You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I have read and followed the Guidance for submissions involving paid services. The skill does not depend on or promote any paid service; the few third-party tools it mentions are evaluated neutrally in one reference file.
My contribution adds a new skill in the correct directory (skills/spa-sharepoint-power-automate/).
The file follows the required naming convention (name matches the folder, lowercase with hyphens).
The content is clearly structured and follows the example format (SKILL.md is a 180-line router; detail lives in references/).
I have tested my skill with GitHub Copilot. Not yet. It was validated with the agentskills.io reference validator, this repo's validator and 29 static evals (router + required facts), but it has not been exercised with GitHub Copilot. I would welcome Copilot feedback in review.
I have run npm start and verified that README.md is up to date (npm run skill:validate: all 424 skills valid).
I am targeting the main branch for this pull request.
Description
A skill for the public SPA/PWA → Power Automate HTTP-trigger flow → SharePoint pipeline and for Power Automate + SharePoint troubleshooting in general.
The existing Power Automate skills in this repo focus on building and debugging flows through an MCP server. This one covers what usually breaks outside the designer, with the exact symptom, cause and fix:
trigger authentication default for new flows (401 from a public web app with an empty run history), Premium licensing, the 120 s / 100 MB limits, automatic suspension
Get items thresholds and pagination, 429 throttling with Retry-After, silent failures after an early Response, idempotent retries
tenant governance (DLP on the three HTTP connectors, corporate-network domains, conditional access) and Sites.Selected
solution flows by code (PAC CLI and the Dataverse workflow table), including Microsoft's own note that api.flow.microsoft.com is unsupported
a 78-row error catalog, list design, email limits, Power BI on lists, personal data
Structure: 34 sections in 22 reference files loaded on demand, English translations of seven key sections in references/en/, and a small tested SPA starter kit in assets/spa-starter/ (Vite + React + TypeScript, 122 tests, plus dependency-free helper scripts).
Evidence. Platform facts end with a Sources block (Microsoft Learn) and a date; anything not confirmed is marked NOT VERIFIED and its origin (official docs / forum / own observation) is labeled. The source repository validates every push with the agentskills.io reference validator, structure and link checks, a privacy scan and 29 static evals: https://github.com/apu242007/power-automate-sharepoint-skills
Type of Contribution
New instruction file.
New prompt file.
New agent file.
New plugin.
New skill file.
New agentic workflow.
New canvas extension.
Update to existing instruction, prompt, agent, plugin, skill, workflow, or canvas extension.
Other (please specify):
Additional Notes
AI assistance disclosure. This PR was prepared with Claude Code (an AI agent) on behalf of the skill's author, following the agent-contribution note in CONTRIBUTING.md.
The skill body is mostly Spanish (platform terms are in English) because it comes from real projects in Spanish-speaking teams. Seven key reference files already have English translations; I am happy to translate the rest or an English index if you prefer.
.codespellrc change. codespell's English dictionary flags ordinary Spanish words (254 hits in this skill, none elsewhere in the repository), so skip now lists only the Spanish source documentation (SKILL.md and references/[0-9]*.md) and the starter kit (Spanish comments and UI strings), the same way the localized website docs (es-es, ja-jp, ...) are skipped. The English translations in references/en/ are spell-checked, and the rest of the repository still is. If you would rather not have a Spanish skill in an English-language repo, I can close this or provide an English edition instead.
The starter kit has 2 moderate npm audit advisories from a dev-only dependency (@vitest/mocker, not part of the bundle). Happy to drop assets/spa-starter/ from this PR if you would rather keep bundled projects out.
Not affiliated with Microsoft or any tool mentioned.
By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.
