Official agent skill

Manage Firewall

by microsoft in microsoft/power-platform-skills

Inspects and configures the web application firewall (WAF) in front of a Power Pages production site.

OfficialMITAuto-check: notesBackend & APIs

Install Manage Firewall

skills CLI
$ npx skills add microsoft/power-platform-skills --skill manage-firewall -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/power-platform-skills manage-firewall --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/power-pages/skills/manage-firewall .claude/skills/manage-firewall && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
manage-firewall
GitHub stars
967
Token cost
~4.5k tokens
SKILL.md length
2,040 words
Files
10 (incl. scripts, references)
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Inspects and configures the web application firewall (WAF) in front of a Power Pages production site.

  • Works in 5 steps: Prerequisites → Check firewall state → Choose an action → …
  • The user wants to turn on WAF
  • SKILL.md covers Gotchas, Workflow, Task Tracking and 1. Prerequisites, plus 6 more sections
  • Runs JavaScript scripts from its folder; calls node and az

What it does

Manage Firewall is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Inspects and configures the web application firewall (WAF) in front of a Power Pages production site. Lists the current state, recommends enabling protection when it is off, and walks the user through adding, updating, or removing custom rules — IP blocks, country blocks, path blocks, and rate limits. Use when the user wants to turn on WAF, block traffic by IP or country, rate-limit login or signup pages, protect pages from brute-force attempts, restrict access to specific paths, review the current firewall…

Its SKILL.md is about 4.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 11 other files, including scripts and reference files (for example `references/commands.md`, `references/rule-reference.md` and `scripts/delete-rules.js`).

It sits in Backend & APIs, covering Rate limiting. The repository describes itself as: A plugin marketplace for GitHub Copilot and other AI agents that provides Power Platform development plugins, including reusable skills, agents, and commands for building and… The licence is MIT.

When your agent uses it

  • The user wants to turn on WAF
  • Block traffic by IP
  • Rate-limit login
  • Protect pages from brute-force attempts

Example prompts

  • “is my site protected against bots / common web attacks?”
  • “add rate limit”
  • “protect login page”
  • “/manage-firewall”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Prerequisites
  2. Check firewall state
  3. Choose an action
  4. Apply the change
  5. Summarize and next steps

What it can do on your machine

Read from SKILL.md and the folder at commit 5ef4e4f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Glob
    • Grep
    • AskUserQuestion
    • TaskCreate
    • TaskUpdate
    • TaskList

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 7 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Manage Firewall loads about 4.5k tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 177 tokens; SKILL.md has 2,040 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~177
When it runs · the whole SKILL.md, loaded when a task matches
~4.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from microsoft/power-platform-skills at commit 5ef4e4f, republished under its MIT licence (© microsoft). 2,040 words, ~4,453 tokens.

Download SKILL.mdSave it as .claude/skills/manage-firewall/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
manage-firewall
description
Inspects and configures the web application firewall (WAF) in front of a Power Pages production site. Lists the current state, recommends enabling protection when it is off, and walks the user through adding, updating, or removing custom rules — IP blocks, country blocks, path blocks, and rate limits. Use when the user wants to turn on WAF, block traffic by IP or country, rate-limit login or signup pages, protect pages from brute-force attempts, restrict access to specific paths, review the current firewall configuration, or asks "is my site protected against bots / common web attacks?" — even if they say "add rate limit" or "protect login page" without mentioning "firewall" or "WAF".
allowed-tools
Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList
user-invocable
true
argument-hint
[optional: --review <out-dir>]
model
opus

Plugin check: Run node "${PLUGIN_ROOT}/scripts/check-version.js" — if it outputs a message, show it to the user before proceeding.

Manage Web Application Firewall

Configure the firewall for a Power Pages production site. The firewall is only available on production sites and in supported regions — the scripts detect and report eligibility issues. After rule changes, edge propagation takes up to one hour.

