Agent skill

Component Governance Remediation

by OfficeDev in OfficeDev/microsoft-365-agents-toolkit

A skill your agent uses when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies…

Custom licenceAuto-check passedDevelopment

Install Component Governance Remediation

skills CLI
$ npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install OfficeDev/microsoft-365-agents-toolkit component-governance-remediation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/OfficeDev/microsoft-365-agents-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/component-governance-remediation .claude/skills/component-governance-remediation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
component-governance-remediation
GitHub stars
780
Token cost
~3k tokens
SKILL.md length
1,448 words
Files
6 (incl. scripts, references)
Skills in repo
7
Repo updated
First seen
Licence
Custom licence

At a glance

A skill your agent uses when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies…

  • Works in 3 steps: Top-level alertState is active. → A stateDetails entry has alertState ==… → The same state entry has the report's…
  • Remediating Azure DevOps Component Governance alerts for this repository
  • SKILL.md covers Goal, Inputs, Retrieve Active Alerts and Triage, plus 4 more sections
  • Runs PowerShell scripts from its folder; calls npx, git and pnpm; reaches packagefeedproxy.microsoft.io

What it does

Component Governance Remediation is an agent skill from OfficeDev/microsoft-365-agents-toolkit. Use when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies, package feed availability, snapshot filtering, lockfile updates, and alert dismissals.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/evals.json`, `evals/fixtures/alerts-response.json` and `references/ado-component-governance-api.md`).

It sits in Development, covering Dependency management. It works with Azure DevOps and pnpm. The repository describes itself as: Developer tools for building Teams apps.

When your agent uses it

  • Remediating Azure DevOps Component Governance alerts for this repository
  • Including CG report URLs
  • Vulnerable pnpm dependencies
  • Package feed availability

Example prompts

  • “/component-governance-remediation”

Requirements

  • Node.js
  • PowerShell

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Top-level alertState is active.
  2. A stateDetails entry has alertState == active.
  3. The same state entry has the report's snapshotTypeId.

What it can do on your machine

Read from SKILL.md and the folder at commit c89a0dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (PowerShell), which the agent can run.

    Shell commands in SKILL.md call:

    • npx
    • git
    • pnpm
    • az
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • packagefeedproxy.microsoft.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Component Governance Remediation loads about 3k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 1,448 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~74
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,448 words (~2,996 tokens).

“Retrieve the exact active alert set represented by an Azure DevOps Component Governance page, map each alert to this repository's PNPM dependency graphs, remediate actionable versions, and leave auditable validation evidence without committing generated reports.”

— opening of SKILL.md by OfficeDev, Custom licence
name
component-governance-remediation
argument-hint
Provide the Component Governance report URL and whether to retrieve, triage, or remediate alerts

Read the full SKILL.md on GitHub

Files

SKILL.md and 5 other files (scripts, references) in .github/skills/component-governance-remediation of OfficeDev/microsoft-365-agents-toolkit.

  • SKILL.md
  • evals/evals.json
  • evals/fixtures/alerts-response.json
  • references/ado-component-governance-api.md
  • scripts/get-active-alerts.ps1
  • scripts/test-get-active-alerts.ps1

Open the folder on GitHubat commit c89a0dd

Compare with similar skills

Component Governance Remediation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Component Governance Remediation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Component Governance Remediation this skillOfficeDev/microsoft-365-agents-toolkit780—~3kAutomated safety check: PassCustom licence
Pnpm Engineteambit/bit18k—~1.9kAutomated safety check: PassCustom licence
Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry1771 repos~3.7kAutomated safety check: WarnMIT
Audit Threadnubjs/nub4.4k—~1.8kAutomated safety check: PassMIT
Dependency Updategocronx-team/gocron801—~891Automated safety check: PassMIT
Monorepo Tooling and Dependenciespierrecomputer/pierre6.3k—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Pnpm Engine

    teambit/bit

    Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.

    18k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Linea Dependency Maintenance

    Consensys-Incorporated/linea-attestation-registry

    Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…

    177 GitHub starsUsed in 1 repo~3.7k tokens
    DevelopmentAuto-check: warnings
  • Audit Thread

    nubjs/nub

    A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…

    4.4k GitHub stars~1.8k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Dependency Update

    gocronx-team/gocron

    Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests.

