Agent skill

Powershell Safe Invocation

by Misaka-Mikoto-Tech in Misaka-Mikoto-Tech/agent-skills

A skill your agent uses when writing or running PowerShell on Windows, especially native programs, quoted paths, escaping, pwsh, Start-Process, file operations, or shell troubleshooting.

MITAuto-check passed

Install Powershell Safe Invocation

skills CLI
$ npx skills add Misaka-Mikoto-Tech/agent-skills --skill powershell-safe-invocation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Misaka-Mikoto-Tech/agent-skills powershell-safe-invocation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Misaka-Mikoto-Tech/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/powershell-safe-invocation .claude/skills/powershell-safe-invocation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
powershell-safe-invocation
GitHub stars
275
Used in
1 other repo
Token cost
~1.8k tokens
SKILL.md length
795 words
Files
2
Skills in repo
3
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when writing or running PowerShell on Windows, especially native programs, quoted paths, escaping, pwsh, Start-Process, file operations, or shell troubleshooting.

  • Works in 2 steps: Write a temporary .ps1 file. → Execute it with
  • Running PowerShell on Windows
  • SKILL.md covers Shell, Native Programs, Cmdlets and Complex Commands, plus 6 more sections
  • Calls pwsh and python

What it does

Powershell Safe Invocation is an agent skill from Misaka-Mikoto-Tech/agent-skills. Use when writing or running PowerShell on Windows, especially native programs, quoted paths, escaping, pwsh, Start-Process, file operations, or shell troubleshooting.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `reference.md`).

It works with PowerShell. The repository describes itself as: Reusable AI agent skills for Codex, including a PowerShell skill for safe Windows command invocation and optional MCP utilities. The licence is MIT.

When your agent uses it

  • Running PowerShell on Windows
  • Especially native programs
  • File operations
  • Shell troubleshooting

Example prompts

  • “/powershell-safe-invocation”

Requirements

  • Python 3

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Write a temporary .ps1 file.
  2. Execute it with

What it can do on your machine

Read from SKILL.md and the folder at commit 711abaf. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pwsh
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Powershell Safe Invocation loads about 1.8k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 795 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Misaka-Mikoto-Tech/agent-skills at commit 711abaf, republished under its MIT licence (© Misaka-Mikoto-Tech). 795 words, ~1,836 tokens.

Download SKILL.mdSave it as .claude/skills/powershell-safe-invocation/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
powershell-safe-invocation
description
Use when writing or running PowerShell on Windows, especially native programs, quoted paths, escaping, pwsh, Start-Process, file operations, or shell troubleshooting.

PowerShell Safe Invocation

Shell

Use PowerShell 7 through pwsh.exe unless Windows PowerShell 5.1 is explicitly required.

When the active shell is uncertain, verify:

powershell
$PSVersionTable.PSVersion
$PSNativeCommandArgumentPassing

Do not assume installing PowerShell 7 makes powershell.exe use PowerShell 7:

  • pwsh.exe = PowerShell 7
  • powershell.exe = Windows PowerShell 5.1

Native Programs

Never construct one large command string when arguments can be passed separately.

Use:

powershell
$exe = 'C:\Path With Spaces\tool.exe'
$argList = @(
    '--input'
    'C:\Data Folder\input.json'
    '--flag'
)

& $exe @argList

$exitCode = $LASTEXITCODE
if ($exitCode -ne 0) {
    throw "$exe failed with exit code $exitCode"
}

Rules:

  • Treat every native argument as one array item.
  • Invoke executable paths stored in variables with &.
  • Capture $LASTEXITCODE immediately.
  • Avoid using $args as your own argument array name; it is a PowerShell automatic variable. Use names like $argList or $nativeArgs.
  • Do not use Invoke-Expression.
  • Do not add a cmd.exe /c layer merely to launch an executable.
  • Do not use Bash-style \" escaping in PowerShell.