Update (skill 1.4.6). After the automated reviews I checked the flagged platform claims against Microsoft Learn and corrected them (DirectQuery is not available for the SharePoint Online list connector; shared-mailbox Sent Items; CORS of the HTTP trigger is marked NOT VERIFIED; Get items pagination wording). The Microsoft first-party client-ID recipe and the Windows Credential Manager token-extraction technique are not part of this distribution. The starter kit was hardened (retries only with server-side idempotency, success only on 200 with the folio, draft expiry and deletion, EXIF-free photos, typed-name signature alternative, per-app storage and cache keys, atomic service-worker install, SP_TOKEN only to SharePoint hosts) and the flow template now requires body validation and a duplicate check by folio. Still open: the CORS preflight of Power Automate triggers has not been verified against a real trigger from a browser.
Skill for the public SPA/PWA -> Power Automate HTTP-trigger flow ->
SharePoint pipeline and Power Automate + SharePoint troubleshooting:
trigger auth default, licensing, limits, throttling, resilience, tenant
governance (DLP), PAC CLI/Dataverse, list design and a 78-row error
catalog. Includes English translations of key sections and a small
tested SPA starter kit.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
✓ [spec-compliance] All 1 skill(s) are spec-compliant.
ℹ️
✓ spec-compliance: All spec checks passed.
ℹ️
✓ [valid-refs] All file references across 1 skill(s) are valid.
ℹ️
✓ valid-refs: All file references resolve to existing files within the skill directory.
ℹ️
1 skill(s) linted, 1 passed
Full linter output
### Linting skills/spa-sharepoint-power-automate
✅ spa-sharepoint-power-automate (2/2 checks passed)
✓ [spec-compliance] All 1 skill(s) are spec-compliant.
✓ spec-compliance: All spec checks passed.
✓ [valid-refs] All file references across 1 skill(s) are valid.
✓ valid-refs: All file references resolve to existing files within the skill directory.
1 skill(s) linted, 1 passed
The spa-sharepoint-power-automate skill is written mostly in Spanish and
codespell's English dictionary flags ordinary Spanish words (254 hits,
none elsewhere in the repository). Skip the skill directory the same way
the localized website docs are skipped.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Adds a differentiated Power Automate–SharePoint troubleshooting skill, including operational guidance and a React/Vite reference SPA.
Changes:
Adds a skill router with Spanish references and selected English translations.
Adds a tested SPA/PWA starter, deployment workflow, and diagnostic scripts.
Regenerates the skills catalog.
However, the starter’s direct browser integration has blocking CORS, validation, retry, privacy, and accessibility issues, alongside several inaccurate documentation claims.
Cache Storage is shared by every app on an origin, regardless of service-worker scope. GitHub Pages commonly hosts multiple repositories under one origin, so this generic prefix lets one starter app delete another app’s caches during activation. Namespace the prefix with self.registration.scope.
The smoke test exits successfully for 202 Accepted, but this skill defines an empty 202 as the symptom of a branch missing its required Response action. As written, the advertised end-to-end check cannot detect that configuration error. Require the expected 200 response here.
Mark external documentation skill as an optional dependency
This says the external power-automate-documentation skill is installed, but installing this contribution does not install anything from microsoft/cat-agent-skills. Consumers may therefore be told to invoke a capability they do not have. Present it as an optional external dependency and include explicit installation/check instructions or a built-in fallback.
…back
- Verified against Microsoft Learn: DirectQuery is not available for the SharePoint Online list connector; shared-mailbox Sent Items go to the sender by default; CORS of the HTTP trigger is marked NOT VERIFIED; Get items pagination wording clarified.
- Added mandatory flow-side validation, untrusted-input notes for email, and gateway-based abuse control.
- Removed the Microsoft first-party client-ID recipe and the Windows Credential Manager token-extraction technique from this distribution.
- description is now a single single-quoted scalar.
- Removed a reference to material that is not distributed and a pointer to a missing file.
- Narrowed the codespell skip to the Spanish documentation and the starter kit; the English translations are checked again.
