Official agent skill

Scan Code

by microsoft in microsoft/power-platform-skills

Scans a Power Pages site project for security issues in source code and dependencies.

OfficialMITAuto-check: notesDevelopment

Install Scan Code

skills CLI
$ npx skills add microsoft/power-platform-skills --skill scan-code -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/power-platform-skills scan-code --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/power-pages/skills/scan-code .claude/skills/scan-code && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
scan-code
GitHub stars
967
Token cost
~3.4k tokens
SKILL.md length
1,578 words
Files
6 (incl. scripts, references)
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Scans a Power Pages site project for security issues in source code and dependencies.

  • Works in 4 steps: Prerequisites → Choose scope → Run scans → …
  • The user wants to review code for security problems
  • SKILL.md covers Gotchas, Workflow, Task Tracking and 1. Prerequisites, plus 5 more sections
  • Runs JavaScript scripts from its folder; calls node and git

What it does

Scan Code is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Scans a Power Pages site project for security issues in source code and dependencies. Runs static analysis and dependency scanning, then surfaces findings by category (code patterns, vulnerable packages, secrets, license issues). Use when the user wants to review code for security problems, check for vulnerable packages, find hard-coded secrets, run a code scan, or asks "is my code safe?", "check my dependencies", "find security issues in my source" — even if they say "audit my code" without mentioning specific…

Its SKILL.md is about 3.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/commands.md`, `scripts/check-tools.js` and `scripts/run-opengrep.js`).

It sits in Development, covering Static analysis and SAST and Code review. It works with Trivy. The repository describes itself as: A plugin marketplace for GitHub Copilot and other AI agents that provides Power Platform development plugins, including reusable skills, agents, and commands for building and… The licence is MIT.

When your agent uses it

  • The user wants to review code for security problems
  • Check for vulnerable packages
  • Find hard-coded secrets
  • Run a code scan

Example prompts

  • “is my code safe?”
  • “check my dependencies”
  • “find security issues in my source”
  • “/scan-code”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Prerequisites
  2. Choose scope
  3. Run scans
  4. Summarize

What it can do on your machine

Read from SKILL.md and the folder at commit 5ef4e4f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Glob
    • Grep
    • AskUserQuestion
    • TaskCreate
    • TaskUpdate
    • TaskList

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Scan Code loads about 3.4k tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 133 tokens; SKILL.md has 1,578 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~133
When it runs · the whole SKILL.md, loaded when a task matches
~3.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from microsoft/power-platform-skills at commit 5ef4e4f, republished under its MIT licence (© microsoft). 1,578 words, ~3,390 tokens.

Download SKILL.mdSave it as .claude/skills/scan-code/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
scan-code
description
Scans a Power Pages site project for security issues in source code and dependencies. Runs static analysis and dependency scanning, then surfaces findings by category (code patterns, vulnerable packages, secrets, license issues). Use when the user wants to review code for security problems, check for vulnerable packages, find hard-coded secrets, run a code scan, or asks "is my code safe?", "check my dependencies", "find security issues in my source" — even if they say "audit my code" without mentioning specific tools.
allowed-tools
Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList
user-invocable
true
argument-hint
[optional: --review <out-dir>]
model
opus

Plugin check: Run node "${PLUGIN_ROOT}/scripts/check-version.js" — if it outputs a message, show it to the user before proceeding.

Scan Code

Scan a Power Pages site project's source files and dependencies for security issues. Runs opengrep (static analysis) and trivy (dependency/secret/license scanning), then surfaces findings.

Initial request: $ARGUMENTS

WARNING: Before proceeding, inform the user: "This skill uses opengrep and trivy, only if they are installed on your local machine. These third-party, open-source tools scan your source code and dependencies and might collect or transmit data under their own terms, privacy policies, and data-handling practices. Microsoft does not control these. If you select the AI fallback, the AI service processes your source code. Review your organization's policies and applicable third-party terms before continuing."

