aai-cli Microsoft 365
aai-labs/agent-barn
Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.
Creates accessible, single-file HTML artifacts that render reliably in SharePoint, OneDrive, Teams, File Viewer, and embedded iframe preview surfaces.
$ npx skills add pnp/sharepoint-skills --skill sharepoint-safe-html -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install pnp/sharepoint-skills sharepoint-safe-html --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/pnp/sharepoint-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/Skills/sharepoint-safe-html/sharepoint-safe-html .claude/skills/sharepoint-safe-html && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sharepoint-safe-html" agent skill from https://github.com/pnp/sharepoint-skills/tree/main/Skills/sharepoint-safe-html/sharepoint-safe-html into .claude/skills/sharepoint-safe-html/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sharepoint-safe-html", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/pnp/sharepoint-skills/tree/main/Skills/sharepoint-safe-html/sharepoint-safe-htmlType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add pnp/sharepoint-skills --skill sharepoint-safe-html -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install pnp/sharepoint-skills sharepoint-safe-html --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pnp/sharepoint-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/Skills/sharepoint-safe-html/sharepoint-safe-html .agents/skills/sharepoint-safe-html && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sharepoint-safe-html" agent skill from https://github.com/pnp/sharepoint-skills/tree/main/Skills/sharepoint-safe-html/sharepoint-safe-html into .agents/skills/sharepoint-safe-html/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sharepoint-safe-html", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pnp/sharepoint-skills --skill sharepoint-safe-html -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install pnp/sharepoint-skills sharepoint-safe-html --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pnp/sharepoint-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/Skills/sharepoint-safe-html/sharepoint-safe-html .cursor/skills/sharepoint-safe-html && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sharepoint-safe-html" agent skill from https://github.com/pnp/sharepoint-skills/tree/main/Skills/sharepoint-safe-html/sharepoint-safe-html into .cursor/skills/sharepoint-safe-html/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sharepoint-safe-html", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/pnp/sharepoint-skills.git --path Skills/sharepoint-safe-html/sharepoint-safe-html--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add pnp/sharepoint-skills --skill sharepoint-safe-html -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install pnp/sharepoint-skills sharepoint-safe-html --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pnp/sharepoint-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/Skills/sharepoint-safe-html/sharepoint-safe-html .gemini/skills/sharepoint-safe-html && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sharepoint-safe-html" agent skill from https://github.com/pnp/sharepoint-skills/tree/main/Skills/sharepoint-safe-html/sharepoint-safe-html into .gemini/skills/sharepoint-safe-html/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sharepoint-safe-html", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install pnp/sharepoint-skills sharepoint-safe-htmlInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add pnp/sharepoint-skills --skill sharepoint-safe-html -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/pnp/sharepoint-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/Skills/sharepoint-safe-html/sharepoint-safe-html .github/skills/sharepoint-safe-html && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sharepoint-safe-html" agent skill from https://github.com/pnp/sharepoint-skills/tree/main/Skills/sharepoint-safe-html/sharepoint-safe-html into .github/skills/sharepoint-safe-html/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sharepoint-safe-html", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pnp/sharepoint-skills --skill sharepoint-safe-html -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install pnp/sharepoint-skills sharepoint-safe-html --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pnp/sharepoint-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/Skills/sharepoint-safe-html/sharepoint-safe-html .opencode/skills/sharepoint-safe-html && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sharepoint-safe-html" agent skill from https://github.com/pnp/sharepoint-skills/tree/main/Skills/sharepoint-safe-html/sharepoint-safe-html into .opencode/skills/sharepoint-safe-html/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sharepoint-safe-html", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sharepoint-safe-htmlCreates accessible, single-file HTML artifacts that render reliably in SharePoint, OneDrive, Teams, File Viewer, and embedded iframe preview surfaces.
