or arbitrary Microsoft Graph endpoints from VS Code. Prefer WorkIQ for common read scenarios. Use Microsoft Graph for write actions and gap-read scenarios that need exact Graph properties, filters, permissions, or endpoints.

Use this Skill: https://skilld.dev/gh/aktsmm/agent-skills/microsoft-graph-gateway

This session only. Nothing lands on disk.

referencesrouting-and-safety.md

≈399 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Routing And Safety

Read Responsibility

  • Prefer WorkIQ for common read requests that map naturally to inbox, meetings, and file discovery.
  • Use Microsoft Graph when WorkIQ cannot answer, lacks detail, or the user needs exact Graph semantics.
  • Go directly to Graph for:
    • endpoint discovery
    • permission lookup
    • exact filters or projections
    • directory, Teams, Planner, To Do, reports, or schema-heavy requests

Write Responsibility

  • All writes go through Microsoft Graph.
  • Treat the following as writes even if they feel lightweight:
    • send
    • create
    • update
    • reply
    • forward
    • move
    • upload
    • respond
    • assign

Confirmation Policy

Before any write, provide a short confirmation summary with:

  1. target resource
  2. intended action
  3. payload intent in plain language
  4. noteworthy risk, if any

Do not execute until the user confirms.

Delete Policy

  • Block delete by default in the first implementation.
  • If delete is later enabled, require a stronger confirmation step than standard writes.

Permission Policy

  • Default to delegated permissions for interactive use.
  • Keep application permissions in a separate future profile.
  • Use least privilege and avoid broad directory or file scopes unless the operation requires them.

Performance Policy

  • Use $select whenever practical.
  • Use minimal response handling for write operations when supported.
  • Respect Retry-After on throttling.
  • Prefer delta query and change notifications over polling for sync scenarios.
  • Keep JSON batching within the platform limit of 20 requests.

Source: SKILL.md on GitHub

1 alert4mo3 checks · Risk HIGH
  • Gen Agent Trust Hub4mo

    The skill acts as a gateway for Microsoft Graph, providing tools to read and write data across Microsoft 365. It includes functionality to download and execute an external runner tool from a third-party GitHub repository. While the skill implements some safety measures like write confirmation summaries and blocking delete operations, the practice of downloading and running external code at runtime from non-verified sources presents a significant security risk.

  • Socket4mo

    1 alert: gptAnomaly

  • Snyk4mo

    Risk: MEDIUM · 1 issue

Signed by skilld at 848fd9b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 18 hours ago.

Activeupdated 3 months ago
user-invocable
true
metadata
{
  "author": "yamapan (https://github.com/aktsmm)"
}
Other metadata
argument-hint
Describe the Graph task, target resource, and any draft payload, endpoint, or constraints

README badge

README badge for aktsmm/agent-skills/microsoft-graph-gateway