Official agent skill

Create Webroles

by microsoft in microsoft/power-platform-skills

Creates and configures web roles for a Power Pages code site.

OfficialMITAuto-check: notes

Install Create Webroles

skills CLI
$ npx skills add microsoft/power-platform-skills --skill create-webroles -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/power-platform-skills create-webroles --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/power-pages/skills/create-webroles .claude/skills/create-webroles && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
create-webroles
GitHub stars
967
Token cost
~3.4k tokens
SKILL.md length
1,706 words
Files
3 (incl. scripts)
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Creates and configures web roles for a Power Pages code site.

  • Works in 7 steps: Detect caller-suppress mode → Verify Site Structure → Discover Existing Roles → …
  • The user wants to create
  • SKILL.md covers Core Principles, Phase 0: Detect…, Workflow and Phase 1: Verify Site Structure, plus 6 more sections
  • Runs JavaScript scripts from its folder; calls node

What it does

Create Webroles is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Creates and configures web roles for a Power Pages code site. Web roles control access and permissions for site users, including authenticated and anonymous roles. Use when the user wants to create, add, set up, or manage web roles for their site.

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `scripts/create-web-role.js` and `scripts/validate-webroles.js`).

The repository describes itself as: A plugin marketplace for GitHub Copilot and other AI agents that provides Power Platform development plugins, including reusable skills, agents, and commands for building and… The licence is MIT.

When your agent uses it

  • The user wants to create
  • Manage web roles for their site

Example prompts

  • “Use the create-webroles skill to create and configures web roles for a Power Pages code site”
  • “/create-webroles”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Grep, Glob, AskUserQuestion, Task, TaskCreate, TaskUpdate, TaskList

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Detect caller-suppress mode
  2. Verify Site Structure
  3. Discover Existing Roles
  4. Determine New Roles
  5. Create Web Role Files
  6. Verify Web Roles
  7. Review & Deploy

What it can do on your machine

Read from SKILL.md and the folder at commit 5ef4e4f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Grep
    • Glob
    • AskUserQuestion
    • Task
    • TaskCreate
    • TaskUpdate
    • TaskList

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Create Webroles loads about 3.4k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 1,706 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Grep, Glob, AskUserQuestion, Task, TaskCreate, TaskUpdate, TaskList

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from microsoft/power-platform-skills at commit 5ef4e4f, republished under its MIT licence (© microsoft). 1,706 words, ~3,354 tokens.

Download SKILL.mdSave it as .claude/skills/create-webroles/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
create-webroles
description
Creates and configures web roles for a Power Pages code site. Web roles control access and permissions for site users, including authenticated and anonymous roles. Use when the user wants to create, add, set up, or manage web roles for their site.
allowed-tools
Read, Write, Bash, Grep, Glob, AskUserQuestion, Task, TaskCreate, TaskUpdate, TaskList
user-invocable
true
model
opus

Plugin check: Run node "${PLUGIN_ROOT}/scripts/check-version.js" — if it outputs a message, show it to the user before proceeding.

Create Web Roles

Create web roles for a Power Pages code site. Web roles define the permissions and access levels for different types of site users.

Core Principles

  • Use TaskCreate/TaskUpdate: Track all progress throughout all phases — create the todo list upfront with all phases before starting any work.
  • Always use the UUID script: Never generate UUIDs manually — always use ${PLUGIN_ROOT}/scripts/generate-uuid.js to produce valid UUID v4 values for each web role.
  • Preserve uniqueness constraints: Only one role can have anonymoususersrole: true and only one can have authenticatedusersrole: true. Always check existing roles before setting these flags.
  • Caller-suppress mode is opt-in: When invoked by another skill (e.g. /add-ai-webapi) with the [CALLED-BY-PARENT-SKILL] sentinel in $ARGUMENTS, suppress this skill's deploy prompts (Phase 1's missing-deploy ask, Phase 6's deploy ask (step 3), and the closing reminder) and return as soon as roles are created. The caller batches the deploy at end-of-orchestration. Human invocations never trigger this mode. See Phase 0 below for parsing.