Sharepoint Safe HTML is an agent skill from pnp/sharepoint-skills. Creates accessible, single-file HTML artifacts that render reliably in SharePoint, OneDrive, Teams, File Viewer, and embedded iframe preview surfaces. Use this skill whenever the user asks for SharePoint-safe HTML, an HTML report, dashboard, deck, artifact, visual page, one-pager, or embeddable HTML file for Microsoft 365 preview surfaces. Enforces inline CSS, no external dependencies, no runtime network calls, responsive iframe-friendly layout, optional live-linked CSV/XLSX data files, WCAG 2.2 AA-oriented…
Its SKILL.md is about 6.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/accessibility.md`).
It sits in Documents & Office, covering Cloud office suites and Accessibility. It works with Microsoft SharePoint, Microsoft OneDrive, Microsoft Excel and Microsoft 365. The repository describes itself as: Skills for Copilot in SharePoint. The licence is MIT.
6 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit aa9eb14. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript and html).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sharepoint Safe HTML loads about 6.4k tokens when it runs, and up to ~8.2k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 3,201 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from pnp/sharepoint-skills at commit aa9eb14, republished under its MIT licence (© pnp). 3,201 words, ~6,352 tokens.
.claude/skills/sharepoint-safe-html/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Generate a single self-contained .html file that works reliably when hosted in SharePoint or OneDrive and opened through preview, File Viewer, Teams, or an embedded iframe.
If a narrower installed skill matches the artifact type (for example, an executive report, dossier, scorecard, or roadmap), use that skill for content structure and apply this skill's safety and accessibility contract to the final HTML.
Create exactly one .html file that works with:
.csv or .xlsx data files.Assume SharePoint and OneDrive render the file inside a restricted sandboxed iframe. If it works locally but relies on anything outside the file, it is not SharePoint-safe.
SharePoint/OneDrive can live link up to 10 .csv or .xlsx files in the same folder as the HTML file, so the artifact updates when those files change. Treat this as the only approved external-file exception, and use it only when the user wants an auto-updating data-backed artifact.
Prefer static, self-contained, CSS-driven HTML.
Use JavaScript only when the user explicitly needs interactivity and accepts that SharePoint/OneDrive sandbox behavior may vary. If JavaScript is used, it must be inline, dependency-free, non-networked, and progressive enhancement only. The artifact must remain useful if scripts are blocked.
Accessibility is not a final polish step. It must shape the content model, visual design, render logic, and validation pass.
Identify the requested output type and audience:
Do not ask for information the user already provided. If the request can be completed from the prompt or attached data, proceed.
Before writing HTML, decide the page sections and data to embed. Keep only the information the user intended to publish in the artifact.
For private M365, email, Teams, SharePoint, CRM, or customer data:
For accessibility, define the semantic purpose of each section before rendering it:
If the user wants the artifact to auto-update from source files, use live-linked .csv or .xlsx data files instead of embedding stale snapshots. Follow the live-linked data rules below before generating the final HTML.
Use live-linked data only when all conditions are true:
.csv or .xlsx file in SharePoint or OneDrive..csv or .xlsx file is in the same folder as the HTML artifact.Rules:
.csv or .xlsx files..csv or .xlsx file in the same SharePoint/OneDrive folder. Do not link across folders, sites, drives, tenants, or local paths.Live-linked .csv and .xlsx files can change after the HTML is created. Generate defensive render logic so updated, empty, renamed, or partially missing data does not crash the artifact.
Required reliability rules:
"", 0, false, or []; they are not allowed to create backup records, fake rows, placeholder metrics, or cached content..map, .filter, .reduce, .forEach, or similar array methods on a value unless it has first been normalized with Array.isArray(value) ? value : []."", 0, false, or [].Not provided and keep the rest of the artifact usable.Use this defensive pattern for any live-linked array before rendering:
const rows = Array.isArray(sourceRows) ? sourceRows : [];
const cards = rows.map(row => ({
title: String(row.Title ?? row.Name ?? "Untitled"),
status: String(row.Status ?? "Not provided"),
value: Number.isFinite(Number(row.Value)) ? Number(row.Value) : 0
}));Before handoff, test the generated artifact logic against these data states:
The expected result for state 6 is a visible error message such as: Live data failed to load. Check that the linked CSV/XLSX files are in the same folder as this HTML file and match the expected schema. It must not show stale, sample, or hardcoded business data.
