Agent skill

Copilot Toolbox

by pnp in pnp/sharepoint-skills

Creates, initializes, synchronizes, repairs, and publishes the portable English Copilot Toolbox, including its list, review workflow, Toolbox.aspx, and English HTML Toolbook.

MITAuto-check passedDocuments & Office

Install Copilot Toolbox

skills CLI
$ npx skills add pnp/sharepoint-skills --skill copilot-toolbox -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pnp/sharepoint-skills copilot-toolbox --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pnp/sharepoint-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/copilot-toolbox/copilot-toolbox .claude/skills/copilot-toolbox && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
copilot-toolbox
GitHub stars
131
Token cost
~3.6k tokens
SKILL.md length
1,818 words
Files
1
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

Creates, initializes, synchronizes, repairs, and publishes the portable English Copilot Toolbox, including its list, review workflow, Toolbox.aspx, and English HTML Toolbook.

  • Works in 9 steps: Detect mode and read state → First-run provisioning → Learn every current tool → …
  • Tasks that involve Cloud office suites
  • SKILL.md covers When to use, Inputs, Steps and Output format, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Copilot Toolbox is an agent skill from pnp/sharepoint-skills. Creates, initializes, synchronizes, repairs, and publishes the portable English Copilot Toolbox, including its list, review workflow, Toolbox.aspx, and English HTML Toolbook. Blocks incomplete imports, enforces Copilot in SharePoint button actions, and resumes safely after failures. Use when the user says: - "Copilot Toolbox" - "install the toolbox and import all tools" - "synchronize the Agent Toolbox list" - "Synchronize the Copilot Toolbox and fully enrich every current tool." - "create the English Copilot…

Its SKILL.md is about 3.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Cloud office suites. It works with Microsoft SharePoint. The repository describes itself as: Skills for Copilot in SharePoint. The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud office suites

Example prompts

  • “Copilot Toolbox”
  • “install the toolbox and import all tools”
  • “synchronize the Agent Toolbox list”
  • “/copilot-toolbox”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Detect mode and read state
  2. First-run provisioning
  3. Learn every current tool
  4. Mandatory enrichment transaction gate
  5. Compare and lifecycle plan
  6. Automatic repair and safe resume
  7. Write and verify
  8. Completion assertion
  9. Publish English Toolbook

What it can do on your machine

Read from SKILL.md and the folder at commit aa9eb14. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Copilot Toolbox loads about 3.6k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 1,818 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~3.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pnp/sharepoint-skills at commit aa9eb14, republished under its MIT licence (© pnp). 1,818 words, ~3,580 tokens.

Download SKILL.mdSave it as .claude/skills/copilot-toolbox/SKILL.md (or your agent's skills folder).
name
copilot-toolbox
description
Creates, initializes, synchronizes, repairs, and publishes the portable English Copilot Toolbox, including its list, review workflow, Toolbox.aspx, and English HTML Toolbook. Blocks incomplete imports, enforces Copilot in SharePoint button actions, and resumes safely after failures. Use when the user says: - "Copilot Toolbox" - "install the toolbox and import all tools" - "synchronize the Agent Toolbox list" - "Synchronize the Copilot Toolbox and fully enrich every current tool." - "create the English Copilot Toolbook"

Copilot Toolbox

When to use

Use this portable workflow to install, synchronize, repair, review, or publish the English copilot-toolbox solution on the current SharePoint site unless another site is named.

  • The generic list copilot-toolbox is the installation marker.
  • If absent, provision the complete solution and import the current catalog.
  • If present, never recreate existing artifacts; synchronize, repair, or publish as requested.
  • Never create, replace, edit, or designate Home.aspx as the site home page.
  • Never hard-code site URLs, list/view IDs, timestamps, page URLs, library paths, or tool counts.

Inputs

  • Target list: copilot-toolbox.
  • Authoritative identities and short descriptions: complete current tool catalog plus supplied --agenttools where present.
  • Mandatory enrichment source: complete learn_tool result for every current tool, including direct tools.
  • Identity key: exact Title, compared trimmed and case-insensitive.
  • Lifecycle: new, active, archived, removed.
  • Page: Toolbox.aspx in Site Pages.
  • Publication: copilot-toolbook-en.html in the current site's runtime-resolved standard document library (Documents or its localized equivalent, such as Dokumente).