Gotchas

  • Both tools must be installed. Run check-tools.js to verify. If either is missing, offer an agent-driven review fallback (see Step 1.2).
  • Opengrep exits 1 when findings exist. This is normal behavior, not an error — the script handles it.
  • Large output. Both tools can produce large JSON for big projects. The scripts normalize the output into a flat findings list.
  • Trivy severity flag only affects vulnerability findings. Secrets and license findings are always returned regardless of the --severity flag.
  • Secrets are never shown in full — anywhere. Whenever you read source directly (the agent-driven review) or present a finding, use your judgment to recognize any credential — API keys, tokens, passwords, connection strings, private keys, or any other secret shape (there is no fixed list). Never output its raw value anywhere — your context, the session, chat, logs, a summary, the report, or any other output — not even partially; where a value would otherwise be shown, replace it with a mask (e.g. ********).

Workflow

  1. Prerequisites — Locate project, check tool availability
  2. Choose scope — What to scan and at what depth
  3. Run scans — Execute tools, capture results
  4. Summarize — Present findings, record usage, offer follow-ups

Task Tracking

Create tasks in three groups. Mark each in_progress when starting, completed when done.

GroupWhen to createTasks
1At startCheck prerequisites
2After prerequisites passChoose scope (skip in review mode)
3After scope is decided (or in review mode)Run scans · Summarize (always)

1. Prerequisites

1.1 Locate the project, detect review mode

Use Glob to find **/powerpages.config.json. If $ARGUMENTS contains --review <out-dir>, remember the output directory — Step 2 is skipped (run all checks at Advanced depth), and Step 4 writes JSON only.

1.2 Check tool availability
bash
node "${PLUGIN_ROOT}/skills/scan-code/scripts/check-tools.js"

If either tool is missing, tell the user which tool is missing. Then offer an agent-driven review as a fallback:

In review mode (non-interactive), do not offer the agent-driven review. It needs an interactive opt-in, and the orchestrator expects a JSON file. Write { "status": "skipped", "reason": "<which tool> is not installed" } to <REVIEW_DIR>/scan-code.json and stop.

<!-- gate: scan-code:1.agent-review-fallback | category=plan | cancel-leaves=nothing -->

🚦 Gate (plan · scan-code:1.agent-review-fallback): When a scanning tool is missing, offer the agent-driven review as a fallback before doing any work. It reads the source with Glob/Read/Grep and has high token consumption, so the user must opt in.

Trigger: Step 1.2, only when check-tools.js reports a missing tool (interactive mode only — review mode never reaches here because it stops when tools are missing). Why we ask: Auto-starting the agent-driven review burns a large amount of tokens without consent; the user may prefer to install the tool and re-run instead. Cancel leaves: Nothing — no files read, no scan run.

Framing — all user-facing text (the warning, any AskUserQuestion option labels, and the summary): MUST NOT call this a "manual review". It is agent-driven — describe it as you reviewing the code yourself, e.g., "I can look through your code directly and flag issues."

Warn the user that this review reads many files and uses a large amount of tokens, then detect the git context:

  • Feature branch (not main, master, or equivalent): offer to review only the changes in the current branch (git diff <main-branch>...HEAD).
  • Main/master branch or no git repo: offer to review the entire project source.

If the user accepts, use Glob + Read + Grep to review the relevant files for common security patterns (hard-coded secrets, unsafe API usage, missing input validation, exposed endpoints, etc.) and present findings. Never surface a secret value anywhere — never output a credential's raw value in any output (your context, the session, chat, logs, etc.), not even partially; where a value would otherwise be shown, replace it with a mask (e.g. ********). Do not attempt to install the tools.


2. Choose scope

Skip in review mode — run both tools at Advanced depth.

Scope selection

Ask the following in order. Each is a separate AskUserQuestion call — do NOT combine. If the user's initial request already answers a question, skip it and move to the next.

<!-- gate: scan-code:2.scope-choice | category=plan | cancel-leaves=nothing -->

🚦 Gate (plan · scan-code:2.scope-choice): Choose what to scan — code, packages, or both — before running any tool. Determines which scanners run.