Cmdlets

Use hashtable splatting for PowerShell cmdlets:

powershell
$params = @{
    LiteralPath = 'C:\Data[1]\input.txt'
    Destination = 'C:\Output'
    Force       = $true
    ErrorAction = 'Stop'
}

Copy-Item @params

Use -LiteralPath for concrete paths when the cmdlet supports it. For cmdlets that expose only -Path, such as New-Item, use -Path; when unsure, check Get-Command <cmdlet> -Syntax.

Do not use $LASTEXITCODE to test a PowerShell cmdlet. Use terminating errors:

powershell
$ErrorActionPreference = 'Stop'

Wrap expressions passed as parameter values in parentheses or assign them first: use Select-Object -Index (100..120), not -Index 100..120.

Do not pipe directly from statement syntax such as foreach (...) { ... } | ...; assign the statement output first or use the pipeline cmdlet ForEach-Object.

Complex Commands

Avoid deeply quoted commands such as:

text
cmd.exe /c pwsh.exe -Command "..."

For multiline code, nested quotes, JSON, XML, regular expressions, pipelines, redirection, or non-ASCII paths:

  1. Write a temporary .ps1 file.
  2. Execute it with:
text
pwsh.exe -NoLogo -NoProfile -NonInteractive -File script.ps1

Prefer -File over -Command for anything beyond a short, simple expression.

Do not add -ExecutionPolicy Bypass unless execution policy is actually blocking a trusted script.

When you must pass a script through -Command from an outer PowerShell process, remember that the outer shell expands $variables first. Use an outer single-quoted script string when the inner script contains $p, $env:..., $PSVersionTable, or similar:

powershell
pwsh.exe -NoLogo -NoProfile -Command '$p = "C:\Data Folder\input.txt"; Test-Path -LiteralPath $p'

If the command has to cross multiple interpreters or wrappers, stop and write a .ps1 file instead of stacking more quoting.

Strings And Multiline Code

  • Use single quotes for literal strings and paths.
  • Use double quotes only when PowerShell expansion is needed.
  • Avoid backtick line continuation; use arrays, hashtables, splatting, parentheses, or script blocks.
  • Do not use Bash heredocs such as python - <<'PY'; PowerShell parses < differently. Use a temporary script file or a PowerShell here-string piped to the program.
  • For JSON, create objects and use ConvertTo-Json; do not hand-escape JSON.
  • Use single-quoted here-strings for literal multiline text: put no characters after opening @', and close with '@ alone at the start of a line.

Encoding

PowerShell 7 defaults to UTF-8 without BOM for text output; Windows PowerShell 5.1 defaults vary by cmdlet.

  • For a new text file consumed by another tool, specify its required encoding explicitly (usually utf8).
  • Before changing an existing text file, identify and preserve its existing encoding. Do not silently convert GBK, UTF-16, or BOM-sensitive files; if the encoding is unclear, inspect or ask.
  • Do not set Console.InputEncoding or Console.OutputEncoding by default. Set them only for a confirmed terminal or native-program encoding mismatch; $OutputEncoding instead controls PowerShell text sent to native programs.
  • Do not apply text encoding options to binary files. Use byte APIs for binary data.
Show full SKILL.md (278 more words)Show less

Start-Process

For normal foreground execution, use:

powershell
& $exe @argList

Use Start-Process only for elevation, new/hidden windows, detached launch, or shell behavior.

Start-Process -ArgumentList joins values into a command-line string and is not a reliable structured-argument API. Prefer ProcessStartInfo.ArgumentList when exact argument boundaries matter.

