Skip to content

Add spa-sharepoint-power-automate skill (Power Automate + SharePoint pipelines: limits, licensing, governance, error catalog) 🤖🤖🤖 - #3730

Open
exertion-solutions wants to merge 12 commits into
github:mainfrom
exertion-solutions:add-spa-sharepoint-power-automate
Open

exertion-solutions wants to merge 12 commits into
github:mainfrom
exertion-solutions:add-spa-sharepoint-power-automate

Conversation

@exertion-solutions

@exertion-solutions exertion-solutions commented Sep 24, 2026 •

Copy link
Copy Markdown

Pull Request Checklist

  • I have read and followed the CONTRIBUTING.md guidelines.
  • I have read and followed the Guidance for submissions involving paid services. The skill does not depend on or promote any paid service; the few third-party tools it mentions are evaluated neutrally in one reference file.
  • My contribution adds a new skill in the correct directory (skills/spa-sharepoint-power-automate/).
  • The file follows the required naming convention (name matches the folder, lowercase with hyphens).
  • The content is clearly structured and follows the example format (SKILL.md is a 180-line router; detail lives in references/).
  • I have tested my skill with GitHub Copilot. Not yet. It was validated with the agentskills.io reference validator, this repo's validator and 29 static evals (router + required facts), but it has not been exercised with GitHub Copilot. I would welcome Copilot feedback in review.
  • I have run npm start and verified that README.md is up to date (npm run skill:validate: all 424 skills valid).
  • I am targeting the main branch for this pull request.

Description

A skill for the public SPA/PWA → Power Automate HTTP-trigger flow → SharePoint pipeline and for Power Automate + SharePoint troubleshooting in general.

The existing Power Automate skills in this repo focus on building and debugging flows through an MCP server. This one covers what usually breaks outside the designer, with the exact symptom, cause and fix:

  • trigger authentication default for new flows (401 from a public web app with an empty run history), Premium licensing, the 120 s / 100 MB limits, automatic suspension
  • Get items thresholds and pagination, 429 throttling with Retry-After, silent failures after an early Response, idempotent retries
  • tenant governance (DLP on the three HTTP connectors, corporate-network domains, conditional access) and Sites.Selected
  • solution flows by code (PAC CLI and the Dataverse workflow table), including Microsoft's own note that api.flow.microsoft.com is unsupported
  • a 78-row error catalog, list design, email limits, Power BI on lists, personal data

Structure: 34 sections in 22 reference files loaded on demand, English translations of seven key sections in references/en/, and a small tested SPA starter kit in assets/spa-starter/ (Vite + React + TypeScript, 122 tests, plus dependency-free helper scripts).

Evidence. Platform facts end with a Sources block (Microsoft Learn) and a date; anything not confirmed is marked NOT VERIFIED and its origin (official docs / forum / own observation) is labeled. The source repository validates every push with the agentskills.io reference validator, structure and link checks, a privacy scan and 29 static evals: https://github.com/apu242007/power-automate-sharepoint-skills


Type of Contribution

  • New instruction file.
  • New prompt file.
  • New agent file.
  • New plugin.
  • New skill file.
  • New agentic workflow.
  • New canvas extension.
  • Update to existing instruction, prompt, agent, plugin, skill, workflow, or canvas extension.
  • Other (please specify):

Additional Notes

  • AI assistance disclosure. This PR was prepared with Claude Code (an AI agent) on behalf of the skill's author, following the agent-contribution note in CONTRIBUTING.md.
  • The skill body is mostly Spanish (platform terms are in English) because it comes from real projects in Spanish-speaking teams. Seven key reference files already have English translations; I am happy to translate the rest or an English index if you prefer.
  • .codespellrc change. codespell's English dictionary flags ordinary Spanish words (254 hits in this skill, none elsewhere in the repository), so skip now lists only the Spanish source documentation (SKILL.md and references/[0-9]*.md) and the starter kit (Spanish comments and UI strings), the same way the localized website docs (es-es, ja-jp, ...) are skipped. The English translations in references/en/ are spell-checked, and the rest of the repository still is. If you would rather not have a Spanish skill in an English-language repo, I can close this or provide an English edition instead.
  • The starter kit has 2 moderate npm audit advisories from a dev-only dependency (@vitest/mocker, not part of the bundle). Happy to drop assets/spa-starter/ from this PR if you would rather keep bundled projects out.
  • Not affiliated with Microsoft or any tool mentioned.

By submitting this pull request, I confirm that my contribution abides by the Code of Conduct and will be licensed under the MIT License.

🤖 Generated with Claude Code

Update (skill 1.4.6). After the automated reviews I checked the flagged platform claims against Microsoft Learn and corrected them (DirectQuery is not available for the SharePoint Online list connector; shared-mailbox Sent Items; CORS of the HTTP trigger is marked NOT VERIFIED; Get items pagination wording). The Microsoft first-party client-ID recipe and the Windows Credential Manager token-extraction technique are not part of this distribution. The starter kit was hardened (retries only with server-side idempotency, success only on 200 with the folio, draft expiry and deletion, EXIF-free photos, typed-name signature alternative, per-app storage and cache keys, atomic service-worker install, SP_TOKEN only to SharePoint hosts) and the flow template now requires body validation and a duplicate check by folio. Still open: the CORS preflight of Power Automate triggers has not been verified against a real trigger from a browser.

