Official agent skill

Scan Site

by microsoft in microsoft/power-platform-skills

Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.

OfficialMITAuto-check: notesSecurity

Install Scan Site

skills CLI
$ npx skills add microsoft/power-platform-skills --skill scan-site -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/power-platform-skills scan-site --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/power-platform-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/power-pages/skills/scan-site .claude/skills/scan-site && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
scan-site
GitHub stars
967
Token cost
~3.2k tokens
SKILL.md length
1,504 words
Files
7 (incl. scripts, references)
Skills in repo
87
Repo updated
First seen
Licence
MIT

At a glance

Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.

  • Works in 6 steps: Prerequisites → Check scan state → Choose an action → …
  • The user wants to scan
  • SKILL.md covers Gotchas, Workflow, Task Tracking and 1. Prerequisites, plus 7 more sections
  • Runs JavaScript scripts from its folder; calls node and az

What it does

Scan Site is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. Scans the live site's public surface for vulnerabilities and surfaces issues by severity. Use when the user wants to scan, check, test, audit, or assess a published site, find vulnerabilities on production, view the latest scan report, see previous scan results, run a security audit, or asks "how safe is my live site?", "is my site vulnerable?", "audit my production site" — even if they say…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `references/commands.md`, `references/scan-reference.md` and `scripts/get-latest-report.js`).

It sits in Security, covering Security review and Plain language and style rules. The repository describes itself as: A plugin marketplace for GitHub Copilot and other AI agents that provides Power Platform development plugins, including reusable skills, agents, and commands for building and… The licence is MIT.

When your agent uses it

  • The user wants to scan
  • Assess a published site
  • Find vulnerabilities on production
  • View the latest scan report

Example prompts

  • “how safe is my live site?”
  • “is my site vulnerable?”
  • “audit my production site”
  • “/scan-site”

Requirements

  • Node.js
  • Pre-approved tools (allowed-tools): Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Prerequisites
  2. Check scan state
  3. Choose an action
  4. Run the scan
  5. Fetch and summarize
  6. Walk through follow-ups

What it can do on your machine

Read from SKILL.md and the folder at commit 5ef4e4f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Glob
    • Grep
    • AskUserQuestion
    • TaskCreate
    • TaskUpdate
    • TaskList

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 4 files in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Scan Site loads about 3.2k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 152 tokens; SKILL.md has 1,504 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~152
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from microsoft/power-platform-skills at commit 5ef4e4f, republished under its MIT licence (© microsoft). 1,504 words, ~3,179 tokens.

Download SKILL.mdSave it as .claude/skills/scan-site/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
scan-site
description
Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. Scans the live site's public surface for vulnerabilities and surfaces issues by severity. Use when the user wants to scan, check, test, audit, or assess a published site, find vulnerabilities on production, view the latest scan report, see previous scan results, run a security audit, or asks "how safe is my live site?", "is my site vulnerable?", "audit my production site" — even if they say "find issues" or "check for problems" without mentioning "scan" or "security".
allowed-tools
Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList
user-invocable
true
argument-hint
[optional: --review <out-dir>]
model
opus

Plugin check: Run node "${PLUGIN_ROOT}/scripts/check-version.js" — if it outputs a message, show it to the user before proceeding.

Scan Site

Run a security scan on a deployed Power Pages site, fetch the latest scan report, and surface findings in a plain-language summary. The scan runs server-side; duration depends on site size — small sites finish in minutes, large sites can take hours.

This skill scans the live deployed site, not local source code.

