Msal Auth Code Flow
AzureAD/microsoft-authentication-library-for-dotnet
Authorization Code Flow for web applications using MSAL.NET confidential client to sign in users and access APIs on their behalf
A skill your agent uses when operating Microsoft Power Automate cloud flows from code — create, enable, update, list or delete via the Dataverse Web API (workflow table, category 5) with Entra ID…
$ npx skills add ericrisco/rsc-harness --skill power-automate -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness power-automate --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/power-automate .claude/skills/power-automate && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "power-automate" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/power-automate into .claude/skills/power-automate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "power-automate", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/power-automateType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill power-automate -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness power-automate --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/power-automate .agents/skills/power-automate && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "power-automate" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/power-automate into .agents/skills/power-automate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "power-automate", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill power-automate -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness power-automate --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/power-automate .cursor/skills/power-automate && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "power-automate" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/power-automate into .cursor/skills/power-automate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "power-automate", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/power-automate--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill power-automate -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness power-automate --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/power-automate .gemini/skills/power-automate && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "power-automate" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/power-automate into .gemini/skills/power-automate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "power-automate", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness power-automateInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill power-automate -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/power-automate .github/skills/power-automate && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "power-automate" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/power-automate into .github/skills/power-automate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "power-automate", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill power-automate -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness power-automate --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/power-automate .opencode/skills/power-automate && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "power-automate" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/power-automate into .opencode/skills/power-automate/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "power-automate", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
power-automateA skill your agent uses when operating Microsoft Power Automate cloud flows from code — create, enable, update, list or delete via the Dataverse Web API (workflow table, category 5) with Entra ID…
Power Automate is an agent skill from ericrisco/rsc-harness. Use when operating Microsoft Power Automate cloud flows from code — create, enable, update, list or delete via the Dataverse Web API (workflow table, category 5) with Entra ID OAuth2, plus run-history debugging. NOT designing the flow definition (that is automation-flows), NOT picking a platform by billing model (that is automation-strategy).
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/dataverse-web-api.md`).
It sits in Development, covering OAuth and OpenID Connect. It works with Power Automate and Microsoft Entra ID. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e3d5b33. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlpython3From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
contoso.crm.dynamics.comschema.management.azure.comlogin.microsoftonline.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
PA_CLIENT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Power Automate loads about 3.1k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 1,295 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Put these in `.env` (never inline a secret in a flow or a script):ecret | Env-specific, leaks in source | `.env`: `PA_DATAVERSE_URL`, `PA_TENANT_ID`, `PA_CLIENT_ID`, `PA_CLIENT_SECRET` |- [ ] `.env` set: `PA_DATAVERSE_URL` (no trailing slash), `PA_TENANT_ID`, `PA_CLIENT_ID`, `PA_CLIENT_SECRET`.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ericrisco/rsc-harness at commit e3d5b33, republished under its MIT licence (© ericrisco). 1,295 words, ~3,134 tokens.
.claude/skills/power-automate/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.Drive Microsoft Power Automate cloud flows from code: create, enable, update, list, and delete them, plus pull run history for debugging. This skill operates the live surface. Deciding what the flow should do and shaping its trigger→actions→error definition is design — that lives in ../automation-flows/SKILL.md; this skill wraps that definition, ships it, and manages it.
Read these three facts before you write a line — they set the boundary of what is even possible:
api.flow.microsoft.com is unsupported. Microsoft's own words: use it "at your own risk," it is subject to breaking changes. The supported programmatic surface is the Dataverse Web API (or the .NET SDK) against the workflow table. For admin-style operations the Power Automate Management connector is the other supported path.api.powerplatform.com) is maturing fast. It already lists cloud flows (api-version 2024-10-01) and its Inventory API went GA in early 2026. It may eventually supersede the Dataverse path for flow management. Treat the Dataverse-vs-Power-Platform-API split as fast-moving — verify the current recommendation at author time.Everything runs against your org's Dataverse Web API. Base URL: https://{org}.{region}.dynamics.com/api/data/v9.2 (find yours under Power Platform admin → your environment → developer resources). Auth is OAuth2 / Entra ID — a user token or, for CI, a service principal (app registration). For a service principal the org needs a Dataverse application user mapped to that app plus a security role; the token audience is the Dataverse URL. Full setup, including the delegated user_impersonation vs app .default scope split and the 401/403 causes, is in references/entra-auth-setup.md.
