Pnpm Engine
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
A skill your agent uses when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies…
$ npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install OfficeDev/microsoft-365-agents-toolkit component-governance-remediation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/OfficeDev/microsoft-365-agents-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/component-governance-remediation .claude/skills/component-governance-remediation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "component-governance-remediation" agent skill from https://github.com/OfficeDev/microsoft-365-agents-toolkit/tree/dev/.github/skills/component-governance-remediation into .claude/skills/component-governance-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "component-governance-remediation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/OfficeDev/microsoft-365-agents-toolkit/tree/dev/.github/skills/component-governance-remediationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install OfficeDev/microsoft-365-agents-toolkit component-governance-remediation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OfficeDev/microsoft-365-agents-toolkit.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/component-governance-remediation .agents/skills/component-governance-remediation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "component-governance-remediation" agent skill from https://github.com/OfficeDev/microsoft-365-agents-toolkit/tree/dev/.github/skills/component-governance-remediation into .agents/skills/component-governance-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "component-governance-remediation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install OfficeDev/microsoft-365-agents-toolkit component-governance-remediation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OfficeDev/microsoft-365-agents-toolkit.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/component-governance-remediation .cursor/skills/component-governance-remediation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "component-governance-remediation" agent skill from https://github.com/OfficeDev/microsoft-365-agents-toolkit/tree/dev/.github/skills/component-governance-remediation into .cursor/skills/component-governance-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "component-governance-remediation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/OfficeDev/microsoft-365-agents-toolkit.git --path .github/skills/component-governance-remediation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install OfficeDev/microsoft-365-agents-toolkit component-governance-remediation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OfficeDev/microsoft-365-agents-toolkit.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/component-governance-remediation .gemini/skills/component-governance-remediation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "component-governance-remediation" agent skill from https://github.com/OfficeDev/microsoft-365-agents-toolkit/tree/dev/.github/skills/component-governance-remediation into .gemini/skills/component-governance-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "component-governance-remediation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install OfficeDev/microsoft-365-agents-toolkit component-governance-remediationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/OfficeDev/microsoft-365-agents-toolkit.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/component-governance-remediation .github/skills/component-governance-remediation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "component-governance-remediation" agent skill from https://github.com/OfficeDev/microsoft-365-agents-toolkit/tree/dev/.github/skills/component-governance-remediation into .github/skills/component-governance-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "component-governance-remediation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install OfficeDev/microsoft-365-agents-toolkit component-governance-remediation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/OfficeDev/microsoft-365-agents-toolkit.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/component-governance-remediation .opencode/skills/component-governance-remediation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "component-governance-remediation" agent skill from https://github.com/OfficeDev/microsoft-365-agents-toolkit/tree/dev/.github/skills/component-governance-remediation into .opencode/skills/component-governance-remediation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "component-governance-remediation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
component-governance-remediationA skill your agent uses when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies…
Component Governance Remediation is an agent skill from OfficeDev/microsoft-365-agents-toolkit. Use when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies, package feed availability, snapshot filtering, lockfile updates, and alert dismissals.
Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/evals.json`, `evals/fixtures/alerts-response.json` and `references/ado-component-governance-api.md`).
It sits in Development, covering Dependency management. It works with Azure DevOps and pnpm. The repository describes itself as: Developer tools for building Teams apps.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c89a0dd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 2 files in scripts/ (PowerShell), which the agent can run.
Shell commands in SKILL.md call:
npxgitpnpmaznpmFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
packagefeedproxy.microsoft.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Component Governance Remediation loads about 3k tokens when it runs, and up to ~3.8k if it reads all its reference files. Until then it costs about 74 tokens; SKILL.md has 1,448 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,448 words (~2,996 tokens).
“Retrieve the exact active alert set represented by an Azure DevOps Component Governance page, map each alert to this repository's PNPM dependency graphs, remediate actionable versions, and leave auditable validation evidence without committing generated reports.”
SKILL.md and 5 other files (scripts, references) in .github/skills/component-governance-remediation of OfficeDev/microsoft-365-agents-toolkit.
Open the folder on GitHubat commit c89a0dd
Component Governance Remediation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Component Governance Remediation this skillOfficeDev/microsoft-365-agents-toolkit | 780 | — | ~3k | Automated safety check: Pass | Custom licence | |
| Pnpm Engineteambit/bit | 18k | — | ~1.9k | Automated safety check: Pass | Custom licence | |
| Linea Dependency MaintenanceConsensys-Incorporated/linea-attestation-registry | 177 | 1 repos | ~3.7k | Automated safety check: Warn | MIT | |
| Audit Threadnubjs/nub | 4.4k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Dependency Updategocronx-team/gocron | 801 | — | ~891 | Automated safety check: Pass | MIT | |
| Monorepo Tooling and Dependenciespierrecomputer/pierre | 6.3k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 |
teambit/bit
Work on the pnpm Rust engine (@pnpm/napi, the pacquet crates) that bit install runs through.