Initial request: $ARGUMENTS

Gotchas

  • Website record id vs portal id. .powerpages-site/website.yml stores the website record id, not the portal id. Every script takes --portalId. Resolve once via website.js --websiteId during prerequisites.
  • Never resolve by name. Site names can duplicate inside an environment; only the website record id is safe.
  • null from the resolver means the site is not deployed, or the authenticated profile points at a different environment.
  • Scans are long-running. Duration depends on site size — small sites finish in minutes, large sites can take hours. Poll in the background and increase --timeoutMinutes for large sites.
  • Only one scan per site at a time. A start while a scan is running returns Z003 — start-deep-scan.js reports it as { "status": "already-running" } (exit 0).
  • Rate limits may apply. The service may throttle repeated scans on the same site. When throttled, wait and retry later.
  • No completed scan yet. A fresh site or a site mid-scan has no completed report — get-latest-report.js returns { "status": "empty" }.

Workflow

  1. Prerequisites — Locate project, confirm sign-in, identify site
  2. Check scan state — Detect whether a scan is currently running
  3. Choose an action — Context-aware recommendation (run new scan / show latest)
  4. Run the scan — Start and poll for completion
  5. Fetch and summarize — Get the report, present findings
  6. Walk through follow-ups — Route issues to the right downstream skill (only if the report contains issues)

Task Tracking

Create tasks in four groups. Mark each in_progress when starting, completed when done.

GroupWhen to createTasks
1At startCheck prerequisites
2After prerequisites passCheck scan state · Choose an action (skip in review mode)
3After user confirms an action (or in review mode)Run the scan (skip only if the user chose to view latest results in interactive mode) · Fetch and summarize (always)
4After fetch and summarizeWalk through follow-ups (only if the report contains issues AND not in review mode)

1. Prerequisites

1.1 Locate the project, detect review mode

Use Glob to find **/powerpages.config.json. If $ARGUMENTS contains --review <out-dir>, remember the output directory — Step 3 (choose an action) is skipped, Step 4 (run scan) executes automatically (start a fresh scan or attach to a running one), Step 5 writes JSON only, and Step 6 (follow-ups) is skipped.

1.2 Resolve site identifiers

Read .powerpages-site/website.yml → extract id field → that is <WEBSITE_ID>.

If missing, the site has not been deployed. Tell the user and recommend /deploy-site. Stop. Do not resolve by name or URL.

Resolve to portalId:

bash
node "${PLUGIN_ROOT}/scripts/website.js" --websiteId "<WEBSITE_ID>"

Capture Id (portalId), Type, Name, WebsiteUrl. If exit code 2 → sign-in required (pac auth create or az login). If null → site not found in this environment. Stop in either case.


2. Check scan state

bash
node "${PLUGIN_ROOT}/skills/scan-site/scripts/poll-deep-scan.js" --portalId "<PORTAL_ID>" --once

--once does a single status check, exits 0, and prints:

  • { "status": "ongoing" } → a scan is currently running.
  • { "status": "idle" } → no scan running.

Then call get-latest-report.js to know whether a completed report exists:

bash
node "${PLUGIN_ROOT}/skills/scan-site/scripts/get-latest-report.js" --portalId "<PORTAL_ID>"

{ "status": "ok" } means a report is available. { "status": "empty" } means no completed scan exists.


3. Choose an action

Skip in review mode — go straight to Step 4 (which always runs in review mode).

MUST use plain language only. Never use words like CSP, CORS, OWASP, hardening, or scan profile.

Default approach
<!-- gate: scan-site:3.action-choice | category=plan | cancel-leaves=nothing -->

🚦 Gate (plan · scan-site:3.action-choice): Recommend an action based on the site's scan state (running, idle, has report, no report), then ask the user to accept or choose differently. Starting a new scan triggers a multi-minute backend run; using an existing report is free.

Trigger: Phase 3 entry (interactive mode only — review mode bypasses to step 4). Why we ask: Auto-starting a new scan wastes minutes if a recent report already answers the question; auto-using a stale report misses recent findings. Cancel leaves: Nothing — no scan triggered, no report consumed.