- Adds the tested flows-as-code recipe (section 26.7).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
allSettled lets a partially populated cache install successfully. The worker then activates and deletes the previous complete cache, so one transient precache failure can break offline startup after an update. Fail the install when any required shell resource cannot be cached so the previous worker/cache remains available.
Prevent upload script from overwriting existing files
The script is advertised as creating a new file to exercise creation triggers, but overwrite=true silently replaces an existing file when --name is reused. That can destroy test-library content and will not exercise the intended “created” behavior. Use overwrite=false and fail clearly on a name collision; update the matching CLI test and documentation snippet as well.
The file input remains enabled while an earlier selection is still being compressed. A second selection can start concurrently; when the first operation finishes it clears compressing, enabling submission while the second selection is still pending, so those newly selected photos may be omitted from the submitted payload. Disable the input during compression.
Use safe non-overwriting uploads for new-file tests
Although this section says the upload must create a new file, overwrite=true can replace an existing file and therefore exercise modification behavior—or destroy existing test content—instead. Use overwrite=false, matching the safety correction in the bundled upload script.
This promises that photos remain in localStorage, but the bundled implementation explicitly persists only text and signature (App.tsx's FormState; draftStorage.ts also documents that photos are excluded). After a reload, users must reselect every photo, so this recovery guidance is misleading.
- Automatic retries: only 429; 500/503 only with serverIdempotent (flow must deduplicate by folio).
- Success requires 200 with the folio; an empty 202 or a 200 without it is reported as unconfirmed and the draft is kept.
- Drafts expire after 7 days and there is a delete-my-data button.
- Photos are always re-encoded through a canvas so EXIF (including GPS) is dropped.
- The service worker no longer reloads on update; it shows a banner.
- The signature has a typed-name alternative for keyboard and screen-reader users.
- 117 starter tests pass; npm run skill:validate passes.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Thanks for the detailed reviews. I pushed two updates (fe9b41e and a23c86f, skill version 1.4.4) that address the findings.
Content (checked against Microsoft Learn)
DirectQuery is not available for the SharePoint Online list connector (Import only); corrected.
Messages sent from a shared mailbox are saved in the sender's Sent Items unless Exchange copy settings are enabled; corrected.
The CORS behaviour of the HTTP trigger is now marked NOT VERIFIED (Learn does not document it). The guidance says to test in a browser against the real trigger and to use a proxy if the preflight fails.
Get items: Learn says items are "paginated by default", but only 100 are returned unless the Pagination setting is turned on; the wording now says so.
Added mandatory flow-side validation of the request body, a note that email fields and attachments from a public caller are untrusted, and gateway-based rate limiting / bot verification from the start.
Removed the Microsoft first-party client-ID recipe and the Windows Credential Manager token-extraction technique from this distribution; they are replaced by approved app registrations, Sites.Selected and gh.
description is a single single-quoted scalar; removed a reference to material that is not distributed and a pointer to a missing file.
.codespellrc: the skip is narrowed to the Spanish documentation and the starter kit (Spanish comments and UI strings); the English translations are spell-checked again.
Starter kit (117 tests, npm run skill:validate passes)
Automatic retries: only 429 retries on its own; 500/503 retry only with serverIdempotent: true, to be enabled only when the flow deduplicates by folio (the flow guide now documents the duplicate check).
Success requires 200 with the folio in the body; an empty 202 or a 200 without the folio is reported as unconfirmed and the draft is kept.
Drafts expire after 7 days and there is a "delete my data on this device" button.
Photos are always re-encoded through a canvas, so EXIF (including GPS) is dropped.
The service worker no longer reloads the page on update; it shows a banner so chosen photos are not lost.
The signature has a typed-name alternative for keyboard and screen-reader users.
Not yet verified: the typed-name signature and the update banner were checked by type-check and unit tests, not in a real browser or phone.
