Agent skill

Guest Access Reviewer

by pnp in pnp/sharepoint-skills

Audits all guest and external user access on the current SharePoint site.

MITAuto-check passedDocuments & Office

Install Guest Access Reviewer

skills CLI
$ npx skills add pnp/sharepoint-skills --skill guest-access-reviewer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pnp/sharepoint-skills guest-access-reviewer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pnp/sharepoint-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/guest-access-reviewer/guest-access-reviewer .claude/skills/guest-access-reviewer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
guest-access-reviewer
GitHub stars
133
Token cost
~2.3k tokens
SKILL.md length
1,209 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Audits all guest and external user access on the current SharePoint site.

  • Works in 8 steps: Resolve the site → Enumerate all users with access → Identify and profile each guest user → …
  • Tasks that involve Cloud office suites
  • SKILL.md covers Purpose, Trigger Phrases, Inputs & Scope and What counts as a guest or…, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Guest Access Reviewer is an agent skill from pnp/sharepoint-skills. Audits all guest and external user access on the current SharePoint site. Identifies who has been invited, what they can access, and flags stale accounts (no activity in 90+ days) for review or removal. Saves a self-contained HTML report. Use when the user says: - "guest access review" - "audit external users" - "who has guest access" - "review external sharing" - "find stale guests" - "external user audit" - "check guest accounts"

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Cloud office suites and Access reviews and audit trails. It works with Microsoft SharePoint. The repository describes itself as: Skills for Copilot in SharePoint. The licence is MIT.

When your agent uses it

  • Tasks that involve Cloud office suites
  • Tasks that involve Access reviews and audit trails

Example prompts

  • “guest access review”
  • “audit external users”
  • “who has guest access”
  • “/guest-access-reviewer”

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Resolve the site
  2. Enumerate all users with access
  3. Identify and profile each guest user
  4. Classify each guest's status
  5. Summarize findings
  6. Build a self-contained HTML report
  7. Save the report
  8. Respond to the user

What it can do on your machine

Read from SKILL.md and the folder at commit 69712d2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Guest Access Reviewer loads about 2.3k tokens when it runs. Until then it costs about 114 tokens; SKILL.md has 1,209 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~114
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pnp/sharepoint-skills at commit 69712d2, republished under its MIT licence (© pnp). 1,209 words, ~2,251 tokens.

Download SKILL.mdSave it as .claude/skills/guest-access-reviewer/SKILL.md (or your agent's skills folder).
name
guest-access-reviewer
description
Audits all guest and external user access on the current SharePoint site. Identifies who has been invited, what they can access, and flags stale accounts (no activity in 90+ days) for review or removal. Saves a self-contained HTML report. Use when the user says: - "guest access review" - "audit external users" - "who has guest access" - "review external sharing" - "find stale guests" - "external user audit" - "check guest accounts"

Guest Access Reviewer

Purpose

External collaborators accumulate on SharePoint sites over time — vendors, contractors, and clients who finished their engagement but were never removed. This skill enumerates every guest and external user who has access to the current SharePoint site, maps the groups and permission levels they hold, flags accounts that appear stale (no activity in 90+ days), and saves a self-contained HTML report that site owners and governance teams can act on. It is strictly read-only: it never removes users, modifies permissions, or changes any site content.

Trigger Phrases

Activate this skill when the user says any of the following (or close variations):

  • "guest access review" / "guest access audit"
  • "audit external users" / "external user audit"
  • "who has guest access" / "which guests have access"
  • "review external sharing" / "external access review"
  • "find stale guests" / "stale external users"
  • "who are the external collaborators on this site"
  • "check guest accounts"

Inputs & Scope

Determine the scope from the user's request:

  • Current site (default) — audit all guest users who have access to the current SharePoint site through any mechanism: SharePoint groups, direct role assignments, or sharing links.
  • Named site — if the user names a specific site, resolve that site and audit it instead.

If no scope can be resolved, default to the current site and note that assumption in the report. Do not scan multiple sites unless the user explicitly asks.

What counts as a guest or external user

Identify the following as guest or external users:

  • Accounts whose User Principal Name (UPN) contains #EXT# — the standard Azure AD guest account marker
  • Accounts in the _spo_ guest account format used by SharePoint sharing
  • Accounts with an email domain that differs from the host organization's primary domain(s) when this can be determined from context
  • Users explicitly shown as "Guest" in SharePoint user information

Do not flag internal service accounts, system accounts, or Microsoft application identities as guests.

Steps

Step 1 — Resolve the site

Resolve the current SharePoint site URL. Record the site title, URL, and the exact date and time of the audit. Confirm read access to site user and permission data before proceeding.

Step 2 — Enumerate all users with access

Collect every user who has any form of access to the site:

  • Members of all SharePoint groups (Owners, Members, Visitors, and any custom permission groups)
  • Users with direct permission grants not through a group
  • Users visible in the site's user information list

For each user record, capture:

  • Display name
  • Login name / UPN
  • Email address
  • Whether the account appears to be a guest or external identity
  • SharePoint group membership (all groups they belong to)
  • Effective permission level (Owner / Edit / Read or equivalent custom level)
Step 3 — Identify and profile each guest user

From the full user list, isolate the guest and external accounts using the criteria in What counts as a guest or external user.

