Agent skill

Permission Report

by pnp in pnp/sharepoint-skills

Create a read-only permission and sharing access review report as a self-contained HTML file saved to SharePoint.

MITAuto-check passedDocuments & Office

Install Permission Report

skills CLI
$ npx skills add pnp/sharepoint-skills --skill permission-report -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pnp/sharepoint-skills permission-report --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pnp/sharepoint-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/permission-report/permission-report .claude/skills/permission-report && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
permission-report
GitHub stars
133
Token cost
~1.2k tokens
SKILL.md length
567 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
MIT

At a glance

Create a read-only permission and sharing access review report as a self-contained HTML file saved to SharePoint.

  • Works in 7 steps: Stay strictly read-only on permissions. → Resolve the scope. → Collect access information. → …
  • The user says: - who has access - permission report - sharing report - access review - review permissions - create a Permission Report
  • SKILL.md covers When to use, Inputs, Steps and Output format, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Permission Report is an agent skill from pnp/sharepoint-skills. Create a read-only permission and sharing access review report as a self-contained HTML file saved to SharePoint. Use when the user says: - "who has access" - "permission report" - "sharing report" - "access review" - "review permissions" - "create a Permission Report"

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Documents & Office, covering Cloud office suites and Access reviews and audit trails. It works with Microsoft SharePoint. The repository describes itself as: Skills for Copilot in SharePoint. The licence is MIT.

When your agent uses it

  • The user says: - who has access - permission report - sharing report - access review - review permissions - create a Permission Report
  • Tasks that involve Cloud office suites
  • Tasks that involve Access reviews and audit trails

Example prompts

  • “who has access”
  • “permission report”
  • “sharing report”
  • “/permission-report”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Stay strictly read-only on permissions.
  2. Resolve the scope.
  3. Collect access information.
  4. Flag risks.
  5. Draft a single self-contained HTML report.
  6. Save the report.
  7. Respond to the user.

What it can do on your machine

Read from SKILL.md and the folder at commit 69712d2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown and html).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Permission Report loads about 1.2k tokens when it runs. Until then it costs about 75 tokens; SKILL.md has 567 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~75
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from pnp/sharepoint-skills at commit 69712d2, republished under its MIT licence (© pnp). 567 words, ~1,247 tokens.

Download SKILL.mdSave it as .claude/skills/permission-report/SKILL.md (or your agent's skills folder).
name
permission-report
description
Create a read-only permission and sharing access review report as a self-contained HTML file saved to SharePoint. Use when the user says: - "who has access" - "permission report" - "sharing report" - "access review" - "review permissions" - "create a Permission Report"

Permission Report

When to use

Use this skill when the user wants a read-only review of who has access to SharePoint files, folders, libraries, lists, or a site, especially requests such as “who has access,” “permission report,” “sharing report,” “access review,” or “review permissions.”

Inputs

Use the current SharePoint context by default. Determine the reporting scope from the user’s request and available context:

  • Selected files or folders, if the user has selected items or says “these/this.”
  • A named library or list, if the user names one.
  • The whole current site, if no narrower scope is provided.

Only report content and permission details the current user can already see. Never invent access data.

Steps

  1. Stay strictly read-only on permissions.

    • Never grant, revoke, change, break, restore, or otherwise modify sharing or permissions.
    • Do not create sharing links or invite users.
    • Use only discovery, listing, permission-checking, and file-creation tools needed to produce the report.
  2. Resolve the scope.

    • If items are selected, report on those selected files or folders.
    • If a list or library is named, resolve it from the current site and report on that list/library and representative or included items as supported by available permission tools.
    • If no narrower scope is clear, report across accessible user-created lists and libraries on the current site.
    • If a scope cannot be resolved, state that plainly in the report and do not guess.
  3. Collect access information. For each scoped site/list/library/file/folder where available, read:

    • Who has access: users, groups, sharing principals, and links.
    • Permission level: normalize to Full Control, Edit, Read, or Other/Unknown.
    • Whether access is inherited or uniquely set.
    • Any sharing links, especially Anyone links.
    • External or guest users. If a tool fails or returns partial/empty permission data, record that limitation plainly; do not fill gaps from assumptions.
  4. Flag risks. Mark rows and findings for:

    • Anyone links.
    • External or guest access.
    • Broad groups such as Everyone, Everyone except external users, All users, or similar tenant-wide groups.
    • Broken inheritance / unique permissions.
    • Individual users with Full Control.
  5. Draft a single self-contained HTML report.