On the first visit, registration happens after the page's JS/CSS have already loaded, but the precache contains only HTML/manifest/icons. The newly installed worker therefore has no hashed /assets/ entries, so going offline after that first visit returns cached HTML whose JS/CSS are unavailable. Inject the Vite build assets into the precache (or use a generated service-worker manifest) so the advertised first-visit offline behavior works.
Use ResourcePath APIs for special-character SharePoint names
This uses the legacy string-based GetFolderByServerRelativeUrl/Files/add APIs even though the surrounding guidance explicitly asks users to test names containing % and #. Microsoft documents the ResourcePath APIs for those names; the legacy form is ambiguous and can fail despite this helper's percent encoding. Use GetFolderByServerRelativePath(decodedurl=...) with Files/AddUsingPath(...) and update the URL tests/reference snippet.
Honor Retry-After instead of retrying after a shorter cap
Capping a server-provided Retry-After and retrying sooner does not respect the header and can extend SharePoint throttling or trigger blocking. If the requested delay exceeds the caller's maximum acceptable wait, stop and return/throw the throttling result rather than retrying after the shorter cap.
Limit photo processing before decoding and compressing
The 10-photo cap is applied only after every selected file has been decoded and compressed concurrently. Selecting many full-resolution photos can therefore allocate hundreds of megabytes on a phone for files that are ultimately discarded. Slice to the remaining slot count before processing and compress sequentially (or with tightly bounded concurrency).
Combinar registros explícitamente por identificador en lugar de union()
union() no combina registros de dos arreglos por una clave. Solo elimina elementos que sean objetos completamente idénticos; dos registros con la misma clave y campos nulos/distintos permanecen separados, y el orden de argumentos no es una estrategia de merge soportada. Indicá una combinación explícita por el identificador del registro.
Use ResourcePath APIs in the special-character upload snippet
This copied snippet has the same special-character problem as the bundled CLI: GetFolderByServerRelativeUrl/Files/add are legacy string-based APIs and are unreliable for the %/# filename cases that §28.3 asks users to test. Show the ResourcePath form (GetFolderByServerRelativePath(decodedurl=...) plus Files/AddUsingPath(...)) instead.
Merge records explicitly by identifier instead of using union()
This is not how union() merges arrays of records. Array elements are deduplicated only when the entire objects are equal; records sharing a lookup key but differing in null/non-null fields are both retained, and input order is not a supported key-based merge strategy. Recommend an explicit merge keyed by the record identifier instead of reversing the arguments.
Test the skill with representative GitHub Copilot scenarios
skills/spa-sharepoint-power-automate/SKILL.md:3
The PR checklist states that this new skill has not yet been exercised with GitHub Copilot. Static router/fact checks do not verify that Copilot selects the intended reference, follows the long cross-file instructions, or produces a usable result. Please run and document representative Copilot scenarios before presenting the skill as ready for installation.
This cache prefix is shared across every app on the same origin. Two GitHub Pages projects built from the starter can share a cache and delete each other's offline assets during activation. Derive the prefix from the service-worker scope so each deployed project owns only its caches.
Fail installation when required precache resources are unavailable
Allowing every precache request to fail still activates this worker, after which activate deletes the previous cache. A transient failure can therefore replace a complete offline cache with an incomplete one. Required shell resources should fail installation so the previous worker/cache remains active.
Use SharePoint ResourcePath APIs for special-character names
GetFolderByServerRelativeUrl is the legacy string API and has ambiguous handling for literal % and #; encoding them here does not make those names reliable. This conflicts with the stated special-character support. Use SharePoint's ResourcePath APIs (GetFolderByServerRelativePath/AddUsingPath) for these names and validate against a real tenant.
The ten-photo limit is applied only after every selected file has been decoded concurrently. Selecting a large camera roll can therefore allocate and compress hundreds of full-resolution images before discarding all but ten, potentially freezing or crashing a mobile browser. Slice to the remaining slots before Promise.all.