Trigger: Phase 2 entry (interactive mode only — review mode scans everything at Advanced depth without asking). Skipped if the initial request already names the scope. Why we ask: Auto-scanning everything can run tools the user did not want (e.g., a slow code pass when they only asked about packages); the wrong scope produces a report that misses what they cared about. Cancel leaves: Nothing — no scanner has run.

Question 1 — What to check?

LabelDescription
EverythingCheck both code and packages. (Recommended)
Code onlyCheck source files for security problems.
Packages onlyCheck installed packages for known issues.
<!-- gate: scan-code:2.depth-choice | category=plan | cancel-leaves=nothing -->

🚦 Gate (plan · scan-code:2.depth-choice): Choose how thorough the code check is. Only asked when code checking is included.

Trigger: Phase 2, after the scope choice includes code (interactive mode only). Skipped if the initial request already names the depth or code checking was excluded. Why we ask: The thorough option runs a deeper rule set that takes longer; auto-picking it can slow a large project unexpectedly, while auto-picking the quick option can silently skip weaknesses the user expected to catch. Cancel leaves: Nothing — no scanner has run.

Question 2 — Only if code checking is included: How thorough?

LabelDescription
AdvancedCovers common risks and deeper code weaknesses. (Recommended)
BasicCovers common risks only.

Depth mapping (internal, not shown to user): Advanced = p/default,p/owasp-top-ten,p/cwe-top-25. Basic = p/default,p/owasp-top-ten.

Show full SKILL.md (566 more words)Show less
Custom rules

Both tools accept custom rules. Do not proactively offer — only use when the user provides them.

  • Opengrep: --rulesets accepts comma-separated registry packs and local file paths. Custom rulesets are appended to the depth's defaults, not replacing them.
  • Trivy: --secretConfig for custom secret detection patterns, --ignoreFile for suppressing known findings, --trivyConfig for license classification and other settings, --no-licenseFull to skip source-level license scanning for faster runs.

3. Run scans

Save each tool's raw JSON output to a temporary file. The transform script in Step 4 normalizes them.

Static analysis (opengrep)
bash
node "${PLUGIN_ROOT}/skills/scan-code/scripts/run-opengrep.js" --projectRoot "<PROJECT_ROOT>" --rulesets "<comma-separated-rulesets>" > "<TEMP_DIR>/opengrep.json"

Pass the rulesets for the chosen depth (Basic or Advanced). Append any user-provided custom rulesets. Run with run_in_background: true for large projects.

Dependency / secret / license scanning (trivy)
bash
node "${PLUGIN_ROOT}/skills/scan-code/scripts/run-trivy.js" --projectRoot "<PROJECT_ROOT>" > "<TEMP_DIR>/trivy.json"

--licenseFull is on by default — source code headers and LICENSE files are scanned alongside package metadata. Run with run_in_background: true for large projects.

Normalize
bash
node "${PLUGIN_ROOT}/skills/scan-code/scripts/transform-scan-code.js" --opengrepFile "<TEMP_DIR>/opengrep.json" --trivyFile "<TEMP_DIR>/trivy.json" --projectRoot "<PROJECT_ROOT>"

Pass only the files for tools that actually ran. Stdout has the unified { status, findings } shape.


4. Summarize

4.1 Review mode

In review mode, write the transform-scan-code.js stdout to <REVIEW_DIR>/scan-code.json. Then stop — the orchestrating skill handles presentation.

4.2 Render HTML report

Skip in review mode.

Render uses the same shared template as the consolidated security review. First write the Step 3 Normalize stdout to <TEMP_DIR>/scan-code.json, then build a single-section review-data payload and render:

bash
node "${PLUGIN_ROOT}/scripts/build-review-data.js" \
  --reportName "Code Scan" \
  --inputDir "<TEMP_DIR>" \
  --siteName "<SITE_NAME>" \
  --goalLabel "Code & Packages scan" \
  --scopeLabel "<SCOPE_LABEL>" \
  --summary "<SUMMARY_TEXT>" \
  --output "<TEMP_DIR>/data.json"

node "${PLUGIN_ROOT}/scripts/render-review.js" \
  --data "<TEMP_DIR>/data.json" \
  --output "<PROJECT_ROOT>/docs/code-scan-<YYYY-MM-DD-HHMMSS>.html"

<TEMP_DIR> also holds the intermediate opengrep.json/trivy.json from Step 3 alongside scan-code.json; build-review-data.js reads only scan-code.json and ignores the rest. The filename must include the local timestamp (e.g., code-scan-2026-05-14-053805.html). Delete <TEMP_DIR> after the render succeeds. Open the rendered HTML in the browser.