Initial request: $ARGUMENTS

Gotchas

  • Website record id vs portal id. .powerpages-site/website.yml stores the website record id, not the portal id. Every script takes --portalId. Resolve once via website.js --websiteId during prerequisites.
  • Never resolve by name. Site names can duplicate; only the website record id is safe.
  • Async operations. enable.js and disable.js poll until the status reaches the target value (or timeout). delete-rules.js returns immediately (202) — verify via get-rules.js.
  • Concurrent-operation guard. B003 means another enable/disable is in flight. Poll status until it settles, then retry.
  • False-positive managed rule: disable via a rule override (EnabledState: "Disabled" inside RuleGroupOverrides — managed rule fields use PascalCase).
  • First-match-wins. Rules evaluate in priority order. A geo-allow-then-default-deny pattern requires an explicit default-deny rule AFTER the allow.
  • Custom rule priority range: 11–65000. Values 1–10 are reserved for platform-managed rules.
  • set-rules.js is additive / update-only. Send only rules being created or modified. The service merges them; existing rules not in the payload are untouched.
  • Use delete-rules.js to remove rules. set-rules.js cannot remove. Always use delete-rules.js --names.
  • WAF state semantics — Created is the only "enabled" state. get-status.js returns value: "Created" when the firewall is enabled and actively filtering (counter-intuitive — the API does NOT use "Enabled"). Any other value (Disabled, None, Enabling, Disabling, Failed) means no active policy exists. MUST call get-status.js first and only invoke get-rules.js when value is Created — otherwise the rules endpoint returns a 500 and the whole firewall section gets skipped in the report.

Workflow

  1. Prerequisites — Locate project, confirm sign-in, identify site, check eligibility
  2. Check firewall state — Capture status and rules
  3. Choose an action — Context-aware recommendation or question
  4. Apply the change — Run the matching script, verify
  5. Summarize and next steps — Present result, record usage, offer follow-ups

Task Tracking

Create tasks in three groups. Mark each in_progress when starting, completed when done.

GroupWhen to createTasks
1At startCheck prerequisites
2After prerequisites passCheck firewall state · Choose an action (skip in review mode)
3After user confirms an actionApply the change (skip in review mode OR no change action was chosen) · Summarize and next steps (always)

1. Prerequisites

1.1 Locate the project, detect review mode

Use Glob to find **/powerpages.config.json. If $ARGUMENTS contains --review <out-dir>, remember the output directory — Steps 3–4 are skipped and Step 5 writes JSON only.

1.2 Resolve site identifiers

Read .powerpages-site/website.yml → extract id field → that is <WEBSITE_ID>.

If missing, the site has not been deployed. Tell the user and recommend /deploy-site. Stop. Do not resolve by name or URL.

Resolve to portalId:

bash
node "${PLUGIN_ROOT}/scripts/website.js" --websiteId "<WEBSITE_ID>"

Capture Id (portalId), Type, Name, WebsiteUrl. If exit code 2 → sign-in required (pac auth create or az login). If null → site not found in this environment. Stop in either case.

1.3 Eligibility

Check the Type field and the script responses for eligibility. The scripts return specific error codes for ineligible sites (non-production, unsupported region, restricted feature). Read references/commands.md § "Common error catalogue" and § "Regional availability" for the full list.

If the site is ineligible, tell the user in plain language what the limitation is and stop.


2. Check firewall state

2.1 Get status (always run first)
bash
node "${PLUGIN_ROOT}/skills/manage-firewall/scripts/get-status.js" --portalId "<PORTAL_ID>"

The response shape is { "status": "ok", "value": "<state>" }.

  • Created — WAF is enabled and filtering. Proceed to 2.2 to fetch rules.
  • Any other value (Disabled, None, Enabling, Disabling, Failed, etc.) — WAF is not enabled. MUST NOT call get-rules.js — the rules endpoint will return a 500 because no active policy exists to read. Skip 2.2 and treat the rules payload as empty: { "status": "ok", "body": { "CustomRules": [], "ManagedRules": [] } }.

If the status response is "status": "unsupported", tell the user the firewall is not available and stop.