Run and document representative GitHub Copilot scenarios
The contribution checklist says this skill has not been exercised with GitHub Copilot, but this line presents it as an end-to-end Copilot reference. The repository requires skills to be tested with Copilot; static evals and starter-kit unit tests do not validate routing or instruction-following. Please run and document representative Copilot scenarios before merging.
Document that failed submissions lose selected photos
This promises that photos survive in localStorage, but the bundled implementation explicitly persists only text and the signature (App.tsx:21, README.md:55). Closing or reloading after a failed submission therefore loses every selected photo, so the recovery guidance must state that limitation.
Avoid auto-reload that discards photos after service-worker updates
This auto-reload recipe conflicts with the bundled starter, which deliberately prompts before reloading because selected photos are not persisted. Following this section can reload immediately after a service-worker update and discard an in-progress user's photos; update the pattern and the later error-catalog entry to emit an update-ready event and let the user choose when to reload.
Correct misleading diagnosis of Apply to each save conflicts
Apply to each is sequential by default, which this skill also states in references/10-resiliencia-y-errores-flow.md:43. A save conflict is caused when concurrency was enabled above 1, not by the default, so this diagnosis can make users change a safe loop unnecessarily.
Do not persist credentials in localStorage: any script running on the same origin can read them, and this section targets shared field devices. Persist only a non-sensitive item identifier or opaque server-issued handle; keep tokens/PINs out of browser storage.
Make power-automate-documentation an optional dependency
This says power-automate-documentation is installed and auto-triggers, but that skill is not bundled in this repository. Consumers installing this skill will not necessarily have it, so the instruction can make Copilot depend on an unavailable external component. Describe it as optional and require checking availability/installing it before use.
SP_TOKEN only to SharePoint hosts; photos that cannot be re-encoded are skipped instead of uploading the original; precache of build assets; per-app draft keys; mandatory validation and duplicate check in the flow template; accurate retry and reload docs. 122 starter tests pass.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Automatically reloading on controllerchange contradicts the bundled starter's update banner and can discard selected photos, which are intentionally not persisted. Update this section to dispatch an update-ready event and let the user choose when to reload, matching assets/spa-starter/src/lib/registerSW.ts.
A manifest icon's sizes value must describe the bitmap's actual dimensions; declaring one PNG as both 192×192 and 512×512 does not make it a valid 512×512 icon. This guidance would teach users to ship incorrect metadata. Require separate correctly sized files (as the bundled starter already does).
Per-scope service worker cache prefix; atomic install so a partial precache cannot replace a working one; DoD SharePoint host in the token allowlist; the SPA guide no longer recommends automatic reloads and declares manifest icons correctly.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
CORS of the HTTP trigger. Several review comments say the trigger does not answer a browser preflight. I tested it instead of assuming: a browser-style OPTIONS (Origin: https://apu242007.github.io, Access-Control-Request-Method: POST, Access-Control-Request-Headers: content-type,x-app-key) against a *.environment.api.powerplatform.com trigger URL was answered 204 with:
and the actual POST response also carried Access-Control-Allow-Origin: *. Caveats, which the skill now states: Microsoft does not document this; the test used the URL of a flow I had just deleted, so it shows the gateway's behaviour rather than a live run from a real page; only this URL format was tested (not older logic.azure.com URLs). The guidance is now "observed, not documented: test with your own trigger", and because the trigger accepts any origin, the docs stress rate limiting and bot verification in front of it for production.
Also fixed in this round: service-worker cache prefix per scope and atomic install, DoD SharePoint host in the SP_TOKEN allowlist, the SPA guide no longer recommends automatic reloads and declares manifest icons correctly.
Still open by design: manual "Retry" after an ambiguous outcome only avoids duplicates if the flow deduplicates by folio; the flow template now requires that (steps 3b and 3c), and the client keeps serverIdempotent off by default.
paintDataUrl() leaves an asynchronous Image.onload callback active. If the user clears the restored signature or starts a new stroke before that callback runs, the old image can be painted back afterward, leaving the canvas visibly signed while the parent value is null or overwriting the new stroke. Invalidate pending paints on clear and pointer-down (for example with a generation token checked inside onload).