Use semantic HTML and inline CSS:
main, section, article, header, footer, h1-h6, p, ul, ol, dl, table, figure, and figcaption where appropriate.h1 and maintain accessible heading order.<style> block..sp-html-artifact."Segoe UI", Aptos, Arial, sans-serif.Use this base pattern unless the requested design requires a different layout:
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<meta name="color-scheme" content="light">
<title>SharePoint-safe HTML artifact</title>
<style>
:root { color-scheme: light; }
* { box-sizing: border-box; }
body {
margin: 0;
font-family: "Segoe UI", Aptos, Arial, sans-serif;
background: #f8fafc;
color: #111827;
line-height: 1.5;
}
.sp-html-artifact {
width: 100%;
max-width: 1440px;
margin: 0 auto;
padding: 24px;
}
.sr-only {
position: absolute;
width: 1px;
height: 1px;
padding: 0;
margin: -1px;
overflow: hidden;
clip: rect(0, 0, 0, 0);
white-space: nowrap;
border: 0;
}
:focus-visible {
outline: 3px solid #2563eb;
outline-offset: 3px;
}
@media (max-width: 640px) {
.sp-html-artifact { padding: 14px; }
}
@media (prefers-reduced-motion: reduce) {
*, *::before, *::after {
animation-duration: 0.01ms !important;
animation-iteration-count: 1 !important;
scroll-behavior: auto !important;
transition-duration: 0.01ms !important;
}
}
</style>
</head>
<body>
<main class="sp-html-artifact" id="main-content">
<header aria-labelledby="page-title">
<h1 id="page-title">Artifact title</h1>
<p>Lead with the most important message.</p>
</header>
</main>
</body>
</html>Generate HTML through a small, explicit render pipeline so the artifact is predictable and debuggable:
Do not intermix raw source parsing, normalization, and HTML string construction in the same code path. Most broken artifacts come from rendering directly from unknown data shapes.
Required render safeguards:
{{TITLE}}, {{CONTENT}}, TODO, undefined, null, [object Object], or NaN in visible output.For live-linked reports, wrap the live-data initialization in a visible error boundary. The boundary may catch parsing/loading exceptions only to replace the broken section with an error panel. It must not render backup business data.
Escape all values from emails, chats, documents, lists, spreadsheets, M365, CRM, or user-provided data before inserting into HTML:
| Character | Escape |
|---|---|
& | & |
< | < |
> | > |
" | " |
' | ' |
Never render raw untrusted HTML.
Before handing the file to the user, verify the source, layout, and accessibility:
alt="".role="status"/role="alert" live regions.Run the full Validation Checklist and Accessibility validation checklist below before handoff.
Target WCAG 2.2 AA unless the user explicitly asks for a different standard.
The artifact must be perceivable, operable, understandable, and robust. Build accessibility into the content model and rendering approach rather than treating it as a final checklist.
This skill's Accessibility Rules and Accessibility validation checklist below cover the rules to apply and verify on every artifact. For the full implementation patterns behind those rules — semantic page structure, live-region markup for dynamic content, accessible KPI card and table markup, accessible chart patterns, color/contrast, keyboard/focus, reduced motion, responsive/zoom behavior, image/SVG alt handling, link/button text, and plain-language guidance, each with runnable HTML/CSS examples — see references/accessibility.md. Read it before building any section that involves dynamic status, charts, tables, or KPI cards.
Use these freely:
<style>.details and summary for progressive disclosure.data:image/svg+xml or data:image/png;base64 assets only when necessary and size-safe.Prefer CSS-only visuals over external chart libraries. For example, use horizontal bars, status chips, sparklines, timelines, matrix cells, inline SVG, or semantic tables.