Analyze the site's current state and recommend the single most relevant action via AskUserQuestion:

  • Scan running, no completed report → recommend waiting for the running scan to finish.
  • Scan running, report exists → recommend showing the latest results while the new scan continues.
  • Idle, no completed report → recommend running a new scan.
  • Idle, recent report exists → ask whether to use the existing report or run a fresh scan.

If the site's state does not warrant a specific recommendation, do not force one — ask what the user wants to do.

Option rules
<!-- not-a-gate: meta-documentation describing how to structure `AskUserQuestion` options in this skill — not a literal call site. The actual prompt ("use existing report / run a fresh scan") fires dynamically in §3 Default approach. See approval-gates.md §6.24a + §6.27. -->

When presenting options via AskUserQuestion:

  • Keep label to 1–5 words. Include description on every option.
  • For options that trigger a new scan, surface the relevant caveats inside that option's description so the user has them at decision time. Do not ask a separate confirmation question after the user picks the option.
  • Include preview only when the option represents a concrete change (starting a new scan). Do not add preview to "show latest" or informational choices.
  • Only show options that are actionable given the current state. If a scan is already running, do not offer "Start a new scan".
  • Mark "(Recommended)" only when the site's state justifies it.

Show full SKILL.md (624 more words)Show less

4. Run the scan

In review mode, always execute this step: if a scan is already running, attach to it and poll; otherwise start a fresh scan and poll. Do not ask — review mode runs end-to-end without user interaction.

In interactive mode, skip if the user chose to view the latest results.

Start the scan:

bash
node "${PLUGIN_ROOT}/skills/scan-site/scripts/start-deep-scan.js" --portalId "<PORTAL_ID>"

If stdout is { "status": "already-running" }, skip ahead to polling — there is already a scan in progress.

Then poll for completion:

bash
node "${PLUGIN_ROOT}/skills/scan-site/scripts/poll-deep-scan.js" --portalId "<PORTAL_ID>"

Run polling with run_in_background: true so the user can keep working. The script exits when the scan finishes or the timeout passes (default 20 minutes). If it times out, fetch whatever report is available and note the timeout in the summary.


5. Fetch and summarize

5.1 Fetch and transform the report
bash
node "${PLUGIN_ROOT}/skills/scan-site/scripts/transform-report.js" --portalId "<PORTAL_ID>"

Parse the stdout JSON. The status field can be:

  • ok — a normal report with findings and details.
  • empty — no completed scan exists for this site (e.g., fresh site or scan still running). Record a single info finding explaining this and continue.
  • malformed — the API returned a response missing the Rules array. The transform emits a single warning finding describing this; surface it to the user and recommend re-running the scan.

See references/scan-reference.md for the Risk → severity mapping the script applies.

5.2 Review mode

In review mode, skip the HTML report and write the transform stdout to <REVIEW_DIR>/scan-site.json. Then stop. The transform emits { status, findings, details }; the orchestrating skill handles presentation.

5.3 Render HTML report

Skip in review mode.

Render uses the same shared template as the consolidated security review. Build a single-section review-data payload, then render:

bash
node "${PLUGIN_ROOT}/scripts/build-review-data.js" \
  --reportName "Site Scan" \
  --inputDir "<TEMP_DIR>" \
  --siteName "<SITE_NAME>" \
  --goalLabel "Live Site Scan" \
  --scopeLabel "<SCOPE_LABEL>" \
  --summary "<SUMMARY_TEXT>" \
  --output "<TEMP_DIR>/data.json"

node "${PLUGIN_ROOT}/scripts/render-review.js" \
  --data "<TEMP_DIR>/data.json" \
  --output "<PROJECT_ROOT>/docs/site-scan-<YYYY-MM-DD-HHMMSS>.html"

<TEMP_DIR> should contain only scan-site.json (the transform output from Step 5.1) — build-review-data.js ignores intermediate files. The filename must include the local timestamp (e.g., site-scan-2026-05-14-053805.html). Delete <TEMP_DIR> after the render succeeds. Open the rendered HTML in the browser.