For each guest, collect:

  • Display name
  • UPN / login name
  • Email address
  • External organization domain (derived from email)
  • All SharePoint groups they belong to
  • Effective permission level on the site
  • Last activity or last modified date (from SharePoint user information or site audit logs, where available)
  • Invited by (if determinable from SharePoint sharing records)

If a field cannot be determined, record it as "Not available" — do not omit it or invent a value.

Step 4 — Classify each guest's status

Assign one of three statuses to each guest account:

StatusCriteria
ActiveLast activity date is within the past 90 days
StaleLast activity date is available and is more than 90 days ago
UnknownNo last activity information is available from the current site data

Assign a recommended action for each:

  • Active → No immediate action; note for periodic review
  • Stale → Recommend reviewing with site owner; consider removing access
  • Unknown → Recommend confirming with site owner whether the guest is still an active collaborator

Do not classify a guest as Stale based solely on the absence of activity data — that is Unknown, not Stale.

Step 5 — Summarize findings

Calculate the following metrics:

  • Total users with site access
  • Total guest / external users
  • Guests by permission level (Owner / Edit / Read)
  • Active guests
  • Stale guests (90+ days)
  • Unknown-status guests
  • Number of unique external domains represented
  • Top external domains by guest count
Show full SKILL.md (515 more words)Show less
Step 6 — Build a self-contained HTML report

Draft a single self-contained HTML file:

  • No scripts. No external CSS, fonts, images, or other resources. Inline CSS only.
  • Include a summary band with: site name, site URL, audit date/time, total users with access, total guest users, stale guest count, and unknown-status count.
  • Include a status breakdown with color-coded indicators:
    • Green for Active
    • Red for Stale
    • Amber for Unknown
  • Include a domain breakdown table showing each external domain, guest count from that domain, and highest permission level held by any guest from that domain.
  • Include a guest details table with one row per guest:
    • Display name
    • Email / UPN
    • External domain
    • Permission level
    • SharePoint group(s)
    • Last activity date (or "Not available")
    • Status (Active / Stale / Unknown)
    • Recommended action
    • Row highlight: red for Stale, amber for Unknown, no highlight for Active
  • Include a prioritized recommendations section in plain English, for example:
    • "5 guests from agency-partner.com have not been active in over 90 days. Review with the site owner and consider removing their access."
    • "3 guests have Owner-level permissions. Verify these elevated grants are still appropriate."
    • "6 guests have no recorded last activity. Confirm with the site owner whether these accounts are still needed."
  • Include a limitations section whenever last-activity data was unavailable, data retrieval was partial, or any information could not be confirmed.
Step 7 — Save the report

Save the HTML file to a Guest Access Reports folder in an appropriate document library on the current site.

  • If the folder does not exist, create only that report folder, and only when needed to save the report.
  • Use a clear timestamped filename: Guest-Access-Report-<SiteName>-YYYY-MM-DD-HHMM.html
Step 8 — Respond to the user

After saving, reply with a compact Markdown summary and the report link:

# Guest access review complete

[Open the report](<link>)

- Site: <site name>
- Total users with access: <n>
- Guest / external users: <n>
- Stale guests (90+ days): <n>
- Unknown status: <n>
- Top recommendation: <1 concise sentence>

Example

User: "Run a guest access review on this site."

Agent response after processing:

I reviewed guest access on the Marketing Hub and found 14 guest users across 6 external organizations.

MetricResult
Total guest users14
Active6
Stale (90+ days)5
Unknown status3
Highest-risk finding5 guests from agency-partner.com have not been active in over 6 months

I saved the report to Guest Access Reports/Guest-Access-Report-Marketing-Hub-2026-09-11-1045.html. Recommended action: review the 5 stale agency-partner.com accounts with the site owner and consider removing their access.

Constraints

  • Strictly read-only for permissions and content. Never remove users, change permission levels, edit SharePoint groups, modify sharing settings, or alter any site content. The only write operation is saving the final HTML report file (and, if needed, creating the Guest Access Reports folder that holds it).
  • Never invent user data, last-activity dates, or permission assignments. If information is not available from the current site's data, record it as "Not available" and surface the limitation in the report.
  • Do not classify a guest as Stale based solely on the absence of last-activity data — that is Unknown.
  • Do not make assumptions about whether a guest is still a valid collaborator based on their name, domain, or email alone.
  • Keep the HTML fully self-contained: no scripts, no external assets, inline CSS only.
  • If any data retrieval is partial or throttled, surface that clearly in the report's limitations section.

© pnp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/guest-access-reviewer/guest-access-reviewer of pnp/sharepoint-skills.