Do not use:
<script src=...>.<link rel="stylesheet" ...>.fetch, XMLHttpRequest, WebSocket, EventSource, Graph, SharePoint REST, Dataverse, Power BI, or any runtime network API from the HTML file..csv or .xlsx exception.file://, C:\..., /Users/..., localhost, blob URLs created outside the page, or temporary paths.outline: none unless an equally visible replacement is applied.Default to no JavaScript.
JavaScript is allowed only if all conditions are true:
eval, dynamic script injection, or remote code loading.Acceptable JavaScript use cases include local tab switching, expand/collapse, sorting/filtering embedded table data, lightweight client-side search over embedded data, and optional failure-tolerant copy-to-clipboard.
Prefer details/summary, anchor links, static tables/charts, and CSS bars/sparklines when they satisfy the need.
When JavaScript changes visible content:
role="status" live region for meaningful state changes.role="alert" for blocking errors.Use these rules for every artifact:
h1.main landmark.alt text for meaningful images.alt="" or aria-hidden="true" as appropriate.prefers-reduced-motion.Search the final HTML source for these banned strings and remove any unsafe usage:
http://https://cdn<script src=<link rel="stylesheet"fetch(XMLHttpRequestWebSocketEventSourcefile://localhostC:\/Users/{{TODOundefined[object Object]NaNThen verify:
.html file, unless the user approved live-linked .csv or .xlsx data files..csv/.xlsx files in the same folder as the HTML artifact and no other external file types..map, .filter, .reduce, .forEach, or nested property reads on unnormalized data.Verify the following before handoff:
h1 exists.main landmark exists.role="status" and aria-live="polite".role="alert".aria-hidden="true".th and scope where appropriate.When a user asks for SharePoint-safe HTML, follow this instruction:
Create a single self-contained HTML file for SharePoint/OneDrive preview. Use inline CSS only. Do not use external CSS, JS, images, fonts, APIs, CDNs, local file references, secrets, or runtime network calls. Avoid JavaScript unless explicitly required; if used, keep it inline, dependency-free, non-networked, optional, and accessible. Escape all untrusted content. Use semantic accessible HTML, responsive iframe-friendly layout, system fonts, and CSS-only visuals where possible. Target WCAG 2.2 AA by default. Include a
mainlandmark, exactly oneh1, logical headings, visible focus, sufficient contrast, descriptive links, accessible buttons, accessible loading/error states, and reduced-motion support. KPI cards must expose label/value relationships, preferably with a definition list. Tables must include captions or nearby summaries and proper headers. Charts must never be visual-only — every chart must provide the same data as text, a list, or a table, and must not rely on color, hover, width, or position alone to communicate meaning. Validate that the source contains no external dependencies and that the file renders in SharePoint/OneDrive preview.
If the user wants auto-updating data, use only the SharePoint/OneDrive live-linked data exception: up to 10 linked .csv or .xlsx files in the same folder as the HTML artifact, with visible source/freshness notes and no agent-authored runtime fetch/API code. Live-linked reports must be live-only: never embed backup rows, fallback datasets, cached snapshots, sample rows, or stale hardcoded business data. If the live link fails, render a visible error explaining what to fix. Because linked files can change after generation, define each file's expected schema, normalize all data to safe defaults, never call array methods on unverified values, and render visible empty/error states instead of uncaught render errors.
© pnp, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in Skills/sharepoint-safe-html/sharepoint-safe-html of pnp/sharepoint-skills.
Open the folder on GitHubat commit aa9eb14
Sharepoint Safe HTML next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sharepoint Safe HTML this skillpnp/sharepoint-skills | 131 | — | ~6.4k | Automated safety check: Pass | MIT | |
| aai-cli Microsoft 365aai-labs/agent-barn | 109 | — | ~1.2k | Automated safety check: Pass | Apache-2.0 | |
| Add Data Sourcemicrosoft/power-platform-skills | 972 | 1 repos | ~1.1k | Automated safety check: Pass | MIT | |
| Msgraphcodemie-ai/codemie-code | 294 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Workiqmicrosoft/work-iq | 1k | — | ~15k | Automated safety check: Pass | Custom licence | |
| Workiq Previewmicrosoft/work-iq | 1k | — | ~3.3k | Automated safety check: Pass | Custom licence |
aai-labs/agent-barn
Guides work with Outlook, OneDrive, SharePoint, Teams, Excel, To Do and Planner through aai-cli's Microsoft Graph commands, starting from which service owns the data.