5.4 Present summary

Plain-language summary in the chat: total findings, count by severity, and what changed since the last scan if available. Do not lead with technical names.

5.5 Record skill usage

Reference: ${PLUGIN_ROOT}/references/skill-tracking-reference.md

Use --skillName "ScanSite".


6. Walk through follow-ups

Skip in review mode. Skip if the report has no issues.

Group findings by which downstream skill can help:

  • Header / cookie issues → /manage-headers
  • WAF / firewall issues (block bots, rate-limit pages, restrict IPs/countries) → /manage-firewall
  • Permission issues → /audit-permissions to review existing table permissions, and/or /create-webroles to set up role-based access
  • Login or external identity issues → /setup-auth
  • Code-level issues (exposed debug pages, information leakage, source visible publicly) → suggest a manual code fix; there is no routed skill for these findings

Suggest only the skills that match findings actually present in the report. If a finding does not map to any skill, surface it as a manual follow-up the user can act on. If no meaningful follow-up exists, end the skill — do not ask just to ask.


Constraints

  • Plain language — MUST NOT use technical jargon with the user. Use everyday language; explain the technical name only when asked.
  • Read-only — this skill only runs scans and reads results. It never enables WAF, deletes scans, or changes site configuration.
  • Background long-running calls — start the scan, then poll via run_in_background: true so the user can continue working.
  • Context-aware interactions — every recommendation MUST reflect the site's current state:
    • Never offer "Start a new scan" while one is already running.
    • Never offer "Show latest results" when no completed report exists.
    • Mark "(Recommended)" only when the state justifies it.
  • Preview is for change review only — include preview only on options that start a new scan. Do not add to navigation or informational choices.

References

  • references/commands.md — script flags, response shapes, error catalogue, operating notes. Read § "Common error catalogue" when a script returns a non-zero exit code.
  • references/scan-reference.md — field-level schema for the deep-scan report, alert risk values, rule statuses, and severity mapping. Read when normalizing findings.

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in plugins/power-pages/skills/scan-site of microsoft/power-platform-skills.

  • SKILL.md
  • references/commands.md
  • references/scan-reference.md
  • scripts/get-latest-report.js
  • scripts/poll-deep-scan.js
  • scripts/start-deep-scan.js
  • scripts/transform-report.js

Open the folder on GitHubat commit 5ef4e4f

Compare with similar skills

Scan Site next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Scan Site compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Scan Site this skillmicrosoft/power-platform-skills967—~3.2kAutomated safety check: NotesMIT
Rational Red Blue Debatedigoal/blog8.6k—~2.2kAutomated safety check: PassGPL-2.0
Deepsec Documentation Guidevercel-labs/deepsec8.1k—~956Automated safety check: PassApache-2.0
Kubernetes Network Security Auditkubeshark/kubeshark12k—~7.3kAutomated safety check: NotesApache-2.0
Native Dependency Updatemono/SkiaSharp5.6k—~4.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0

Similar skills

  • Answer general or cross-domain questions with a non-pleasing rational mode: adversarial red-team and blue-team expert analysis, mutually exclusive conclusions, up to five debate rounds, saved…

    8.6k GitHub stars~2.2k tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Deepsec Documentation Guide

    vercel-labs/deepsec

    Official

    Points the agent at deepsec's own docs to answer questions about initializing, configuring, resuming, scanning with and extending the vulnerability scanner.

    8.1k GitHub stars~956 tokensUpdated 8 days ago
    SecurityAuto-check passed
  • Hunts for compromised workloads and malicious traffic in a Kubernetes cluster by sweeping network data through Kubeshark MCP, mapped to MITRE ATT&CK.

    12k GitHub stars~7.3k tokensUpdated 6 days ago
    SecurityAuto-check: notes
  • Update native dependencies (libpng, libexpat, zlib, libwebp, harfbuzz, freetype, libjpeg-turbo, etc.) in SkiaSharp's Skia fork.