4.3 Present summary

Skip in review mode.

Plain-language summary: total findings, count by category (code patterns, vulnerable packages, secrets, licenses), and what the user should look at first.

4.4 Record skill usage

Reference: ${PLUGIN_ROOT}/references/skill-tracking-reference.md

Use --skillName "ScanCode".

4.5 Offer follow-ups

If findings map to other skills, suggest them:

  • Header / cookie issues → /manage-headers
  • WAF / firewall issues → /manage-firewall
  • Permission issues → /audit-permissions to review existing permissions, and/or /create-webroles to set up role-based access
  • Login or external identity issues → /setup-auth
  • Code-level issues (exposed debug pages, information leakage) → suggest a manual code fix

If no meaningful follow-up exists, end the skill.


Constraints

  • Plain language — MUST NOT use technical jargon with the user. Never use words like opengrep, trivy, OWASP, CWE, static analysis, SAST, or ruleset in user-facing text. Use everyday language like "check your code for security problems", "check your packages for known issues", "thorough check", "quick check". Explain the technical name only when the user asks. For the tool-missing fallback, MUST NOT call it a "manual review" — it is agent-driven; describe it as you reviewing the code yourself.
  • Background long-running calls — run both tools via run_in_background: true for large projects.
  • Context-aware interactions — recommendations MUST reflect the site's actual scan results. Do not present generic advice.
  • Recommendations MUST NOT break the site — when suggesting fixes for code findings, verify that the fix does not introduce regressions.
  • NEVER recommend broadening security — if a finding suggests tightening (e.g., removing a hard-coded secret), do not suggest keeping it for convenience.
  • NEVER disclose a secret value — Never output, log, store, or repeat a raw secret anywhere, not even partially or when a regex/grep matches it. Identify a secret finding by its type, file, and line — not its value. Masking (e.g. ********) applies only where a secret value would otherwise be shown; you are not required to display it.

References

  • references/commands.md — script flags and response shapes. Read when constructing script invocations.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in plugins/power-pages/skills/scan-code of microsoft/power-platform-skills.

  • SKILL.md
  • references/commands.md
  • scripts/check-tools.js
  • scripts/run-opengrep.js
  • scripts/run-trivy.js
  • scripts/transform-scan-code.js

Open the folder on GitHubat commit 5ef4e4f

Compare with similar skills

Scan Code next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scan Code compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scan Code this skillmicrosoft/power-platform-skills967—~3.4kAutomated safety check: NotesMIT
Codexqa Rootcause Analyzeropenqa-cn/codexqa152—~2.6kAutomated safety check: PassApache-2.0
ReviewdogAgentSecOps/SecOpsAgentKit2191 repos~3kAutomated safety check: PassCustom licence
Code Review AI AI Reviewaiskillstore/marketplace4306 repos~3.9kAutomated safety check: PassNone
Trailmark Graph Evolutiontrailofbits/skills7.4k—~3.4kAutomated safety check: PassCC-BY-SA-4.0
Security Vulnerabilities Patcheraxelixlabs/axelix147—~4.2kAutomated safety check: PassLGPL-3.0

Similar skills

  • Diagnoses exception root causes from stack traces, logs, call-chain dumps, and debug output using the CodexQA CLI for structured repo analysis.

    152 GitHub stars~2.6k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Reviewdog

    AgentSecOps/SecOpsAgentKit

    Automated code review and security linting integration for CI/CD pipelines using reviewdog.