microsoft/power-platform-skills
Guide the user to add a data source, connection, or API connector to a Canvas App via Power Apps Studio, then verify and continue.
codemie-ai/codemie-code
Work with Microsoft 365 services via the Graph API — emails, calendar events, SharePoint sites (read and write), Teams chats and channel messages, OneDrive files, OneNote notebooks, Planner task…
microsoft/work-iq
WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.
microsoft/work-iq
WorkIQ tools for Microsoft 365 workplace data and actions. An agent skill from microsoft/work-iq.
github/awesome-copilot
Integrate Microsoft Graph SDK into any project — .NET, TypeScript/JavaScript, or Python.
pnp/sharepoint-skills
Generates a polished, self-contained HTML heatmap scorecard — a weighted comparison matrix where entities (rows) are scored across dimensions (columns), with computed totals, rank badges, and a…
pnp/sharepoint-skills
Analyze the current SharePoint document library in read-only mode and produce a structured summary of files, folders, file types, recent activity, naming issues, and organization recommendations.
pnp/sharepoint-skills
Audits SharePoint pages, news posts, and hyperlink fields for broken or risky links and saves a self-contained HTML link-health report to the site.
pnp/sharepoint-skills
Analyze selected construction images, create missing object metadata columns, and write concise visual metadata back to SharePoint columns using explicit image-analysis, list-schema, list-update…
pnp/sharepoint-skills
Renders a polished, self-contained HTML briefing from any data source — SharePoint lists, uploaded documents, or a verbal description.
pnp/sharepoint-skills
Generates a polished, self-contained HTML executive report or dashboard from any data source — SharePoint lists, CSV exports, or a user description.
Categories
Creates accessible, single-file HTML artifacts that render reliably in SharePoint, OneDrive, Teams, File Viewer, and embedded iframe preview surfaces. Sharepoint Safe HTML is an agent skill from pnp/sharepoint-skills. Creates accessible, single-file HTML artifacts that render reliably in SharePoint, OneDrive, Teams, File Viewer, and embedded iframe preview surfaces.
Sharepoint Safe HTML fits situations like: the user asks for SharePoint-safe HTML; embeddable HTML file for Microsoft 365 preview surfaces.
Run `npx skills add pnp/sharepoint-skills --skill sharepoint-safe-html -a claude-code`. Or copy the skill folder (Skills/sharepoint-safe-html/sharepoint-safe-html in pnp/sharepoint-skills) into .claude/skills/sharepoint-safe-html in your project. Claude Code loads it when a task matches its description.
Run `npx skills add pnp/sharepoint-skills --skill sharepoint-safe-html -a codex`. Or copy the skill folder (Skills/sharepoint-safe-html/sharepoint-safe-html in pnp/sharepoint-skills) into .agents/skills/sharepoint-safe-html in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pnp/sharepoint-skills --skill sharepoint-safe-html -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sharepoint-safe-html, .gemini/skills/sharepoint-safe-html, .github/skills/sharepoint-safe-html and .opencode/skills/sharepoint-safe-html in your project.
SKILL.md names no scripts, command-line tools or credentials: Sharepoint Safe HTML is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sharepoint Safe HTML is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 6.4k tokens (SKILL.md is roughly 25k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Sharepoint Safe HTML: aai-cli Microsoft 365 (aai-labs/agent-barn, 109 stars), Add Data Source (microsoft/power-platform-skills, 972 stars), Msgraph (codemie-ai/codemie-code, 294 stars) and Workiq (microsoft/work-iq, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
pnp (a GitHub organization) maintains it in pnp/sharepoint-skills, which has 131 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 6, 2026.
Source: pnp/sharepoint-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.