Managed fields:

FieldRequired rule
TitleExact tool identity; display name Tool Name.
descriptionOriginal short catalog description unchanged.
CategoryMost specific verified functional family.
UseCaseLearned When to invoke, When not to invoke, Usage notes, in that order.
ExampleConcrete valid English request specific to the tool.
PromptTemplateCapability-specific reusable request with meaningful placeholders.
KeyParametersEvery exact learned input name and concise verified meaning.
Statusnew, active, archived, or removed.
TagsConservative English search terms.
Sourcetool-catalog, --agenttools, manual, or generated.
FirstSeenInitial verified detection; preserve existing populated values.
LastSeenCurrent verified detection.
RemovedOnSet only for removed tools.
workstepQuick Steps column for deterministic review.

Do not create Purpose, Prerequisites, Complexity, OutputType, or ReviewNotes.

Steps

1. Detect mode and read state
  1. Discover generic lists and resolve copilot-toolbox by normalized title.
  2. Do not use metadata itemCount as row truth.
  3. If the list exists, read every row with all managed internal fields; re-read at returned count if truncated.
  4. Preserve exact identities, accurate editorial content, FirstSeen, and active/archived lifecycle state unless verified current learning requires correction.
2. First-run provisioning

Run only when the list is absent.

  1. Create the English generic list with all managed fields and rename built-in Title to Tool Name. Seed no fixed records.
  2. Create view New Tools with query <Where><Eq><FieldRef Name="Status"/><Value Type="Choice">new</Value></Eq></Where>, fields LinkTitle, description, Category, Status, FirstSeen, workstep, and row limit 30.
  3. Fetch actual schema and create exactly one active Quick Step named Set tool active, condition [$Status] == 'new', action SetValue, Status = active, Choice overwrite, no prompt and no flow.
  4. Configure only verified workstep with that Quick Step using paired CornflowerBlue classes. Never attach it to Action0.
  5. Create exactly one full-width home-layout Toolbox.aspx through create_page_workspace, without changing the site home page.

Before page creation resolve actual list/view IDs and URLs and pass them in providedContent.

The pageSpec MUST include these exact binding and action rules:

The List web part MUST use the list whose title is exactly copilot-toolbox and the view whose title is exactly New Tools. It MUST NOT use Documents, Shared Documents, Site Pages, or any other library.

Each required Button web part MUST set its Action / Action type to Copilot in SharePoint (the localized UI label may also be Copilot in SharePoint). It MUST NOT use Link, URL, text link, Quick Links, Hero link, or any navigation action. Enter the exact required request in the Prompt field shown below the Copilot in SharePoint action selector.

The page must contain, in order:

  1. Image-free white-to-teal/green-blue full-width surface with strong contrast.
  2. Exact title Copilot in SharePoint Toolbox.
  3. Exact subtitle A Self-Updating SharePoint List of All Copilot in SharePoint Agent Tools.
  4. Short English explanation of create, synchronize, enrich, review, and publish.
  5. Exactly two real SharePoint Button web parts:
    • Update Toolbox: Action / Action type = Copilot in SharePoint, never Link; Prompt field = Synchronize the Copilot Toolbox and fully enrich every current tool.
    • Toolbook HTML: Action / Action type = Copilot in SharePoint, never Link; Prompt field = Create or refresh copilot-toolbook-en.html in this site's standard document library.
  6. List web part bound to actual copilot-toolbox and New Tools IDs.
  7. Built by Michael Greth — yourcopilot.de and Source: github.com/mysharepoint.

The page agent must not put the prompt into a URL field, button URL, description, tooltip, or visible body text as a substitute. The prompt belongs in the Prompt field beneath the Copilot in SharePoint action selection.