The bundled starter payload has no checklist property, yet this canonical template iterates that property directly. Following the starter instructions therefore passes null to Apply to each, so the run fails after the early 200 response and the email is skipped. Default the missing property to an empty array (or add checklist: [] to the starter contract).
Align attachment contract with starter payload contents
This attachment contract does not match the bundled starter: buildPayload() puts the signature at attachments[0], followed by photos, and §34 explicitly says the starter does not generate a PDF. A user combining the advertised starter and canonical flow will therefore attach the signature image as the business PDF. Make PDF attachment conditional, or align the starter payload ordering and content.
Clarify that parallel processing requires enabled concurrency
Apply to each runs sequentially by default; it only runs in parallel after Concurrency Control is enabled above 1. Calling parallelism the default gives users the wrong diagnosis for a Save Conflict. Describe this as the cause only when concurrency was enabled, while retaining the degree-1 requirement for same-item writes.
This instruction contradicts §10 (references/04-sharepoint.md:6-10), which explicitly corrected the old “skip the script” rule and says to attempt the REST POST once before falling back to the UI. Keeping both makes the router produce different setup procedures depending on which reference Copilot opens.
Use the SharePoint list delta endpoint for generic lists
This endpoint tracks drive items, so it only covers document libraries. For the generic SharePoint lists discussed in this section, Graph's delta endpoint is /sites/{siteId}/lists/{listId}/items/delta; directing users to the drive endpoint will miss their list changes.
Mark power-automate-documentation as an optional dependency
power-automate-documentation is not bundled with this contribution, so it will not be installed—or auto-triggered—for users who install this skill. Describing the author's private environment as current state makes Copilot rely on an unavailable dependency. Mark it as an optional external skill and require checking/installing it separately before invoking it.
Use the SharePoint list delta endpoint for generic lists
This endpoint tracks drive items, so it only covers document libraries. For the generic SharePoint lists discussed in this section, Graph's delta endpoint is /sites/{siteId}/lists/{listId}/items/delta; directing users to the drive endpoint will miss their list changes.
spFetch retries every 503 regardless of the HTTP method. For a POST, the server can commit the write and still return/lose a 503 response, so replaying it can create duplicate list items—the same ambiguity that uploadClient guards with serverIdempotent. Restrict automatic 503 retries to idempotent methods or require an explicit idempotency/deduplication option for writes, and update the tests and usage docs accordingly.
Reject invalid --max-chars values to enforce output limits
--max-chars is not validated. With NaN the truncation comparison is always false, and with a negative number slice(0, -1) emits almost the entire body, defeating this CLI's output cap and potentially exposing a large or sensitive SharePoint response. Reject invalid values before making the request.
--max-chars is not validated. A typo such as --max-chars nope makes the comparison against NaN false and prints the complete response body; a negative value prints nearly all of it. Since flow responses can contain operational or personal data, reject non-integer or negative values just as this code already rejects an invalid timeout.
Require exact 200 response and matching folio in smoke test
This smoke test treats every 2xx response as success, so Power Automate's silent 202 for a branch without a Response action passes even though the starter client deliberately classifies it as unconfirmed. Require the documented contract (200 plus the same folio) before returning exit code 0; otherwise this script misses the exact flow wiring failure it is intended to catch.
Prevent stale image loads from repainting deleted signatures
Image loading is asynchronous, but this callback does not verify that the signature is still current. If a restored/typed signature is still decoding when the user clicks “Borrar firma,” its later onload repaints the supposedly deleted signature; it can likewise overwrite a newly drawn stroke. Track/cancel stale paint requests (for example with a generation ref incremented by clear/new input) before drawing.