Prerequisite: The site must be deployed at least once before web roles can be created, since deployment creates the .powerpages-site folder structure that stores web role definitions.

Initial request: $ARGUMENTS

Phase 0: Detect caller-suppress mode

Inspect $ARGUMENTS. If the text contains the sentinel [CALLED-BY-PARENT-SKILL], set an internal flag caller-suppress = true that downstream phases consult. The optional token caller=<skill-name> may follow the sentinel for diagnostic purposes (e.g. caller=add-ai-webapi); record it for the final summary but do not branch on it.

When the flag is set, skip every deploy prompt this skill would otherwise issue:

  • Phase 1 missing-deploy ask: if .powerpages-site is absent, do NOT ask the user to deploy now. Stop with a clear contract-violation message back to the caller — the caller was supposed to gate on this before invoking us.
  • Phase 6 deploy ask (step 3) and the closing "Please run /deploy-site" reminder: skip both. The caller batches the single deploy decision at end-of-orchestration.

When the sentinel is absent, proceed exactly as today (full interactive flow). This is the regression guard — no human invocation changes behavior.


Workflow

  1. Phase 1: Verify Site Structure → Check for .powerpages-site/web-roles/ directory
  2. Phase 2: Discover Existing Roles → Read current web role YAML files
  3. Phase 3: Determine New Roles → Analyze the site and ask the user what roles are needed
  4. Phase 4: Create Web Role Files → Generate YAML files with UUIDs from the Node script
  5. Phase 5: Verify Web Roles → Validate all created files exist, have valid UUIDs, and flags are correct
  6. Phase 6: Review & Deploy → Present summary and proceed to deployment

Phase 1: Verify Site Structure

Goal: Confirm the .powerpages-site/web-roles/ directory exists and is ready for web role files

Actions:

  1. Locate the project root (**/powerpages.config.json) and check for .powerpages-site/web-roles/.
<!-- gate: create-webroles:1.deploy-first | category=plan | cancel-leaves=nothing -->

🚦 Gate (plan · create-webroles:1.deploy-first): .powerpages-site missing — skill cannot proceed without that folder. Prompt to deploy first or stop.

Trigger: Phase 1 found no .powerpages-site directory. Why we ask: Web role YAML files written to a non-existent path will never get picked up by deploy; user thinks roles were created but they weren't. Cancel leaves: Nothing — no YAML files written.

  1. If .powerpages-site does NOT exist:

    • In caller-suppress mode (Phase 0 flag): stop with a contract-violation message — the calling skill should have gated on this folder existing before invoking us.
    • Otherwise: ask the user to deploy first via AskUserQuestion (options: "Yes, deploy now (Recommended)", "No, I'll do it later"). If yes, invoke /deploy-site then resume from Phase 2. If no, stop.
  2. If .powerpages-site exists but web-roles/ does NOT: Create the <PROJECT_ROOT>/.powerpages-site/web-roles/ directory.

  3. If both exist: Proceed to Phase 2.

Output: Confirmed .powerpages-site/web-roles/ directory exists and is ready


Phase 2: Discover Existing Roles

Goal: Identify all web roles already defined for the site

Actions:

  1. Read all YAML files in the .powerpages-site/web-roles/ directory. Each file represents one web role with this format:

    yaml
    anonymoususersrole: false
    authenticatedusersrole: false
    id: 778fa3d0-a2ef-4d2b-98b8-e6c7d8ce1444
    name: Administrators
  2. Parse each file and compile a list of existing web roles (name, id, and flags).

  3. Present the existing roles to the user:

    "I found the following existing web roles in your site:"

    • Administrators (id: 778fa3d0-..., authenticated: false, anonymous: false)
    • (etc.)
  4. If no roles exist yet, inform the user:

    "No web roles are currently defined for your site."