2.2 Get rules (only when WAF is enabled)
bash
node "${PLUGIN_ROOT}/skills/manage-firewall/scripts/get-rules.js" --portalId "<PORTAL_ID>"

Both scripts output the full response as JSON to stdout. If get-rules.js returns "status": "unsupported", tell the user the firewall is not available and stop.


3. Choose an action

Skip in review mode.

MUST use plain language only with the user. Never use words like WAF, OWASP, ModSec, ruleset, geo-block, rate-limit, ASN, SocketAddr, or rule priority.

Each AskUserQuestion call is a separate call. Wait for the user's answer before asking the next.

Default approach
<!-- gate: manage-firewall:3.action-choice | category=plan | cancel-leaves=nothing -->

🚦 Gate (plan · manage-firewall:3.action-choice): Recommend an action based on the site's current state, then ask the user to accept or choose differently. Fires once per Phase 3 entry — loops back here if the user wants to make additional changes after Phase 4 applies the first one.

Trigger: Phase 3 entry (interactive mode only — skipped in review mode). Why we ask: Wrong-action firewall changes are visible to every site visitor; auto-recommend without consent can disable an active rule the maker added deliberately. Cancel leaves: Nothing — Phase 4 hasn't fired yet.

Analyze the site's current state (firewall status, existing custom rules, managed rules, region eligibility) and recommend the single most relevant action. Present the recommendation via AskUserQuestion:

  • Firewall off → recommend enabling it.
  • Firewall on, no custom rules → recommend adding a rule if there is a clear gap (e.g., no rate limiting). Otherwise, summarize the state and ask if the user wants to add a rule.
  • Firewall on, rules exist → summarize what is configured and ask what the user wants to do.

If the site's state does not warrant a specific recommendation, do not force one — ask what the user wants to do.

MUST NOT proactively offer actions that reduce security (disabling the firewall, removing managed rules, weakening existing rules). If the user needs those, they will ask.

Option rules
<!-- not-a-gate: meta-documentation describing how to structure `AskUserQuestion` options in this skill — not a literal call site. The actual destructive firewall changes (enable/disable/add-rule/remove-rule) are gated by the prose-described "apply only after user approval" rule in §3 Plan-validate-execute and §4 Apply the change. See approval-gates.md §6.24a + §6.25. -->

When presenting options via AskUserQuestion:

  • Keep label to 1–5 words. Include description on every option.
  • Include preview only when the option represents a concrete change (create, update, or delete a rule) — use it to show the configuration that will be applied so the user can review before approving. Do not add preview to navigation or informational choices.
  • Only show options that are actionable given the current state. Omit options for features the site cannot use (check references/commands.md § "Regional availability").
  • Mark "(Recommended)" only when there is a genuine, context-based reason. If nothing stands out, do not mark any.
  • When offering to add a rule type that already exists on the site, acknowledge it in the description — include the count and summarize what is configured so the user can decide whether to add or update.
  • For path-based rules, reference actual page paths from the project structure when known. Fall back to generic language only when no project context is available.
Rule type follow-up

When the user picks "Add a rule", ask a follow-up for the rule type. The same option rules apply. Translate the answer into set-rules.js parameters — keep the user out of priority-numbering and rule-naming details. Read references/rule-reference.md for rule shapes.

Remove a rule

List current custom rules showing: what each rule does (plain language), what traffic it matches, whether it blocks or allows, and its priority relative to others. If removing a rule would break a deny/allow pattern, warn before proceeding.

Show full SKILL.md (866 more words)Show less
Plan-validate-execute
<!-- gate: manage-firewall:3.execute-consent | category=consent | cancel-leaves=nothing -->

🚦 Gate (consent · manage-firewall:3.execute-consent): Final consent before any destructive WAF mutation (enable/disable, add/update/delete rule). Echoes the proposed JSON payload + the surfaced validation issues. Fires PER CHANGE — each enable, disable, rule add, rule update, and rule delete is its own consent.