Clarify that failed submissions do not persist selected photos
This says the failed submission's photos remain in localStorage, but the starter explicitly persists only text and signature (App.tsx:20, draftStorage.ts:14); photos survive only while the current page remains open. This can make users believe it is safe to close/reload after a failure and then lose all selected photos. Document that limitation here.
An administrator role by itself is not sufficient authorization for this Graph call: the access token used for POST /sites/{siteId}/permissions must carry the required Sites.FullControl.All permission. As written, a global administrator can follow this step and still receive 403, while the actual token requirement is obscured. State the required Graph permission (and the applicable admin role/consent separately).
An administrator role by itself is not sufficient authorization for this Graph call: the access token used for POST /sites/{siteId}/permissions must carry the required Sites.FullControl.All permission. As written, a global administrator can follow this step and still receive 403, while the actual token requirement is obscured. State the required Graph permission (and the applicable admin role/consent separately).
This retries every 429/503 regardless of method, while the CLI accepts arbitrary methods and bodies. Automatically replaying POST/PATCH requests can duplicate a mutation when the server committed it before returning a transient error; restrict automatic retries to idempotent methods unless callers explicitly opt in with an idempotency guarantee.
Overlapping file processing can re-enable submission prematurely
The picker remains enabled while an earlier batch is being compressed, so two handleFiles calls can overlap. The first completion can clear compressing while the second is still running, re-enabling submission before every selected photo has been processed.
SignaturePad owns the typed signer name in internal state, so startOver() clears the parent draft but leaves that personal data visible in the mounted child after “Borrar mis datos.” Remount it when a new folio is created so all signature state is cleared.
Returning the original blob for unsupported formats defeats the section's privacy guarantee: the original can retain EXIF/GPS metadata and later be uploaded. Reject unsupported input instead of passing it through unchanged.
This issue also appears on line 379 of the same file.
This saves a profile that can contain a DNI indefinitely in localStorage; deletion is only manual. On shared or lost devices that retains identity data beyond the stated privacy/minimization model, so add an expiry and avoid storing DNI by default (or scope it to an authenticated user).
Photo removal buttons need unique accessible names
Every photo-removal button has the same accessible name, “Quitar,” so screen-reader button navigation cannot identify which photo will be removed. Include the photo number or file name in an aria-label.
Synchronous response limit is incorrectly stated as 110 seconds
The platform's documented synchronous response limit is 120 seconds, not approximately 110 seconds. Keeping the incorrect value here makes this otherwise copyable guidance disagree with the limit reference.
Use the documented 120-second synchronous response limit
The documented synchronous HTTP response limit is 120 seconds, not approximately 110 seconds; this also conflicts with the 120-second value used elsewhere in this skill. Use the platform limit consistently.
Anonymous triggers can still write validated Person values
An anonymous trigger does not prevent the authenticated SharePoint connector from populating a Person column. What is unavailable is trustworthy caller identity; a validated tenant email/claims value can still be written, so this rule would make users unnecessarily redesign their list.
Sequential Apply to each does not explain concurrent conflicts
Apply to each is sequential by default; it only runs iterations in parallel when concurrency control is explicitly enabled. This diagnosis can send users looking for a default that does not exist and misses other concurrent flow runs or writers that can cause the same conflict.
The platform's documented synchronous response limit is 120 seconds, so calling this a 110-second gateway timeout makes the troubleshooting guidance internally inconsistent.
Troubleshooting row uses an incorrect 110-second limit
This troubleshooting row should use the documented 120-second synchronous response limit. The current 110-second value conflicts with the skill's own limits reference and can mislead timing investigations.
Risk tier:merge-risk:high — Privileged execution, automation, or review-policy change Required to merge: passing submission-gate checks plus 2 approvals from reviewers with write access, including a maintainer with admin or maintain permission.