Output: Complete list of existing web roles with their names, IDs, and flags


Phase 3: Determine New Roles

Goal: Decide which new web roles to create based on site needs and user input

Actions:

<!-- gate: create-webroles:3.role-selection | category=plan | cancel-leaves=nothing -->

🚦 Gate (plan · create-webroles:3.role-selection): Multi-select over suggested + custom web roles. Drives the Phase 4 YAML file writes.

Trigger: Phase 2 inventoried existing roles; Phase 3 suggests new ones. Why we ask: Wrong roles get created locally — fixable but adds churn to the .powerpages-site/web-roles/ folder. Cancel leaves: Nothing — no YAML files written yet.

  1. Based on the site's purpose and the existing roles, suggest appropriate web roles. Use AskUserQuestion to confirm with the user.

    Common web roles for Power Pages sites include:

    • Administrators — Full access to site management
    • Authenticated Users — Default role for logged-in users (set authenticatedusersrole: true)
    • Anonymous Users — Default role for non-logged-in visitors (set anonymoususersrole: true)
    • Content Editors — Users who can edit site content
    • Moderators — Users who can moderate community content
    • Custom roles based on business needs
  2. Ask the user which roles they want to create:

    QuestionOptions
    Which web roles would you like to create for your site? You can select from suggestions or describe custom roles.(Provide relevant suggestions based on site context, existing roles, and business domain)

    CRITICAL: Do NOT suggest roles that already exist. Filter out any existing role names before presenting options.

  3. Allow the user to specify custom role names as well.

Output: Confirmed list of new web roles to create


Phase 4: Create Web Role Files

Goal: Generate properly formatted YAML files with valid UUIDs for each new web role

Actions:

For each new web role the user approved, create a YAML file in .powerpages-site/web-roles/.

4.1 Generate UUID

For each role, generate a UUID using the Node script. NEVER generate UUIDs yourself — always use the script.

bash
node "${PLUGIN_ROOT}/scripts/generate-uuid.js"
Show full SKILL.md (706 more words)Show less
4.2 Create the YAML File

The filename should be the role name in kebab-case with a .yml extension (e.g., Administrators → administrators.yml, Content Editors → content-editors.yml).

Write the file with this exact format (4 fields, no extra whitespace or comments):

yaml
anonymoususersrole: <true if this is the anonymous users role, false otherwise>
authenticatedusersrole: <true if this is the authenticated users role, false otherwise>
id: <UUID from generate-uuid.js>
name: <Role Name>

Rules:

  • Only ONE role can have anonymoususersrole: true
  • Only ONE role can have authenticatedusersrole: true
  • If an existing role already has one of these flags set to true, do not set it again on a new role
  • Each role MUST have a unique UUID generated by the script — run the script once per role

Output: All new web role YAML files created


Phase 5: Verify Web Roles

Goal: Validate that all created web role files exist, have valid format, and constraints are satisfied

Actions:

  1. List all files in .powerpages-site/web-roles/ and read each new file to confirm they were written correctly.

  2. For each new web role file, verify:

    • The file exists at the expected path
    • The id field contains a valid UUID v4 format
    • The name field matches the expected role name
    • anonymoususersrole and authenticatedusersrole are valid booleans
  3. Verify uniqueness constraints across ALL role files (existing + new):

    • At most one role has anonymoususersrole: true
    • At most one role has authenticatedusersrole: true
    • No duplicate id values exist across roles
  4. If any file fails validation, fix the issue before proceeding.

Output: All web role files validated — correct format, valid UUIDs, no constraint violations


Phase 6: Review & Deploy

Goal: Present a summary of created roles and offer deployment

Actions:

  1. Record skill usage:

    Reference: ${PLUGIN_ROOT}/references/skill-tracking-reference.md

    Follow the skill tracking instructions in the reference to record this skill's usage. Use --skillName "CreateWebroles".