Read the page once after creation. Verify what extraction exposes. A button is valid only if all three facts are proven: it is a real Button web part; its action is Copilot in SharePoint and not Link; its Prompt field equals the required prompt. Also verify image-free design, title/subtitle, List binding, and unchanged Home.aspx. If extraction cannot prove action type or prompt storage, report those requirements as unverified and the page provisioning as partial; never claim the buttons work. If a button uses Link, report it as failed provisioning and provide the exact manual correction.

3. Learn every current tool
  1. Enumerate the complete authoritative tool set exactly, including direct-tool identities.
  2. Call learn_tool for every current tool in safe batches and retain every complete result.
  3. Map each tool independently:
    • Keep description unchanged from the short catalog.
    • Build UseCase only from learned guidance and preserve explicit exclusions, prerequisites, sequencing, limits, identifiers, and constraints.
    • Build KeyParameters from every exact learned input plus its verified meaning.
    • Choose the most specific family, such as automation.approvals.* → Approvals.
    • Write a capability-specific Example and PromptTemplate, not boilerplate.
    • Never invent a missing learned section; mark it unavailable and fail the gate below.
4. Mandatory enrichment transaction gate

Treat enrichment and synchronization as one logical transaction. Before any tool-record create or update:

  1. Retain one complete learn_tool result for every authoritative current tool.
  2. Build the complete final row for every current tool in memory.
  3. Finish identity comparison, lifecycle decisions, timestamps, choices, and the full write plan.
  4. Validate every current row against every blocking check.
  5. Write nothing unless all current tools pass.

Blocking checks:

  • UseCase has When to invoke, When not to invoke, and Usage notes in order.
  • UseCase retains tool-specific exclusions, prerequisites, sequencing, limits, and constraints.
  • KeyParameters contains every learned input and a non-empty verified meaning for each; name-only lists fail.
  • Category is the most specific verified family.
  • Example is a concrete valid request, not boilerplate.
  • PromptTemplate has capability-specific placeholders.
  • No managed field contains placeholder, fallback, or generic filler.

Forbidden patterns include Needs review, requires enrichment, exact meanings require, generic verified inputs, concrete task, specific outcome, specific target, copying the short description as the whole UseCase, name-only KeyParameters, and generic Examples or PromptTemplates reusable unchanged for unrelated tools.

This gate applies after timeout, throttling, parser errors, declined or expired confirmation, partial writes, and every fallback/recovery path. There is no emergency, simplified, provisional, placeholder, or seed import mode. If learning or validation is incomplete, stop before tool-record writes and report the failed gate.

Show full SKILL.md (679 more words)Show less
5. Compare and lifecycle plan
  • Match exact trimmed lowercase identity; use only confirmed aliases.
  • New current tools → new.
  • Preserve archived.
  • Returning removed tools → new, clear RemovedOn.
  • Mark missing tools removed only when the complete authoritative set proves absence; never delete automatically.
  • Add required Category choices before writing affected rows.
6. Automatic repair and safe resume

At the start of every synchronization, scan all existing current-tool rows against the blocking checks. Treat a violating row as incomplete regardless of Status, including active.

After an ambiguous write result, timeout, expired confirmation, or interrupted execution:

  1. Fresh-read every managed field.
  2. Match by normalized exact Title.
  3. Classify every authoritative identity as verified, missing, incomplete, or duplicate.
  4. Preserve verified rows and human-reviewed lifecycle state.
  5. Create only missing rows.
  6. Update only incomplete rows from retained complete learned definitions.
  7. Never repeat a write whose intended state is already present.
  8. Do not delete duplicates automatically; report exact duplicate identities unless a verified safe correction is available.

When execution can continue safely, resume automatically from the fresh-read state. If the platform requires a new confirmation, stop before degraded writes; after confirmation, fresh-read and repeat the complete enrichment gate.

7. Write and verify

Write only after the transaction gate passes. Set LastSeen, preserve or initialize FirstSeen, set Source, clear RemovedOn for current tools, and fresh-read all rows. Verify exact identity coverage, duplicates, required fields, forbidden markers, lifecycle values, and parameter meanings. Sample every learned batch and compare stored UseCase and KeyParameters with retained learned definitions. After ambiguous timeouts, fresh-read before retrying.