When a separate process is required and arguments are complex, use:

powershell
$psi = [System.Diagnostics.ProcessStartInfo]::new()
$psi.FileName = $exe
$psi.UseShellExecute = $false

foreach ($arg in $argList) {
    $psi.ArgumentList.Add($arg)
}

$process = [System.Diagnostics.Process]::Start($psi)
$process.WaitForExit()

if ($process.ExitCode -ne 0) {
    throw "Process failed with exit code $($process.ExitCode)"
}

File Operations

Before recursive delete, move, or overwrite:

  • Resolve the absolute root and target paths.
  • Verify the target is inside the intended root.
  • Reject empty, root-level, or unexpected paths.
  • Keep filesystem mutations in PowerShell instead of passing paths to another shell.

Mapped drives are per user/session. If Test-Path X:\... fails under an automation or sandbox account but works interactively, check the current identity with whoami and inspect Get-PSDrive. If the mapping is not visible, ask the user for the UNC path, establish the mapping for the same account, or switch the task to a current-user/full-access execution mode when the platform supports it.

Version And Module Differences

PowerShell 5.1 and PowerShell 7 can expose the same command with different parameters or command types. Verify syntax in the active shell before relying on version-specific parameters:

powershell
$PSVersionTable.PSVersion
Get-Command Format-Hex -Syntax
Get-Command Get-FileHash -Syntax

For example, Format-Hex -Count is available in PowerShell 7 but not in Windows PowerShell 5.1. In 5.1, use pipeline limiting instead:

powershell
Format-Hex -LiteralPath 'C:\Data\buffer.bin' | Select-Object -First 2

If command discovery behaves strangely, inspect $env:PSModulePath and Get-Module -ListAvailable <ModuleName> before assuming the cmdlet is missing.

Decision Order

Choose the simplest safe option:

  1. PowerShell cmdlet.
  2. & $exe @argList.
  3. Temporary .ps1 file with pwsh.exe -File.
  4. ProcessStartInfo.ArgumentList.
  5. Start-Process when its special behavior is required.
  6. cmd.exe /c only when cmd semantics are required.
  7. Invoke-Expression only as a tightly controlled last resort.

For uncommon cases and complete examples, read reference.md.

© Misaka-Mikoto-Tech, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/powershell-safe-invocation of Misaka-Mikoto-Tech/agent-skills.

  • SKILL.md
  • reference.md

Open the folder on GitHubat commit 711abaf

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Misaka-Mikoto-Tech/agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Powershell Safe Invocation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Powershell Safe Invocation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Powershell Safe Invocation this skillMisaka-Mikoto-Tech/agent-skills2751 repos~1.8kAutomated safety check: PassMIT
Pester Failure AnalysisPowerShell/PowerShell56k—~5.1kAutomated safety check: PassMIT
Copilot Session Failure Analysisdotnet/maui23k—~3.4kAutomated safety check: PassMIT
Windows App SDK Issue Triage Reportmicrosoft/WindowsAppSDK4.7k—~3.4kAutomated safety check: PassApache-2.0
Evaluate PR Testsdotnet/maui23k—~2.9kAutomated safety check: PassMIT
Translation ReviewDevolutions/UniGetUI26k—~1.3kAutomated safety check: PassMIT

Similar skills

  • Pester Failure Analysis

    PowerShell/PowerShell

    Investigates failing Pester tests in PowerShell CI jobs by following a six-step workflow from pull request status to documented fix recommendations.

    56k GitHub stars~5.1k tokensUpdated today
    Testing & QAAuto-check passed
  • Mines local Copilot CLI session logs for dotnet/maui to rank costly or failing runs, tag recurring failure modes, propose repo edits and emit guard evals.

    23k GitHub stars~3.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Official

    Generates GitHub Feature Area Status reports for the Windows App SDK repository, scoring issues so teams can see what needs attention in each area.

    4.7k GitHub stars~3.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Official

    Reviews the tests added in a pull request for fix coverage, quality, edge cases and test type, and recommends lighter test types where they would do.