Trigger: Phase 3 action chosen, plan + validation surfaced. Why we ask: Firewall changes are env-level and visible to every site visitor; auto-applying can lock out legitimate traffic or weaken protection. Cancel leaves: Nothing — the API call hasn't fired yet; the plan + validation are throwaway.

For all rule changes:

  1. Plan — build the JSON payload containing only the rules being added or updated.
  2. Validate — check the plan against the existing rule set and surface:
    • Priority conflicts with existing rules
    • Overlapping match conditions (same matchVariable/operator, overlapping matchValue) — explain which rule wins via first-match-wins
    • Contradictions between Allow and Block rules — flag and explain priority implications
    • Redundancy — suggest updating the existing rule instead of adding a duplicate
  3. Execute — apply only after user approval via AskUserQuestion:

For deletions, show the rule names and what each currently does before proceeding.

In review mode, skip this step entirely.


4. Apply the change

Skip in review mode.

ActionScript
Enableenable.js --portalId <id>
Disabledisable.js --portalId <id>
Add / update rulesset-rules.js --portalId <id> --data-inline '<json>'
Remove rulesdelete-rules.js --portalId <id> --names <comma-separated>

Run enable/disable with run_in_background: true (async operations with built-in polling).

Before applying, show only the disclosure relevant to the action being taken:

  • Enabling: managed rule set enforces immediately; some legitimate requests may be blocked until reviewed.
  • Disabling: site is unprotected until re-enabled.
  • Adding / updating rules: propagation takes up to an hour. If the rule uses Allow, explain it creates an exception even when block rules would apply.
  • Deleting rules: matched traffic is no longer blocked (or allowed). If the rule was an Allow exception in a deny pattern, warn that traffic will now be blocked.
  • Disabling a managed rule: that attack category is no longer inspected — name the category.

After completion, re-run status and rules calls to verify the new state.


5. Summarize and next steps

5.1 Review mode

Apply the same status-then-rules gating as § 2 — get-rules.js MUST only be invoked when the status value is Created. For any other value the WAF policy does not exist and the rules endpoint will return 500; the orchestrator must write the empty-rules payload directly instead of calling the script.

Step A — always run status:

bash
node "${PLUGIN_ROOT}/skills/manage-firewall/scripts/get-status.js" --portalId "<PORTAL_ID>" > "<REVIEW_DIR>/firewall-status.json"

Step B — branch on the captured value:

  • If value is Created, fetch rules:

    bash
    node "${PLUGIN_ROOT}/skills/manage-firewall/scripts/get-rules.js" --portalId "<PORTAL_ID>" > "<REVIEW_DIR>/firewall-rules.json"
  • Otherwise (Disabled, None, Enabling, Disabling, Failed, anything else), do NOT call get-rules.js. Write the empty-rules payload yourself:

    json
    { "status": "ok", "body": { "CustomRules": [], "ManagedRules": [] } }

After capturing the raw output, read both files and write <REVIEW_DIR>/firewall-annotations.json with plain-language descriptions of the state and each rule (the transform script no longer hardcodes these — they come from you):

json
{
  "state": {
    "description": "Plain-language explanation of what \"<value>\" means — is the firewall actively filtering requests, or not?",
    "fix": "Optional — include only if the state genuinely needs action."
  },
  "rules": {
    "<RuleName>": { "description": "What this rule does, in plain language.", "fix": "Optional fix if the rule has a genuine issue." }
  }
}

Power Pages WAF state semantics (use these when writing the state description — do not invent meanings):

  • Created — WAF is enabled. The firewall is active and filtering requests.
  • Disabled — WAF is not enabled and no firewall policy exists. The site is unprotected.
  • None — no firewall policy has ever been provisioned. Same user-facing meaning as Disabled.
  • Enabling / Disabling — operation in progress; wait.
  • Failed — last enable/disable operation failed.