Put these in .env (never inline a secret in a flow or a script):
PA_DATAVERSE_URL=https://contoso.crm.dynamics.com # no trailing slash, no /api/...
PA_TENANT_ID=<entra-tenant-guid>
PA_CLIENT_ID=<app-registration-client-id>
PA_CLIENT_SECRET=<app-registration-secret> # service-principal flow onlyWhen to use the REST API vs the MCP:
| You need to… | Use | Why |
|---|---|---|
| Create / enable / update / delete / list flows | Dataverse Web API | The only supported CRUD surface; scriptable, CI-friendly, service-principal auth. |
| Read a flow's action-level run inputs/outputs to debug a failure | FlowStudio MCP (third-party) | Dataverse exposes run records (flowrun table) but not per-action I/O; the MCP does. See references/flowstudio-mcp-and-limits.md. |
| Admin-scope operations (turn on/off across an environment) | Power Automate Management connector | Supported management surface when raw Dataverse is awkward. |
FlowStudio MCP is NOT Microsoft-affiliated — it is a de-facto third-party server (mcp.flowstudio.app/mcp). Microsoft's own MCP story is Copilot Studio consuming MCP servers and a Dataverse MCP, neither of which authors Power Automate flows. Flag the third-party dependency to anyone before wiring it into a pipeline.
workflow table — the data modelCloud flows are rows in the Dataverse Process (workflow) table. The columns that matter:
| Column | Meaning | Values you use |
|---|---|---|
category | Kind of process | 5 = modern cloud flow (automated / instant / scheduled). (0 classic workflow, 4 business process flow, 6 desktop flow.) |
type | Definition vs template | 1 = Definition (a runnable flow). |
statecode | On/off state | 0 = Draft (Off), 1 = Activated (On), 2 = Suspended. |
name | Display name | your string |
primaryentity | Bound table | "none" for automated/instant/scheduled flows |
clientdata | The flow itself | string-encoded JSON (see below) |
workflowid | GUID key | returned on create; used in workflows({id}) |
List the cloud flows that are on:
curl -s "$PA_DATAVERSE_URL/api/data/v9.2/workflows?\$filter=category eq 5 and statecode eq 1&\$select=name,statecode,type,workflowid" \
-H "Authorization: Bearer $TOKEN" -H "OData-Version: 4.0" -H "Accept: application/json"clientdata — the payload, and the trap that bites everyoneclientdata is a JSON string, not a nested JSON object. It is the serialized form of:
{
"properties": {
"connectionReferences": { "shared_commondataserviceforapps": { "runtimeSource": "embedded", "connection": {}, "api": { "name": "shared_commondataserviceforapps" } } },
"definition": { "$schema": "https://schema.management.azure.com/providers/Microsoft.Logic/schemas/2016-06-01/workflowdefinition.json#", "contentVersion": "1.0.0.0", "triggers": { }, "actions": { } }
},
"schemaVersion": "1.0.0.0"
}Two load-bearing parts:
definition — a Logic Apps workflow definition: triggers (exactly one) then actions. This is the design artifact. Do not invent it from scratch here — get the trigger→actions→branch→error shape from ../automation-flows/SKILL.md, then drop it into definition. Fastest reliable way to get a real one: build the flow once in the maker portal, export the solution, and copy its clientdata.connectionReferences — the map from the definition's connectors to actual connections. A flow whose connection references are not authorized will not turn on. In a solution these are connection-reference records the target environment must resolve; unresolved references are the #1 reason a PATCH statecode=1 "succeeds" but the flow never runs.The trap: clientdata must be escaped into a string before it goes in the request body — a nested object is rejected. In a script, JSON.stringify(clientDataObject) and assign the result; do not paste the object raw. Full annotated example — plus the endpoint cheat-sheet (token, list/filter, create, enable, update, delete, ExportSolution, share), OData headers and error handling — in references/dataverse-web-api.md.