8. Completion assertion

Report created-and-initialized or existing-list-updated as successful only when a fresh read proves exact authoritative identity coverage, zero duplicate current identities, zero missing required values, zero forbidden markers or generic filler, zero name-only KeyParameters, and stored samples from every learning batch matching retained definitions.

Otherwise report partial, name each failed check, list affected identities or a bounded sample plus count, and never describe the import as complete. Continue automatic repair when safely possible.

9. Publish English Toolbook

Create or refresh only copilot-toolbook-en.html in the current site's runtime-resolved standard document library. Discover the site's standard document library at runtime; its title is commonly Documents or a localized equivalent such as Dokumente. Never hard-code the library title or URL, and never save the Toolbook to AgentAssets, the skill folder, or any library other than the resolved standard document library. Save the file at the root of the resolved standard document library. Include new, active, and archived; exclude removed by default. Preserve multiline UseCase and exact KeyParameters, sort categories alphabetically, provide search, status filtering, collapsible categories and lifecycle badges, keep blue/orange design and attribution, use English only, verify file existence in the resolved standard document library, and return its browser link.

Output format

Report briefly:

  • Mode: created-and-initialized, existing-list-updated, toolbook-published, or partial.
  • Artifact status: list, schema, New Tools, Quick Step, workstep, Toolbox.aspx, image-free header, two Button web parts, each button's action type, each Prompt field, and verified List binding.
  • Current, created, updated, removed, reactivated, duplicate, and incomplete counts.
  • Learned sent, successful, incomplete, and failed counts.
  • Blocking-gate result and unresolved learned sections.
  • New, Removed, Reactivated, and Needs repair sets; for more than 20 show totals and about five examples.
  • Links to Toolbox.aspx, the list, and Toolbook when present.

If any tool or page operation fails or returns empty, say so plainly and never invent success.

Constraints

  • Never modify Home.aspx.
  • Never rerun first-run provisioning when the list exists.
  • Never seed fixed tool identities or counts.
  • Never create duplicate lists, views, Quick Steps, pages, or Toolbook files.
  • Never write tool records before complete mandatory learning and validation.
  • Never use generic filler or placeholder imports.
  • Never call name-only parameters complete.
  • Never overwrite accurate editorial fields without verified reason.
  • Never publish the Toolbook outside the runtime-resolved standard document library.
  • Never produce German Toolbox or Toolbook artifacts.
  • Never configure either Toolbox button with action Link; both MUST use Copilot in SharePoint and store the exact request in the Prompt field.
  • A confirmation timeout is not permission to degrade quality; after confirmation, resume from fresh state and rerun the gate.

© pnp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/copilot-toolbox/copilot-toolbox of pnp/sharepoint-skills.

Open the folder on GitHubat commit aa9eb14

Compare with similar skills

Copilot Toolbox next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Copilot Toolbox compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Copilot Toolbox this skillpnp/sharepoint-skills131—~3.6kAutomated safety check: PassMIT
Colleague DistillationZhixiangLuo/10xProductivity478—~2.1kAutomated safety check: NotesMIT
Msgraphcodemie-ai/codemie-code294—~4.1kAutomated safety check: PassApache-2.0
aai-cli Microsoft 365aai-labs/agent-barn109—~1.2kAutomated safety check: PassApache-2.0
Workiqmicrosoft/work-iq1k—~15kAutomated safety check: PassCustom licence
Workiq Previewmicrosoft/work-iq1k—~3.3kAutomated safety check: PassCustom licence

Similar skills

  • Colleague Distillation

    ZhixiangLuo/10xProductivity

    Distill a colleague into a reusable AI skill (work + persona) using tool connections — Slack, Slack AI, Jira, GHE, Bitbucket, Confluence, SharePoint, Teams, Outlook, Notion, Linear, Google Docs, and…

    478 GitHub stars~2.1k tokensUpdated 2 mo ago
    Documents & OfficeAuto-check: notes
  • Msgraph

    codemie-ai/codemie-code

    Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…

    294 GitHub stars~4.1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • aai-cli Microsoft 365

    aai-labs/agent-barn

    Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.