    219 GitHub starsUsed in 1 repo~3k tokens
    DevelopmentAuto-check passed
  • Code Review AI AI Review

    aiskillstore/marketplace

    You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices.

    430 GitHub starsUsed in 6 repos~3.9k tokens
    DevelopmentAuto-check passed
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Create batched Dependabot-style pull requests for GitHub security findings in axelixlabs/axelix, grouped by dependency surface such as master/front-end, master/build.gradle.kts, or starter Gradle…

    147 GitHub stars~4.2k tokensUpdated yesterday
    SecurityAuto-check passed
  • Refactorability

    meain/dotfiles

    Review code for refactorability — surface concrete, prioritized refactoring opportunities grounded in Martin Fowler's smell catalog and SOLID, augmented with static analysis tools (gocyclo…

    285 GitHub stars~2k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed

More from microsoft/power-platform-skills

All 87 skills in this repo
  • Manage Firewall

    microsoft/power-platform-skills

    Official

    Inspects and configures the web application firewall (WAF) in front of a Power Pages production site.

    967 GitHub stars~4.5k tokensUpdated today
    Auto-check: notes
  • Manage Headers

    microsoft/power-platform-skills

    Official

    Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…

    967 GitHub stars~3k tokensUpdated today
    Auto-check: notes
  • Scan Site

    microsoft/power-platform-skills

    Official

    Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.

    967 GitHub stars~3.2k tokensUpdated today
    Auto-check: notes
  • Setup Datamodel

    microsoft/power-platform-skills

    Official

    Creates Dataverse tables, columns, and relationships for a Power Pages site based on a data model proposal.

    967 GitHub stars~4k tokensUpdated today
    Auto-check: notes
  • Add Server Logic

    microsoft/power-platform-skills

    Official

    Creates, edits, and manages Power Pages Server Logic files — server-side JavaScript that runs securely on the Power Pages runtime.

    967 GitHub stars~18k tokensUpdated today
    Auto-check: notes
  • Activate Site

    microsoft/power-platform-skills

    Official

    Activates and provisions a Power Pages website in a Power Platform environment via the Power Platform REST API.

    967 GitHub starsUsed in 1 repo~5k tokens
    Auto-check: notes

Works with

Questions about Scan Code

What does Scan Code do?

Scans a Power Pages site project for security issues in source code and dependencies. Scan Code is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Scans a Power Pages site project for security issues in source code and dependencies.

When should I use Scan Code?

Scan Code fits situations like: the user wants to review code for security problems; check for vulnerable packages; find hard-coded secrets; run a code scan.

How do I install Scan Code in Claude Code?

Run `npx skills add microsoft/power-platform-skills --skill scan-code -a claude-code`. Or copy the skill folder (plugins/power-pages/skills/scan-code in microsoft/power-platform-skills) into .claude/skills/scan-code in your project. Claude Code loads it when a task matches its description.

How do I install Scan Code in Codex?

Run `npx skills add microsoft/power-platform-skills --skill scan-code -a codex`. Or copy the skill folder (plugins/power-pages/skills/scan-code in microsoft/power-platform-skills) into .agents/skills/scan-code in your project. Codex loads it when a task matches its description.

Can I use Scan Code in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/power-platform-skills --skill scan-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scan-code, .gemini/skills/scan-code, .github/skills/scan-code and .opencode/skills/scan-code in your project.

What does Scan Code need to run?

Going by SKILL.md and its folder, Scan Code needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and git). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList.

Does Scan Code access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Scan Code safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Scan Code use?

Scan Code is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scan Code use?

About 3.4k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 972 tokens, read only when the agent opens those files.

What are the alternatives to Scan Code?

Skills that share tags, products or a category with Scan Code: Codexqa Rootcause Analyzer (openqa-cn/codexqa, 152 stars), Reviewdog (AgentSecOps/SecOpsAgentKit, 219 stars), Code Review AI AI Review (aiskillstore/marketplace, 430 stars) and Trailmark Graph Evolution (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scan Code?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/power-platform-skills, which has 967 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/power-platform-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.