    5.6k GitHub stars~4.1k tokensUpdated today
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Skillward Audit

    Fangcun-AI/SkillWard

    Security-audit a third-party skill bundle (folder with SKILL.md, or .zip / .tar.gz archive) before installing it, using the SkillWard cloud scanner.

    143 GitHub stars~2.9k tokensUpdated 2 mo ago
    SecurityAuto-check passed

More from microsoft/power-platform-skills

All 87 skills in this repo
  • Manage Firewall

    microsoft/power-platform-skills

    Official

    Inspects and configures the web application firewall (WAF) in front of a Power Pages production site.

    967 GitHub stars~4.5k tokensUpdated today
    Auto-check: notes
  • Manage Headers

    microsoft/power-platform-skills

    Official

    Inspects and configures the security headers a Power Pages site sends to browsers — Content Security Policy, frame and clickjacking protection, cross-origin sharing, cookie behavior, and related…

    967 GitHub stars~3k tokensUpdated today
    Auto-check: notes
  • Scan Code

    microsoft/power-platform-skills

    Official

    Scans a Power Pages site project for security issues in source code and dependencies.

    967 GitHub stars~3.4k tokensUpdated today
    Auto-check: notes
  • Setup Datamodel

    microsoft/power-platform-skills

    Official

    Creates Dataverse tables, columns, and relationships for a Power Pages site based on a data model proposal.

    967 GitHub stars~4k tokensUpdated today
    Auto-check: notes
  • Add Server Logic

    microsoft/power-platform-skills

    Official

    Creates, edits, and manages Power Pages Server Logic files — server-side JavaScript that runs securely on the Power Pages runtime.

    967 GitHub stars~18k tokensUpdated today
    Auto-check: notes
  • Activate Site

    microsoft/power-platform-skills

    Official

    Activates and provisions a Power Pages website in a Power Platform environment via the Power Platform REST API.

    967 GitHub starsUsed in 1 repo~5k tokens
    Auto-check: notes

Questions about Scan Site

What does Scan Site do?

Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. Scan Site is an agent skill from microsoft/power-platform-skills, published by the product's own GitHub organization. Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.

When should I use Scan Site?

Scan Site fits situations like: the user wants to scan; assess a published site; find vulnerabilities on production; view the latest scan report.

How do I install Scan Site in Claude Code?

Run `npx skills add microsoft/power-platform-skills --skill scan-site -a claude-code`. Or copy the skill folder (plugins/power-pages/skills/scan-site in microsoft/power-platform-skills) into .claude/skills/scan-site in your project. Claude Code loads it when a task matches its description.

How do I install Scan Site in Codex?

Run `npx skills add microsoft/power-platform-skills --skill scan-site -a codex`. Or copy the skill folder (plugins/power-pages/skills/scan-site in microsoft/power-platform-skills) into .agents/skills/scan-site in your project. Codex loads it when a task matches its description.

Can I use Scan Site in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/power-platform-skills --skill scan-site -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/scan-site, .gemini/skills/scan-site, .github/skills/scan-site and .opencode/skills/scan-site in your project.

What does Scan Site need to run?

Going by SKILL.md and its folder, Scan Site needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and az). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList.

Does Scan Site access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Scan Site safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Scan Site use?

Scan Site is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Scan Site use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.9k tokens, read only when the agent opens those files.

What are the alternatives to Scan Site?

Skills that share tags, products or a category with Scan Site: Rational Red Blue Debate (digoal/blog, 8.6k stars), Deepsec Documentation Guide (vercel-labs/deepsec, 8.1k stars), Kubernetes Network Security Audit (kubeshark/kubeshark, 12k stars) and Native Dependency Update (mono/SkiaSharp, 5.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Scan Site?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/power-platform-skills, which has 967 GitHub stars. The repository holds 87 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/power-platform-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.