    • No scripts.
    • No external CSS, fonts, images, or resources.
    • Use inline CSS only.
    • Include a summary band with totals such as scoped objects reviewed, principals found, Full Control/Edit/Read counts, external/guest count, sharing link count, and flagged risk count.
    • Include a color-coded access table: red for Full Control/high risk, amber for Edit or caution, green for Read/low risk, gray for unknown. Highlight flagged rows.
    • Include a plain-English findings list explaining the main risks and safe observations.
    • Include a limitations section if permission details were unavailable or partial.
  6. Save the report.

    • Save the HTML file in an Access Reports folder in an appropriate document library on the current site.
    • If the folder does not exist, create only that report folder and only if needed for saving the report.
    • Use a clear filename such as Permission-Report-YYYY-MM-DD-HHMM.html.
  7. Respond to the user.

    • Provide the report link.
    • Give a short summary of the highest-risk findings.
    • Do not claim permissions were changed.
Show full SKILL.md (70 more words)Show less

Output format

After saving the report, respond:

markdown
# Permission report created

[Open the report](<link>)

- Scope: <selected items, named list/library, or whole site>
- Reviewed: <count or brief description>
- Key findings: <1 concise sentence with highest-risk issues, or “No high-risk access was found in the data available.”>

HTML report requirements

The saved file must be a complete HTML document:

html
<!doctype html>
<html>
<head>
  <meta charset="utf-8">
  <title>Permission Report</title>
  <style>
    /* inline CSS only */
  </style>
</head>
<body>
  <h1>Permission Report</h1>
  <section><!-- summary band --></section>
  <section><!-- findings --></section>
  <section><!-- access table --></section>
  <section><!-- limitations, if any --></section>
</body>
</html>

Constraints

  • Strictly read-only for permissions and sharing.
  • Never grant, revoke, share, unshare, create sharing links, or change inheritance.
  • Never invent users, groups, permission levels, links, or inheritance status.
  • If access data is unavailable, say so plainly in the report.
  • HTML must be self-contained and must not include scripts or external resources.

© pnp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in Skills/permission-report/permission-report of pnp/sharepoint-skills.

Open the folder on GitHubat commit 69712d2

Compare with similar skills

Permission Report next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Permission Report compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Permission Report this skillpnp/sharepoint-skills133—~1.2kAutomated safety check: PassMIT
Hunt Sharepointsickn33/agentic-awesome-skills47k1 repos~8.5kAutomated safety check: PassMIT
Colleague DistillationZhixiangLuo/10xProductivity479—~2.1kAutomated safety check: NotesMIT
Msgraphcodemie-ai/codemie-code294—~4.1kAutomated safety check: PassApache-2.0
aai-cli Microsoft 365aai-labs/agent-barn109—~1.2kAutomated safety check: PassApache-2.0
Workiqmicrosoft/work-iq1k—~15kAutomated safety check: PassCustom licence

Similar skills

  • Hunt Sharepoint

    sickn33/agentic-awesome-skills

    Hunt Microsoft SharePoint Server (2013/2016/2019/Subscription Edition) on-prem farms

    47k GitHub starsUsed in 1 repo~8.5k tokens
    Documents & OfficeAuto-check passed
  • Colleague Distillation

    ZhixiangLuo/10xProductivity

    Distill a colleague into a reusable AI skill (work + persona) using tool connections — Slack, Slack AI, Jira, GHE, Bitbucket, Confluence, SharePoint, Teams, Outlook, Notion, Linear, Google Docs, and…

    479 GitHub stars~2.1k tokensUpdated 3 mo ago
    Documents & OfficeAuto-check: notes
  • Msgraph

    codemie-ai/codemie-code

    Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…

    294 GitHub stars~4.1k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • aai-cli Microsoft 365

    aai-labs/agent-barn

    Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.