1. Get a token (service-principal / client-credentials shown):
TOKEN=$(curl -s -X POST "https://login.microsoftonline.com/$PA_TENANT_ID/oauth2/v2.0/token" \
-d "grant_type=client_credentials" -d "client_id=$PA_CLIENT_ID" \
-d "client_secret=$PA_CLIENT_SECRET" -d "scope=$PA_DATAVERSE_URL/.default" \
| python3 -c "import sys,json;print(json.load(sys.stdin)['access_token'])")2. Create the flow (comes up statecode=0, Off — expected):
curl -s -i -X POST "$PA_DATAVERSE_URL/api/data/v9.2/workflows" \
-H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
-H "OData-Version: 4.0" \
-d '{ "category": 5, "type": 1, "name": "Nightly sync", "primaryentity": "none", "clientdata": "<string-encoded JSON>" }'
# → 204 No Content. The workflowid is in the OData-EntityId response header:
# OData-EntityId: .../workflows(00aa00aa-bb11-cc22-dd33-44ee44ee44ee)3. Validate before enabling. Read it back, confirm category/type are right, and confirm every connectionReferences entry resolves to an authorized connection in this environment. Enabling a flow with dangling connections is the classic silent failure.
4. Enable — flip statecode to 1 (use If-Match: * for the update):
curl -s -X PATCH "$PA_DATAVERSE_URL/api/data/v9.2/workflows(<workflowid>)" \
-H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json" \
-H "OData-Version: 4.0" -H "If-Match: *" \
-d '{ "statecode": 1 }'
# → 204 No Content5. Manage — update the definition or owner with the same PATCH (send only the fields you change; to reassign use "ownerid@odata.bind": "systemusers(<id>)"). To turn a flow off, PATCH statecode=0.
6. Delete — irreversible; export first. There is no undo on DELETE. Before deleting, export the containing solution (POST /api/data/v9.2/ExportSolution → base64 zip you save to source control), so the flow can be reimported:
curl -s -X DELETE "$PA_DATAVERSE_URL/api/data/v9.2/workflows(<workflowid>)" \
-H "Authorization: Bearer $TOKEN"
# → 204 No ContentDebug a run — Dataverse's flowrun table lists run records but not per-action I/O. To see which action failed and with what payload, use FlowStudio MCP: list_live_flows → get_live_flow_runs → get_live_flow_run_action_outputs. See references/flowstudio-mcp-and-limits.md.
Power Automate is Microsoft's iPaaS across M365 and Dynamics; flows live in Dataverse and glue Outlook, Teams, SharePoint, Dynamics, and hundreds of connectors. This skill is for when the automation genuinely is a Power Automate flow you must operate by code. When it isn't:
../api-connector-builder/SKILL.md (there is no first-party MS-Graph skill), or ../google-workspace/SKILL.md for the Google equivalent. Same route for a general typed client with auth/pagination/backoff — this skill uses the Dataverse endpoints surgically, it does not build a client.../automation-strategy/SKILL.md, before you commit to operating here.../webhooks/SKILL.md; this skill triggers and operates flows, it does not build the receiver.| Anti-pattern | Why it bites | Do instead |
|---|---|---|
| Trying to CRUD a My Flow by code | Unsupported — silently impossible, not a bug you can fix | Move it into a Dataverse solution, or drive it by hand |
clientdata sent as a nested object | Request rejected; the column expects an escaped string | Serialize (JSON.stringify) the definition+connectionReferences before sending |
PATCH statecode=1 "worked" but the flow never runs | Connection references unresolved/unauthorized in the target environment | Authorize every connection reference before enabling; validate on read-back |
Building against api.flow.microsoft.com | Unsupported; breaks without warning | Dataverse Web API, or the Power Automate Management connector |
DELETE with no export | No undo; the flow and its history are gone | ExportSolution first, save the zip, then delete |
| Hardcoding the Dataverse URL / secret | Env-specific, leaks in source | .env: PA_DATAVERSE_URL, PA_TENANT_ID, PA_CLIENT_ID, PA_CLIENT_SECRET |
| Assuming the Dataverse path is permanent | Power Platform API is superseding surfaces piecemeal | Re-check api.powerplatform.com coverage at author time; the split is fast-moving |
.env set: PA_DATAVERSE_URL (no trailing slash), PA_TENANT_ID, PA_CLIENT_ID, PA_CLIENT_SECRET.{PA_DATAVERSE_URL}/.default (or delegated user_impersonation).category:5, type:1, primaryentity:"none", and clientdata as an escaped string.connectionReferences entry maps to an authorized connection before enabling.PATCH statecode=1 and verified on read-back.DELETE.© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (references) in skills/power-automate of ericrisco/rsc-harness.