Why this tier
skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/cli.test.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/make-icons.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/sp-upload-test-file.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/spfetch.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/spfetch.test.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/test-flow.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
Spawns processes or evaluates code in skills/spa-sharepoint-power-automate/references/08-flows-como-codigo.md
The contributor check succeeded but its result artifact was missing, unreadable, or for another commit · logs
Action needed
🔧 Contributor risk signal hit an automation problem that is not caused by your contribution. Comment /rerun-checks to retry; maintainers are notified if it keeps failing.
Still needed: 2 more approval(s); an approval from a maintainer with admin or maintain permission
The core-maintainers pool is not staffed yet; an approver with admin or maintain permission is required instead.
Commands
Command
Who
What it does
/rerun-checks
PR author, maintainers
Re-runs failed or incomplete checks and re-evaluates this gate
/request-review
PR author, maintainers
Asks the review rotation to assign a reviewer (adds needs-reviewer)
Updated for c4aa911 · This comment is maintained automatically — see submission gate docs.
This branch has not been deployed
No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pull Request Checklist
skills/spa-sharepoint-power-automate/).namematches the folder, lowercase with hyphens).SKILL.mdis a 180-line router; detail lives inreferences/).npm startand verified thatREADME.mdis up to date (npm run skill:validate: all 424 skills valid).mainbranch for this pull request.Description
A skill for the public SPA/PWA → Power Automate HTTP-trigger flow → SharePoint pipeline and for Power Automate + SharePoint troubleshooting in general.
The existing Power Automate skills in this repo focus on building and debugging flows through an MCP server. This one covers what usually breaks outside the designer, with the exact symptom, cause and fix:
Get itemsthresholds and pagination, 429 throttling withRetry-After, silent failures after an earlyResponse, idempotent retriesSites.Selectedworkflowtable), including Microsoft's own note thatapi.flow.microsoft.comis unsupportedStructure: 34 sections in 22 reference files loaded on demand, English translations of seven key sections in
references/en/, and a small tested SPA starter kit inassets/spa-starter/(Vite + React + TypeScript, 122 tests, plus dependency-free helper scripts).Evidence. Platform facts end with a Sources block (Microsoft Learn) and a date; anything not confirmed is marked NOT VERIFIED and its origin (official docs / forum / own observation) is labeled. The source repository validates every push with the agentskills.io reference validator, structure and link checks, a privacy scan and 29 static evals: https://github.com/apu242007/power-automate-sharepoint-skills
Type of Contribution
Additional Notes
.codespellrcchange. codespell's English dictionary flags ordinary Spanish words (254 hits in this skill, none elsewhere in the repository), soskipnow lists only the Spanish source documentation (SKILL.mdandreferences/[0-9]*.md) and the starter kit (Spanish comments and UI strings), the same way the localized website docs (es-es,ja-jp, ...) are skipped. The English translations inreferences/en/are spell-checked, and the rest of the repository still is. If you would rather not have a Spanish skill in an English-language repo, I can close this or provide an English edition instead.npm auditadvisories from a dev-only dependency (@vitest/mocker, not part of the bundle). Happy to dropassets/spa-starter/from this PR if you would rather keep bundled projects out.By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.
🤖 Generated with Claude Code
Update (skill 1.4.6). After the automated reviews I checked the flagged platform claims against Microsoft Learn and corrected them (DirectQuery is not available for the SharePoint Online list connector; shared-mailbox Sent Items; CORS of the HTTP trigger is marked NOT VERIFIED; Get items pagination wording). The Microsoft first-party client-ID recipe and the Windows Credential Manager token-extraction technique are not part of this distribution. The starter kit was hardened (retries only with server-side idempotency, success only on
200with the folio, draft expiry and deletion, EXIF-free photos, typed-name signature alternative, per-app storage and cache keys, atomic service-worker install,SP_TOKENonly to SharePoint hosts) and the flow template now requires body validation and a duplicate check by folio. Still open: the CORS preflight of Power Automate triggers has not been verified against a real trigger from a browser.