  2. Present a summary of what was created:

    "I've created the following new web roles:"

Role NameIDAnonymousAuthenticated
Content Editorsa1b2c3d4-...falsefalse
(etc.)
<!-- gate: create-webroles:6.deploy | category=plan | cancel-leaves=nothing -->

🚦 Gate (plan · create-webroles:6.deploy): Final post-create prompt — deploy now to make the new roles take effect, or defer.

Trigger: Phase 5 validation succeeded. Why we ask: Auto-invoking /deploy-site would push the site to whatever env PAC CLI happens to point at — wrong-env push is messy to undo. Cancel leaves: Nothing — the YAML files stay on disk; no deploy fired.

  1. In caller-suppress mode (Phase 0 flag): skip the deploy ask and the closing reminder entirely. Return the created-roles summary to the caller and stop. The caller owns the single end-of-orchestration deploy decision; nesting deploy reminders inside delegations gives the user 2–3 redundant prompts per parent-skill run.

    Otherwise, ask the user if they want to deploy the site to apply the new roles:

    QuestionOptions
    The new web roles have been created locally. To apply them in Power Pages, the site needs to be deployed. Would you like to deploy now?Yes, deploy now (Recommended), No, I'll deploy later
  2. If "Yes, deploy now": Tell the user to invoke the deploy skill:

    "Please run /deploy-site to deploy your site and apply the new web roles."

  3. If "No, I'll deploy later": Acknowledge and remind them:

    "No problem! Remember to deploy your site using /deploy-site when you're ready to apply the new web roles to your Power Pages environment."

Output: Summary presented and deployment offered


Important Notes

Key Decision Points (Wait for User)
  1. After Phase 1: Confirm deployment if .powerpages-site is missing
  2. After Phase 3: Confirm which roles to create
  3. After Phase 6: Deploy or skip
Progress Tracking

Before starting Phase 1, create a task list with all phases using TaskCreate:

Task subjectactiveFormDescription
Verify site structureVerifying site structureCheck for .powerpages-site/web-roles/ directory, create if needed
Discover existing rolesDiscovering existing rolesRead current web role YAML files and compile list of existing roles
Determine new rolesDetermining new rolesAnalyze site needs and ask user which roles to create
Create web role filesCreating web role filesGenerate YAML files with UUIDs from the Node script for each new role
Verify web rolesVerifying web rolesValidate all files exist, have valid UUIDs, and uniqueness constraints are satisfied
Review and deployReviewing and deployingPresent summary of created roles and offer deployment

Mark each task in_progress when starting it and completed when done via TaskUpdate. This gives the user visibility into progress and keeps the workflow deterministic.


Begin with Phase 1: Verify Site Structure

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in plugins/power-pages/skills/create-webroles of microsoft/power-platform-skills.

  • SKILL.md
  • scripts/create-web-role.js
  • scripts/validate-webroles.js

Open the folder on GitHubat commit 5ef4e4f

Compare with similar skills

Create Webroles next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Create Webroles compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Create Webroles this skillmicrosoft/power-platform-skills967—~3.4kAutomated safety check: NotesMIT
Sitesasgeirtj/system_prompts_leaks69k—~1.6kAutomated safety check: PassCC0-1.0
Aria Rolesthedaviddias/Front-End-Checklist74k—~515Automated safety check: PassMIT
Configure Sitepymc-labs/pathmc132—~2kAutomated safety check: PassMIT
Statistical PowerK-Dense-AI/scientific-agent-skills48k1 repos~4.4kAutomated safety check: NotesMIT
Configure Eccaffaan-m/ECC274k1 repos~2kAutomated safety check: PassMIT

Similar skills

  • Sites

    asgeirtj/system_prompts_leaks

    A skill your agent uses when creating or updating a website, web app, or browser game, or when a visual layout or interactive tool would help with what the user is doing.

    69k GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Aria Roles

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing rendered HTML, interactive components, or design-system patterns related to Use valid ARIA role values.

    74k GitHub stars~515 tokensUpdated yesterday
    Frontend & DesignAuto-check passed
  • Configure Site

    pymc-labs/pathmc

    Configure a Great Docs documentation site through great-docs.yml.