Open the folder on GitHubat commit 69712d2

Compare with similar skills

Guest Access Reviewer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Guest Access Reviewer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Guest Access Reviewer this skillpnp/sharepoint-skills133—~2.3kAutomated safety check: PassMIT
Hunt Sharepointsickn33/agentic-awesome-skills47k1 repos~8.5kAutomated safety check: PassMIT
Colleague DistillationZhixiangLuo/10xProductivity479—~2.1kAutomated safety check: NotesMIT
Msgraphcodemie-ai/codemie-code294—~4.1kAutomated safety check: PassApache-2.0
aai-cli Microsoft 365aai-labs/agent-barn109—~1.2kAutomated safety check: PassApache-2.0
Workiqmicrosoft/work-iq1k—~15kAutomated safety check: PassCustom licence

Similar skills

  • Hunt Sharepoint

    sickn33/agentic-awesome-skills

    Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms

    47k GitHub starsUsed in 1 repo~8.5k tokens
    Documents & OfficeAuto-check passed
  • Colleague Distillation

    ZhixiangLuo/10xProductivity

    Distill a colleague into a reusable AI skill (work + persona) using tool connections — Slack, Slack AI, Jira, GHE, Bitbucket, Confluence, SharePoint, Teams, Outlook, Notion, Linear, Google Docs, and…

    479 GitHub stars~2.1k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check: notes
  • Msgraph

    codemie-ai/codemie-code

    Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…

    294 GitHub stars~4.1k tokensUpdated 2 days ago
    Documents & OfficeAuto-check passed
  • aai-cli Microsoft 365

    aai-labs/agent-barn

    Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.

    109 GitHub stars~1.2k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~15k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq Preview

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~3.3k tokensUpdated yesterday
    Documents & OfficeAuto-check passed

More from pnp/sharepoint-skills

All 52 skills in this repo
  • Scorecard Matrix

    pnp/sharepoint-skills

    Generates a polished, self-contained HTML heatmap scorecard — a weighted comparison matrix where entities (rows) are scored across dimensions (columns), with computed totals, rank badges, and a…

    133 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Analyze Document Library

    pnp/sharepoint-skills

    Analyze the current SharePoint document library in read-only mode and produce a structured summary of files, folders, file types, recent activity, naming issues, and organization recommendations.

    133 GitHub stars~899 tokensUpdated yesterday
    Auto-check passed
  • Broken Link Auditor

    pnp/sharepoint-skills

    Audits SharePoint pages, news posts, and hyperlink fields for broken or risky links and saves a self-contained HTML link-health report to the site.

    133 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Custom Image Tagger

    pnp/sharepoint-skills

    Analyze selected construction images, create missing object metadata columns, and write concise visual metadata back to SharePoint columns using explicit image-analysis, list-schema, list-update…

    133 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Dossier

    pnp/sharepoint-skills

    Renders a polished, self-contained HTML briefing from any data source — SharePoint lists, uploaded documents, or a verbal description.

    133 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Exec Report

    pnp/sharepoint-skills

    Generates a polished, self-contained HTML executive report or dashboard from any data source — SharePoint lists, CSV exports, or a user description.

    133 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Questions about Guest Access Reviewer

What does Guest Access Reviewer do?

Audits all guest and external user access on the current SharePoint site. Guest Access Reviewer is an agent skill from pnp/sharepoint-skills. Audits all guest and external user access on the current SharePoint site.

When should I use Guest Access Reviewer?

Guest Access Reviewer fits situations like: tasks that involve Cloud office suites; tasks that involve Access reviews and audit trails.

How do I install Guest Access Reviewer in Claude Code?

Run `npx skills add pnp/sharepoint-skills --skill guest-access-reviewer -a claude-code`. Or copy the skill folder (Skills/guest-access-reviewer/guest-access-reviewer in pnp/sharepoint-skills) into .claude/skills/guest-access-reviewer in your project. Claude Code loads it when a task matches its description.

How do I install Guest Access Reviewer in Codex?

Run `npx skills add pnp/sharepoint-skills --skill guest-access-reviewer -a codex`. Or copy the skill folder (Skills/guest-access-reviewer/guest-access-reviewer in pnp/sharepoint-skills) into .agents/skills/guest-access-reviewer in your project. Codex loads it when a task matches its description.

Can I use Guest Access Reviewer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pnp/sharepoint-skills --skill guest-access-reviewer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guest-access-reviewer, .gemini/skills/guest-access-reviewer, .github/skills/guest-access-reviewer and .opencode/skills/guest-access-reviewer in your project.

What does Guest Access Reviewer need to run?

SKILL.md names no scripts, command-line tools or credentials: Guest Access Reviewer is instructions for the agent only.

Does Guest Access Reviewer access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Guest Access Reviewer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Guest Access Reviewer use?

Guest Access Reviewer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Guest Access Reviewer use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Guest Access Reviewer?

Skills that share tags, products or a category with Guest Access Reviewer: Hunt Sharepoint (sickn33/agentic-awesome-skills, 47k stars), Colleague Distillation (ZhixiangLuo/10xProductivity, 479 stars), Msgraph (codemie-ai/codemie-code, 294 stars) and aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Guest Access Reviewer?

pnp (a GitHub organization) maintains it in pnp/sharepoint-skills, which has 133 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 9, 2026.

Source: pnp/sharepoint-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.