    109 GitHub stars~1.2k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~15k tokensUpdated yesterday
    Documents & OfficeAuto-check passed
  • Workiq Preview

    microsoft/work-iq

    Official

    WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.

    1k GitHub stars~3.3k tokensUpdated yesterday
    Documents & OfficeAuto-check passed

More from pnp/sharepoint-skills

All 52 skills in this repo
  • Scorecard Matrix

    pnp/sharepoint-skills

    Generates a polished, self-contained HTML heatmap scorecard — a weighted comparison matrix where entities (rows) are scored across dimensions (columns), with computed totals, rank badges, and a…

    133 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Analyze Document Library

    pnp/sharepoint-skills

    Analyze the current SharePoint document library in read-only mode and produce a structured summary of files, folders, file types, recent activity, naming issues, and organization recommendations.

    133 GitHub stars~899 tokensUpdated yesterday
    Auto-check passed
  • Broken Link Auditor

    pnp/sharepoint-skills

    Audits SharePoint pages, news posts, and hyperlink fields for broken or risky links and saves a self-contained HTML link-health report to the site.

    133 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • Custom Image Tagger

    pnp/sharepoint-skills

    Analyze selected construction images, create missing object metadata columns, and write concise visual metadata back to SharePoint columns using explicit image-analysis, list-schema, list-update…

    133 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Dossier

    pnp/sharepoint-skills

    Renders a polished, self-contained HTML briefing from any data source — SharePoint lists, uploaded documents, or a verbal description.

    133 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Exec Report

    pnp/sharepoint-skills

    Generates a polished, self-contained HTML executive report or dashboard from any data source — SharePoint lists, CSV exports, or a user description.

    133 GitHub stars~2k tokensUpdated yesterday
    Auto-check passed

Questions about Permission Report

What does Permission Report do?

Create a read-only permission and sharing access review report as a self-contained HTML file saved to SharePoint. Permission Report is an agent skill from pnp/sharepoint-skills. Create a read-only permission and sharing access review report as a self-contained HTML file saved to SharePoint.

When should I use Permission Report?

Permission Report fits situations like: the user says: - who has access - permission report - sharing report - access review - review permissions - create a Permission Report; tasks that involve Cloud office suites; tasks that involve Access reviews and audit trails.

How do I install Permission Report in Claude Code?

Run `npx skills add pnp/sharepoint-skills --skill permission-report -a claude-code`. Or copy the skill folder (Skills/permission-report/permission-report in pnp/sharepoint-skills) into .claude/skills/permission-report in your project. Claude Code loads it when a task matches its description.

How do I install Permission Report in Codex?

Run `npx skills add pnp/sharepoint-skills --skill permission-report -a codex`. Or copy the skill folder (Skills/permission-report/permission-report in pnp/sharepoint-skills) into .agents/skills/permission-report in your project. Codex loads it when a task matches its description.

Can I use Permission Report in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pnp/sharepoint-skills --skill permission-report -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/permission-report, .gemini/skills/permission-report, .github/skills/permission-report and .opencode/skills/permission-report in your project.

What does Permission Report need to run?

SKILL.md names no scripts, command-line tools or credentials: Permission Report is instructions for the agent only.

Does Permission Report access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Permission Report safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Permission Report use?

Permission Report is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Permission Report use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Permission Report?

Skills that share tags, products or a category with Permission Report: Hunt Sharepoint (sickn33/agentic-awesome-skills, 47k stars), Colleague Distillation (ZhixiangLuo/10xProductivity, 479 stars), Msgraph (codemie-ai/codemie-code, 294 stars) and aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Permission Report?

pnp (a GitHub organization) maintains it in pnp/sharepoint-skills, which has 133 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 9, 2026.

Source: pnp/sharepoint-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.