Then run the transform:

bash
node "${PLUGIN_ROOT}/skills/manage-firewall/scripts/transform-firewall.js" \
  --statusFile "<REVIEW_DIR>/firewall-status.json" \
  --rulesFile  "<REVIEW_DIR>/firewall-rules.json" \
  --annotations "<REVIEW_DIR>/firewall-annotations.json"

Write the transform stdout to <REVIEW_DIR>/manage-firewall.json and stop. The transform emits { status, findings }; the orchestrating skill handles presentation.

5.2 Present summary

Plain-language summary: firewall on/off, rule count, what changed, important gaps.

5.3 Record skill usage

Reference: ${PLUGIN_ROOT}/references/skill-tracking-reference.md

Use --skillName "ManageFirewall".

5.4 Offer follow-ups

If a natural follow-up action exists based on the site's verified post-action state, suggest it. Do not offer actions that reduce security. If no meaningful follow-up exists, end the skill — do not ask just to ask.


Constraints

  • Plain language — MUST NOT use technical jargon with the user. Use everyday language; explain the technical name only when asked.
  • Eligibility — MUST short-circuit on ineligible sites (non-production, unsupported region). The scripts detect these — read references/commands.md for the full error catalogue.
  • Background ops — MUST run enable/disable via run_in_background.
  • Send only what changes — set-rules.js payload MUST contain only new or modified rules.
  • Rule naming — PascalCase, letters and numbers only (e.g., BlockCountries, AllowOfficeIP).
  • No company names — use generic names in rule examples.
  • Context-aware interactions — every question, option, follow-up, and disclosure MUST reflect the site's current state:
    • Never offer options that don't apply (e.g., "Remove a rule" when none exist).
    • Acknowledge existing rules of the same type when offering to add a new one.
    • Reference actual site page paths in descriptions when known from the project.
    • Check new rules against existing rules for conflicts, overlaps, contradictions, and redundancy before presenting the plan.
    • Show only the disclosure relevant to the action being taken.
    • Never proactively suggest reducing protection.
  • Preview is for change review only — include preview only on options representing a concrete change the user needs to approve. Do not add to navigation or informational choices.

References

  • references/commands.md — script flags, response shapes, error catalogue, regional availability. Read § "Common error catalogue" when a script returns a non-zero exit code. Read § "Regional availability" during eligibility checks.
  • references/rule-reference.md — field-level schema for custom rules, match conditions, managed rule overrides, match variables, operators, and priority bands. Read when building a rule plan.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in plugins/power-pages/skills/manage-firewall of microsoft/power-platform-skills.

  • SKILL.md
  • references/commands.md
  • references/rule-reference.md
  • scripts/delete-rules.js
  • scripts/disable.js
  • scripts/enable.js
  • scripts/get-rules.js
  • scripts/get-status.js
  • scripts/set-rules.js
  • scripts/transform-firewall.js

Open the folder on GitHubat commit 5ef4e4f

Compare with similar skills

Manage Firewall next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Manage Firewall compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Manage Firewall this skillmicrosoft/power-platform-skills967—~4.5kAutomated safety check: NotesMIT
Upstash Ratelimit TSupstash/ratelimit-js2.1k1 repos~313Automated safety check: PassMIT
API Gatewayitsmostafa/aws-agent-skills1.2k1 repos~2.2kAutomated safety check: PassMIT
Add Hosted Keysimstudioai/sim30k—~3.4kAutomated safety check: PassApache-2.0
Repo2skillzhangyanxs/repo2skill246—~3.6kAutomated safety check: PassNone
Better Auth Security Best PracticesEpicenterHQ/epicenter4.8k—~896Automated safety check: PassCustom licence

Similar skills

  • Upstash Ratelimit TS

    upstash/ratelimit-js

    Official

    Lightweight guidance for using the Redis Rate Limit TypeScript SDK, including setup steps, basic usage, and pointers to advanced algorithm, features, pricing, and traffic‑protection docs.

    2.1k GitHub starsUsed in 1 repo~313 tokens
    Backend & APIsAuto-check passed
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Backend & APIsAuto-check passed
  • Add Hosted Key

    simstudioai/sim

    Add hosted API key support to a tool so Sim provides the key (metered and billed to the workspace) when a user has not brought their own.