Consensys-Incorporated/linea-attestation-registry
Safely plan and execute dependency maintenance for JavaScript/TypeScript (npm, pnpm) and GitHub Actions, including npm lockfiles, pnpm workspaces, catalogs, overrides, SHA-pinned action versions…
nubjs/nub
A skill your agent uses when running a compatibility/parity AUDIT — enumerating where nub diverges from a reference it claims parity with (pnpm CLI grammar, a lockfile format, a Node behavior, a…
gocronx-team/gocron
Review, apply, verify, or merge gocron dependency updates from Dependabot or manual requests.
pierrecomputer/pierre
Sets one monorepo's rules for toolchain pins, pnpm package operations, the shared dependency catalog and moon tasks, so the agent adds versions and scripts the right way.
ossf/oss-crs
Read every open Dependabot PR for an application-code dependency (Python pip/uv and JS npm/yarn/pnpm) and carry each version bump over to the local dependency files (requirements.txt…
OfficeDev/microsoft-365-agents-toolkit
Builds, tests, and deploys Microsoft 365 apps and agents for Teams and Copilot.
OfficeDev/microsoft-365-agents-toolkit
A skill your agent uses when: running an existing vscuse test case, reproducing a failing vscuse plan, deciding product bug vs test plan drift vs setup failure vs flake, repairing a failing case…
OfficeDev/microsoft-365-agents-toolkit
A skill your agent uses when: reading a docs scenario, PRD, mockup, or user flow and using vscuse-ui/noVNC as the primary authoring surface to record, generate, replace, or update vscuse test plans…
OfficeDev/microsoft-365-agents-toolkit
A skill your agent uses when adding or changing product requirements, scenarios, user flows, surface behavior, or design artifacts before specs or implementation.
OfficeDev/microsoft-365-agents-toolkit
End-to-end workflow for agent-driven changes that add or modify behavior in the toolkit packages.
OfficeDev/microsoft-365-agents-toolkit
A skill your agent uses when: setting up shared local vscuse prerequisites, credentials, runner, local or pinned published Docker images, local VSIX, env variables, and common rules for Microsoft…
Works with
Categories
A skill your agent uses when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies…. Component Governance Remediation is an agent skill from OfficeDev/microsoft-365-agents-toolkit. Use when: retrieving, exporting, triaging, or remediating Azure DevOps Component Governance alerts for this repository, including CG report URLs, vulnerable pnpm dependencies, package feed availability, snapshot filtering, lockfile updates, and alert dismissals.
Component Governance Remediation fits situations like: remediating Azure DevOps Component Governance alerts for this repository; including CG report URLs; vulnerable pnpm dependencies; package feed availability.
Run `npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a claude-code`. Or copy the skill folder (.github/skills/component-governance-remediation in OfficeDev/microsoft-365-agents-toolkit) into .claude/skills/component-governance-remediation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a codex`. Or copy the skill folder (.github/skills/component-governance-remediation in OfficeDev/microsoft-365-agents-toolkit) into .agents/skills/component-governance-remediation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add OfficeDev/microsoft-365-agents-toolkit --skill component-governance-remediation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/component-governance-remediation, .gemini/skills/component-governance-remediation, .github/skills/component-governance-remediation and .opencode/skills/component-governance-remediation in your project.
Going by SKILL.md and its folder, Component Governance Remediation needs PowerShell for the scripts in its folder and the command-line tools its instructions call (npx, git, pnpm, az and npm). Our summary lists: Node.js; PowerShell.
SKILL.md names 1 domain. In commands or code: packagefeedproxy.microsoft.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Component Governance Remediation has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.
About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 827 tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Component Governance Remediation: Pnpm Engine (teambit/bit, 18k stars), Linea Dependency Maintenance (Consensys-Incorporated/linea-attestation-registry, 177 stars), Audit Thread (nubjs/nub, 4.4k stars) and Dependency Update (gocronx-team/gocron, 801 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
OfficeDev (a GitHub organization) maintains it in OfficeDev/microsoft-365-agents-toolkit, which has 780 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 10, 2026.
Source: OfficeDev/microsoft-365-agents-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.