    132 GitHub stars~2k tokensUpdated 5 days ago
    Frontend & DesignAuto-check passed
  • Statistical Power

    K-Dense-AI/scientific-agent-skills

    Calculates sample sizes and statistical power for study planning.

    48k GitHub starsUsed in 1 repo~4.4k tokens
    Research & ScienceAuto-check: notes
  • Configure Ecc

    affaan-m/ECC

    Run the conversational ECC setup wizard inside the current harness: inventory the install, collect scope (user/project/local) and hook mode (off/minimal/standard/strict) in Claude Code, use Codex's…

    274k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Configure Ecc

    affaan-m/ECC

    Claude Code、Codex、Kimi 内で ECC のインストール、更新、再設定を案内し、各ハーネスが実際に備えるプラグイン、スコープ、フック機能を守ります。

    274k GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

More from microsoft/power-platform-skills

All 87 skills in this repo
  • Manage Firewall

    microsoft/power-platform-skills

    Official

    Inspects and configures the web application firewall (WAF) in front of a Power Pages production site.

    967 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check: notes
  • Manage Headers

    microsoft/power-platform-skills

    Official

    Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…

    967 GitHub stars~3k tokensUpdated yesterday
    Auto-check: notes
  • Scan Code

    microsoft/power-platform-skills

    Official

    Scans a Power Pages site project for security issues in source code and dependencies.

    967 GitHub stars~3.4k tokensUpdated yesterday
    Auto-check: notes
  • Scan Site

    microsoft/power-platform-skills

    Official

    Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.

    967 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check: notes
  • Setup Datamodel

    microsoft/power-platform-skills

    Official

    Creates Dataverse tables, columns, and relationships for a Power Pages site based on a data model proposal.

    967 GitHub stars~4k tokensUpdated yesterday
    Auto-check: notes
  • Add Server Logic

    microsoft/power-platform-skills

    Official

    Creates, edits, and manages Power Pages Server Logic files — server-side JavaScript that runs securely on the Power Pages runtime.

    967 GitHub stars~18k tokensUpdated yesterday
    Auto-check: notes

Questions about Create Webroles

What does Create Webroles do?

Creates and configures web roles for a Power Pages code site. Create Webroles is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Creates and configures web roles for a Power Pages code site.

When should I use Create Webroles?

Create Webroles fits situations like: the user wants to create; manage web roles for their site.

How do I install Create Webroles in Claude Code?

Run `npx skills add microsoft/power-platform-skills --skill create-webroles -a claude-code`. Or copy the skill folder (plugins/power-pages/skills/create-webroles in microsoft/power-platform-skills) into .claude/skills/create-webroles in your project. Claude Code loads it when a task matches its description.

How do I install Create Webroles in Codex?

Run `npx skills add microsoft/power-platform-skills --skill create-webroles -a codex`. Or copy the skill folder (plugins/power-pages/skills/create-webroles in microsoft/power-platform-skills) into .agents/skills/create-webroles in your project. Codex loads it when a task matches its description.

Can I use Create Webroles in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/power-platform-skills --skill create-webroles -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/create-webroles, .gemini/skills/create-webroles, .github/skills/create-webroles and .opencode/skills/create-webroles in your project.

What does Create Webroles need to run?

Going by SKILL.md and its folder, Create Webroles needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Bash, Grep, Glob, AskUserQuestion, Task, TaskCreate, TaskUpdate, TaskList.

Does Create Webroles access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Create Webroles safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Create Webroles use?

Create Webroles is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Create Webroles use?

About 3.4k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Create Webroles?

Skills that share tags, products or a category with Create Webroles: Sites (asgeirtj/system_prompts_leaks, 69k stars), Aria Roles (thedaviddias/Front-End-Checklist, 74k stars), Configure Site (pymc-labs/pathmc, 132 stars) and Statistical Power (K-Dense-AI/scientific-agent-skills, 48k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Create Webroles?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/power-platform-skills, which has 967 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/power-platform-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.