Open the folder on GitHubat commit e3d5b33
Power Automate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Power Automate this skillericrisco/rsc-harness | 174 | — | ~3.1k | Automated safety check: Notes | MIT | |
| Msal Auth Code FlowAzureAD/microsoft-authentication-library-for-dotnet | 1.5k | — | ~917 | Automated safety check: Pass | MIT | |
| Entra Agent Idmicrosoft/GitHub-Copilot-for-Azure | 255 | 2 repos | ~4k | Automated safety check: Pass | MIT | |
| Azure APIM Policy Authoringthomast1906/github-copilot-agent-skills | 202 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Maui Authenticationdavidortinau/maui-skills | 175 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Implementing Google Workspace Sso Configurationmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 |
AzureAD/microsoft-authentication-library-for-dotnet
Authorization Code Flow for web applications using MSAL.NET confidential client to sign in users and access APIs on their behalf
microsoft/GitHub-Copilot-for-Azure
Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…
thomast1906/github-copilot-agent-skills
Generates Azure API Management policy XML for authentication, rate limiting, CORS, error handling and transformations, consulting Azure best-practice and documentation tools first.
davidortinau/maui-skills
Add authentication to .NET MAUI apps. An agent skill from davidortinau/maui-skills.
mukul975/Anthropic-Cybersecurity-Skills
Configures SAML 2.0 single sign-on for Google Workspace against a third-party identity provider (Okta, Azure AD/Entra ID, ADFS), with Workspace as the Service Provider, to centralize authentication…
microsoft/GitHub-Copilot-for-Azure
Guides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Works with
Categories
A skill your agent uses when operating Microsoft Power Automate cloud flows from code — create, enable, update, list or delete via the Dataverse Web API (workflow table, category 5) with Entra ID…. Power Automate is an agent skill from ericrisco/rsc-harness. Use when operating Microsoft Power Automate cloud flows from code — create, enable, update, list or delete via the Dataverse Web API (workflow table, category 5) with Entra ID OAuth2, plus run-history debugging.
Power Automate fits situations like: operating Microsoft Power Automate cloud flows from code — create; delete via the Dataverse Web API (workflow table; with Entra ID OAuth2; plus run-history debugging.
Run `npx skills add ericrisco/rsc-harness --skill power-automate -a claude-code`. Or copy the skill folder (skills/power-automate in ericrisco/rsc-harness) into .claude/skills/power-automate in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill power-automate -a codex`. Or copy the skill folder (skills/power-automate in ericrisco/rsc-harness) into .agents/skills/power-automate in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill power-automate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/power-automate, .gemini/skills/power-automate, .github/skills/power-automate and .opencode/skills/power-automate in your project.
Going by SKILL.md and its folder, Power Automate needs the command-line tools its instructions call (curl and python3) and credentials named PA_CLIENT_SECRET. Our summary lists: Python 3; A credential in PA_CLIENT_SECRET.
SKILL.md names 3 domains. In commands or code: contoso.crm.dynamics.com, schema.management.azure.com and login.microsoftonline.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Power Automate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Power Automate: Msal Auth Code Flow (AzureAD/microsoft-authentication-library-for-dotnet, 1.5k stars), Entra Agent Id (microsoft/GitHub-Copilot-for-Azure, 255 stars), Azure APIM Policy Authoring (thomast1906/github-copilot-agent-skills, 202 stars) and Maui Authentication (davidortinau/maui-skills, 175 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 174 GitHub stars. The repository holds 233 skills in this directory. The repository was last updated on October 7, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.