All skills
microsoft avatar

/teams-app-developer

@0bef15b
by microsoftmicrosoft/skills3.1k stars
351

Builds, tests, and deploys Microsoft 365 apps and agents for Teams and Copilot. Includes sub-skills for project creation, local testing, cloud deployment, troubleshooting, and Slack-to-Teams migration. USE FOR: Teams agent, bot, tab, message extension, Declarative Agents, Custom Engine Agents, local testing, Agents Playground, Azure resource provision, remote deployment, Slack to Teams migration, cross-platform bot development, Block Kit to Adaptive Cards conversion. DO NOT USE FOR: general web development, non-bot/non-Teams projects.

Use this Skill: https://skilld.dev/gh/microsoft/skills/teams-app-developer

This session only. Nothing lands on disk.

expertssecurityindex.md

≈307 tokens on demand. Your agent reads this file only when SKILL.md points to it.

security-router

purpose

Route security-hardening tasks to the minimal set of micro-expert files. Read only the clusters that match the user's request.

task clusters

Input Validation

When: sanitizing user input, preventing injection, XSS prevention, content validation, PII handling Read:

  • input-validation-ts.md Cross-domain deps: ../teams/ui.adaptive-cards-ts.md (card action payloads that need validation), ../teams/ai.function-calling-implementation-ts.md (AI function parameter validation)

Secrets Management

When: secrets, credentials, API keys, Key Vault, environment variables, secret rotation Read:

  • secrets-ts.md Cross-domain deps: ../teams/runtime.app-init-ts.md (App constructor credentials), ../bridge/infra-secrets-config-ts.md (only if bridging between AWS and Azure)

General Hardening

When: broad security review, security audit, hardening checklist, defense in depth Read:

  • input-validation-ts.md
  • secrets-ts.md Cross-domain deps: ../teams/mcp.security-ts.md (only if using MCP)

combining rule

If a request covers both input validation and secrets, read both files (same as "General Hardening").

file inventory

input-validation-ts.md | secrets-ts.md

Source: SKILL.md on GitHub

1 alert3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub3mo

    This skill provides a comprehensive developer guide for building Microsoft 365 agents and Teams applications. It includes several security considerations such as handling untrusted user input, using dynamic execution in examples, and reading sensitive local files for protocol requirements. These patterns are presented with appropriate security warnings and architectural mitigations. See detailed analysis for more context.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: HIGH · 1 issue

Signed by skilld at 0bef15b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 3 months ago

README badge

README badge for microsoft/skills/teams-app-developer