    23k GitHub stars~2.9k tokensUpdated today
    Testing & QAAuto-check passed
  • Translation Review

    Devolutions/UniGetUI

    Reviews UniGetUI .json language files for localization quality, detects parity issues, English-equal entries, wrong-script content, and cross-language outliers, then generates a dataset for…

    26k GitHub stars~1.3k tokensUpdated today
    Frontend & DesignAuto-check passed
  • Pebrel Runtime

    Kuddev/pebrel

    Control the live Pebrel terminal workspace from Codex or Claude Code.

    3k GitHub stars~3.5k tokensUpdated today
    DevelopmentAuto-check passed

More from Misaka-Mikoto-Tech/agent-skills

  • Locus Unity Bridge

    Misaka-Mikoto-Tech/agent-skills

    A skill your agent uses when an agent needs to inspect or control a real Unity Editor through Locus, especially when Unity MCP is unavailable, named-pipe discovery is needed, C must be executed, or…

    275 GitHub stars~4k tokensUpdated 16 days ago
    Auto-check passed
  • Bilibili Page Reader

    Misaka-Mikoto-Tech/agent-skills

    Get content from Bilibili videos: official subtitles, danmaku (density/peaks/sample), comments.

    275 GitHub stars~3.6k tokensUpdated 16 days ago
    Auto-check passed

Works with

Questions about Powershell Safe Invocation

What does Powershell Safe Invocation do?

A skill your agent uses when writing or running PowerShell on Windows, especially native programs, quoted paths, escaping, pwsh, Start-Process, file operations, or shell troubleshooting. Powershell Safe Invocation is an agent skill from Misaka-Mikoto-Tech/agent-skills. Use when writing or running PowerShell on Windows, especially native programs, quoted paths, escaping, pwsh, Start-Process, file operations, or shell troubleshooting.

When should I use Powershell Safe Invocation?

Powershell Safe Invocation fits situations like: running PowerShell on Windows; especially native programs; file operations; shell troubleshooting.

How do I install Powershell Safe Invocation in Claude Code?

Run `npx skills add Misaka-Mikoto-Tech/agent-skills --skill powershell-safe-invocation -a claude-code`. Or copy the skill folder (skills/powershell-safe-invocation in Misaka-Mikoto-Tech/agent-skills) into .claude/skills/powershell-safe-invocation in your project. Claude Code loads it when a task matches its description.

How do I install Powershell Safe Invocation in Codex?

Run `npx skills add Misaka-Mikoto-Tech/agent-skills --skill powershell-safe-invocation -a codex`. Or copy the skill folder (skills/powershell-safe-invocation in Misaka-Mikoto-Tech/agent-skills) into .agents/skills/powershell-safe-invocation in your project. Codex loads it when a task matches its description.

Can I use Powershell Safe Invocation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Misaka-Mikoto-Tech/agent-skills --skill powershell-safe-invocation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/powershell-safe-invocation, .gemini/skills/powershell-safe-invocation, .github/skills/powershell-safe-invocation and .opencode/skills/powershell-safe-invocation in your project.

What does Powershell Safe Invocation need to run?

Going by SKILL.md and its folder, Powershell Safe Invocation needs the command-line tools its instructions call (pwsh and python). Our summary lists: Python 3.

Does Powershell Safe Invocation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Powershell Safe Invocation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Powershell Safe Invocation use?

Powershell Safe Invocation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Powershell Safe Invocation use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Powershell Safe Invocation?

Skills that share tags, products or a category with Powershell Safe Invocation: Pester Failure Analysis (PowerShell/PowerShell, 56k stars), Copilot Session Failure Analysis (dotnet/maui, 23k stars), Windows App SDK Issue Triage Report (microsoft/WindowsAppSDK, 4.7k stars) and Evaluate PR Tests (dotnet/maui, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Powershell Safe Invocation?

Misaka-Mikoto-Tech (a GitHub user) maintains it in Misaka-Mikoto-Tech/agent-skills, which has 275 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on September 21, 2026.

Source: Misaka-Mikoto-Tech/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.