    30k GitHub stars~3.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Repo2skill

    zhangyanxs/repo2skill

    Convert GitHub/GitLab/Gitee repositories into comprehensive OpenCode Skills using embedded LLM calls with multiple mirrors and rate limit handling

    246 GitHub stars~3.6k tokensUpdated 7 mo ago
    Backend & APIsAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated today
    Backend & APIsAuto-check passed
  • Dload Fetch Tool

    php-internal/dload

    Get a CLI tool — native binary or PHAR — from a GitHub release into a project folder with dload (vendor/bin/dload).

    105 GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from microsoft/power-platform-skills

All 87 skills in this repo
  • Manage Headers

    microsoft/power-platform-skills

    Official

    Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…

    967 GitHub stars~3k tokensUpdated today
    Auto-check: notes
  • Scan Code

    microsoft/power-platform-skills

    Official

    Scans a Power Pages site project for security issues in source code and dependencies.

    967 GitHub stars~3.4k tokensUpdated today
    Auto-check: notes
  • Scan Site

    microsoft/power-platform-skills

    Official

    Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.

    967 GitHub stars~3.2k tokensUpdated today
    Auto-check: notes
  • Setup Datamodel

    microsoft/power-platform-skills

    Official

    Creates Dataverse tables, columns, and relationships for a Power Pages site based on a data model proposal.

    967 GitHub stars~4k tokensUpdated today
    Auto-check: notes
  • Add Server Logic

    microsoft/power-platform-skills

    Official

    Creates, edits, and manages Power Pages Server Logic files — server-side JavaScript that runs securely on the Power Pages runtime.

    967 GitHub stars~18k tokensUpdated today
    Auto-check: notes
  • Activate Site

    microsoft/power-platform-skills

    Official

    Activates and provisions a Power Pages website in a Power Platform environment via the Power Platform REST API.

    967 GitHub starsUsed in 1 repo~5k tokens
    Auto-check: notes

Categories

Questions about Manage Firewall

What does Manage Firewall do?

Inspects and configures the web application firewall (WAF) in front of a Power Pages production site. Manage Firewall is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Inspects and configures the web application firewall (WAF) in front of a Power Pages production site.

When should I use Manage Firewall?

Manage Firewall fits situations like: the user wants to turn on WAF; block traffic by IP; rate-limit login; protect pages from brute-force attempts.

How do I install Manage Firewall in Claude Code?

Run `npx skills add microsoft/power-platform-skills --skill manage-firewall -a claude-code`. Or copy the skill folder (plugins/power-pages/skills/manage-firewall in microsoft/power-platform-skills) into .claude/skills/manage-firewall in your project. Claude Code loads it when a task matches its description.

How do I install Manage Firewall in Codex?

Run `npx skills add microsoft/power-platform-skills --skill manage-firewall -a codex`. Or copy the skill folder (plugins/power-pages/skills/manage-firewall in microsoft/power-platform-skills) into .agents/skills/manage-firewall in your project. Codex loads it when a task matches its description.

Can I use Manage Firewall in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/power-platform-skills --skill manage-firewall -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/manage-firewall, .gemini/skills/manage-firewall, .github/skills/manage-firewall and .opencode/skills/manage-firewall in your project.

What does Manage Firewall need to run?

Going by SKILL.md and its folder, Manage Firewall needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and az). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList.

Does Manage Firewall access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Manage Firewall safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Manage Firewall use?

Manage Firewall is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Manage Firewall use?

About 4.5k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.1k tokens, read only when the agent opens those files.

What are the alternatives to Manage Firewall?

Skills that share tags, products or a category with Manage Firewall: Upstash Ratelimit TS (upstash/ratelimit-js, 2.1k stars), API Gateway (itsmostafa/aws-agent-skills, 1.2k stars), Add Hosted Key (simstudioai/sim, 30k stars) and Repo2skill (zhangyanxs/repo2skill, 246 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Manage Firewall?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/power-platform-skills, which has 967 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/power-platform-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.