    801 GitHub stars~891 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.

    6.3k GitHub stars~1.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…

    165 GitHub stars~1.7k tokensUpdated yesterday
    DevelopmentAuto-check: notes

More from OfficeDev/microsoft-365-agents-toolkit

  • Microsoft 365 Agents Toolkit

    OfficeDev/microsoft-365-agents-toolkit

    Builds, tests, and deploys Microsoft 365 apps and agents for Teams and Copilot.

    780 GitHub stars~2.8k tokensUpdated yesterday
    Auto-check: notes
  • Vscuse Case Diagnosis

    OfficeDev/microsoft-365-agents-toolkit

    A skill your agent uses when: running an existing vscuse test case, reproducing a failing vscuse plan, deciding product bug vs test plan drift vs setup failure vs flake, repairing a failing case…

    780 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed
  • Vscuse Scenario Authoring

    OfficeDev/microsoft-365-agents-toolkit

    A skill your agent uses when: reading a docs scenario, PRD, mockup, or user flow and using vscuse-ui/noVNC as the primary authoring surface to record, generate, replace, or update vscuse test plans…

    780 GitHub stars~4.3k tokensUpdated yesterday
    Auto-check passed
  • Prd UX Design

    OfficeDev/microsoft-365-agents-toolkit

    A skill your agent uses when adding or changing product requirements, scenarios, user flows, surface behavior, or design artifacts before specs or implementation.

    780 GitHub stars~8.1k tokensUpdated yesterday
    Auto-check passed
  • Vibe Coding

    OfficeDev/microsoft-365-agents-toolkit

    End-to-end workflow for agent-driven changes that add or modify behavior in the toolkit packages.

    780 GitHub stars~5.5k tokensUpdated yesterday
    Auto-check passed
  • Local Vscuse Validation

    OfficeDev/microsoft-365-agents-toolkit

    A skill your agent uses when: setting up shared local vscuse prerequisites, credentials, runner, local or pinned published Docker images, local VSIX, env variables, and common rules for Microsoft…

    780 GitHub stars~10k tokensUpdated yesterday
    Auto-check: warnings

Categories

Questions about Component Governance Remediation

What does Component Governance Remediation do?

A skill your agent uses when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies…. Component Governance Remediation is an agent skill from OfficeDev/microsoft-365-agents-toolkit. Use when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies, package feed availability, snapshot filtering, lockfile updates, and alert dismissals.

When should I use Component Governance Remediation?

Component Governance Remediation fits situations like: remediating Azure DevOps Component Governance alerts for this repository; including CG report URLs; vulnerable pnpm dependencies; package feed availability.

How do I install Component Governance Remediation in Claude Code?

Run `npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a claude-code`. Or copy the skill folder (.github/skills/component-governance-remediation in OfficeDev/microsoft-365-agents-toolkit) into .claude/skills/component-governance-remediation in your project. Claude Code loads it when a task matches its description.

How do I install Component Governance Remediation in Codex?

Run `npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a codex`. Or copy the skill folder (.github/skills/component-governance-remediation in OfficeDev/microsoft-365-agents-toolkit) into .agents/skills/component-governance-remediation in your project. Codex loads it when a task matches its description.

Can I use Component Governance Remediation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/component-governance-remediation, .gemini/skills/component-governance-remediation, .github/skills/component-governance-remediation and .opencode/skills/component-governance-remediation in your project.

What does Component Governance Remediation need to run?

Going by SKILL.md and its folder, Component Governance Remediation needs PowerShell for the scripts in its folder and the command-line tools its instructions call (npx, git, pnpm, az and npm). Our summary lists: Node.js; PowerShell.

Does Component Governance Remediation access the network?

SKILL.md names 1 domain. In commands or code: packagefeedproxy.microsoft.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Component Governance Remediation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Component Governance Remediation use?

Component Governance Remediation has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Component Governance Remediation use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 827 tokens, read only when the agent opens those files.

What are the alternatives to Component Governance Remediation?

Skills that share tags, products or a category with Component Governance Remediation: Pnpm Engine (teambit/bit, 18k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Audit Thread (nubjs/nub, 4.4k stars) and Dependency Update (gocronx-team/gocron, 801 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Component Governance Remediation?

OfficeDev (a GitHub organization) maintains it in OfficeDev/microsoft-365-agents-toolkit, which has 780 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 10, 2026.

Source: OfficeDev/microsoft-365-agents-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.