    109 GitHub stars~1.2k tokensUpdated today
    Documents & OfficeAuto-check passed
  • Workiq

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~15k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq Preview

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~3.3k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Hunt Ntlm Info

    sickn33/agentic-awesome-skills

    Hunt NTLM/Negotiate information disclosure on internet-reachable IIS/SharePoint/Exchange.

    47k GitHub starsUsed in 1 repo~4.7k tokens
    Documents & OfficeAuto-check passed

More from pnp/sharepoint-skills

All 51 skills in this repo
  • Scorecard Matrix

    pnp/sharepoint-skills

    Generates a polished, self-contained HTML heatmap scorecard — a weighted comparison matrix where entities (rows) are scored across dimensions (columns), with computed totals, rank badges, and a…

    131 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Analyze Document Library

    pnp/sharepoint-skills

    Analyze the current SharePoint document library in read-only mode and produce a structured summary of files, folders, file types, recent activity, naming issues, and organization recommendations.

    131 GitHub stars~899 tokensUpdated yesterday
    Auto-check passed
  • Broken Link Auditor

    pnp/sharepoint-skills

    Audits SharePoint pages, news posts, and hyperlink fields for broken or risky links and saves a self-contained HTML link-health report to the site.

    131 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Custom Image Tagger

    pnp/sharepoint-skills

    Analyze selected construction images, create missing object metadata columns, and write concise visual metadata back to SharePoint columns using explicit image-analysis, list-schema, list-update…

    131 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Dossier

    pnp/sharepoint-skills

    Renders a polished, self-contained HTML briefing from any data source — SharePoint lists, uploaded documents, or a verbal description.

    131 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Exec Report

    pnp/sharepoint-skills

    Generates a polished, self-contained HTML executive report or dashboard from any data source — SharePoint lists, CSV exports, or a user description.

    131 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Questions about Copilot Toolbox

What does Copilot Toolbox do?

Creates, initializes, synchronizes, repairs, and publishes the portable English Copilot Toolbox, including its list, review workflow, Toolbox.aspx, and English HTML Toolbook. Copilot Toolbox is an agent skill from pnp/sharepoint-skills.aspx, and English HTML Toolbook.

When should I use Copilot Toolbox?

Copilot Toolbox fits situations like: tasks that involve Cloud office suites.

How do I install Copilot Toolbox in Claude Code?

Run `npx skills add pnp/sharepoint-skills --skill copilot-toolbox -a claude-code`. Or copy the skill folder (Skills/copilot-toolbox/copilot-toolbox in pnp/sharepoint-skills) into .claude/skills/copilot-toolbox in your project. Claude Code loads it when a task matches its description.

How do I install Copilot Toolbox in Codex?

Run `npx skills add pnp/sharepoint-skills --skill copilot-toolbox -a codex`. Or copy the skill folder (Skills/copilot-toolbox/copilot-toolbox in pnp/sharepoint-skills) into .agents/skills/copilot-toolbox in your project. Codex loads it when a task matches its description.

Can I use Copilot Toolbox in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pnp/sharepoint-skills --skill copilot-toolbox -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/copilot-toolbox, .gemini/skills/copilot-toolbox, .github/skills/copilot-toolbox and .opencode/skills/copilot-toolbox in your project.

What does Copilot Toolbox need to run?

SKILL.md names no scripts, command-line tools or credentials: Copilot Toolbox is instructions for the agent only.

Does Copilot Toolbox access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Copilot Toolbox safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Copilot Toolbox use?

Copilot Toolbox is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Copilot Toolbox use?

About 3.6k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Copilot Toolbox?

Skills that share tags, products or a category with Copilot Toolbox: Colleague Distillation (ZhixiangLuo/10xProductivity, 478 stars), Msgraph (codemie-ai/codemie-code, 294 stars), aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars) and Workiq (microsoft/work-iq, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Copilot Toolbox?

pnp (a GitHub organization) maintains it in pnp/sharepoint-skills, which has 131 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 6, 2026.

Source: pnp/sharepoint-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.