Skill for the public SPA/PWA -> Power Automate HTTP-trigger flow ->
SharePoint pipeline and Power Automate + SharePoint troubleshooting:
trigger auth default, licensing, limits, throttling, resilience, tenant
governance (DLP), PAC CLI/Dataverse, list design and a 78-row error
catalog. Includes English translations of key sections and a small
tested SPA starter kit.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI balanced review requested due to automatic review settings September 24, 2026 15:59
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

🔒 PR Risk Scan Results

Scanned 65 changed file(s).

Severity Count
🔴 High 0
🟠 Medium 201
ℹ️ Info 20
Severity Rule File Line Match
🟠 package-exec-command skills/spa-sharepoint-power-automate/assets/spa-starter/.github/workflows/deploy-pages.yml 39 npx tsc --noEmit
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 11 "react": "^18.3.1",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 12 "react-dom": "^18.3.1"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 15 "@​​types/node": "^22.10.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 16 "@​​types/react": "^18.3.12",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 17 "@​​types/react-dom": "^18.3.1",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 18 "@​​vitejs/plugin-react": "^4.3.4",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 19 "typescript": "^5.6.3",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 20 "vite": "^6.0.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 21 "vitest": "^3.0.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 34 "@​​babel/helper-validator-identifier": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 35 "js-tokens": "^4.0.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 36 "picocolors": "^1.1.1"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 59 "@​​babel/code-frame": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 60 "@​​babel/generator": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 61 "@​​babel/helper-compilation-targets": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 62 "@​​babel/helper-module-transforms": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 63 "@​​babel/helpers": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 64 "@​​babel/parser": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 65 "@​​babel/template": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 66 "@​​babel/traverse": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 67 "@​​babel/types": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 68 "@​​jridgewell/remapping": "^2.3.5",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 69 "convert-source-map": "^2.0.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 70 "debug": "^4.1.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 71 "gensync": "^1.0.0-beta.2",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 72 "json5": "^2.2.3",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 73 "semver": "^6.3.1"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 90 "@​​babel/parser": "^7.29.8",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 91 "@​​babel/types": "^7.29.8",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 92 "@​​jridgewell/gen-mapping": "^0.3.12",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 93 "@​​jridgewell/trace-mapping": "^0.3.28",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 94 "jsesc": "^3.0.2"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 107 "@​​babel/compat-data": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 108 "@​​babel/helper-validator-option": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 109 "browserslist": "^4.24.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 110 "lru-cache": "^5.1.1",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 111 "semver": "^6.3.1"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 134 "@​​babel/traverse": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 135 "@​​babel/types": "^7.29.7"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 148 "@​​babel/helper-module-imports": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 149 "@​​babel/helper-validator-identifier": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 150 "@​​babel/traverse": "^7.29.7"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 156 "@​​babel/core": "^7.0.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 206 "@​​babel/template": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 207 "@​​babel/types": "^7.29.7"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 220 "@​​babel/types": "^7.29.8"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 236 "@​​babel/helper-plugin-utils": "^7.29.7"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 242 "@​​babel/core": "^7.0.0-0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 252 "@​​babel/helper-plugin-utils": "^7.29.7"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 258 "@​​babel/core": "^7.0.0-0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 268 "@​​babel/code-frame": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 269 "@​​babel/parser": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 270 "@​​babel/types": "^7.29.7"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 283 "@​​babel/code-frame": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 284 "@​​babel/generator": "^7.29.8",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 285 "@​​babel/helper-globals": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 286 "@​​babel/parser": "^7.29.8",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 287 "@​​babel/template": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 288 "@​​babel/types": "^7.29.8",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 289 "debug": "^4.3.1"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 302 "@​​babel/helper-string-parser": "^7.29.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 303 "@​​babel/helper-validator-identifier": "^7.29.7"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 758 "@​​jridgewell/sourcemap-codec": "^1.5.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 759 "@​​jridgewell/trace-mapping": "^0.3.24"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 769 "@​​jridgewell/gen-mapping": "^0.3.5",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 770 "@​​jridgewell/trace-mapping": "^0.3.24"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 797 "@​​jridgewell/resolve-uri": "^3.1.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 798 "@​​jridgewell/sourcemap-codec": "^1.4.14"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 815 "node": "^22.20 || ^24.12 || &gt;=25"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1182 "@​​babel/parser": "^7.20.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1183 "@​​babel/types": "^7.20.7",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1184 "@​​types/babel__generator": "*",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1185 "@​​types/babel__template": "*",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1186 "@​​types/babel__traverse": "*"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1196 "@​​babel/types": "^7.0.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1206 "@​​babel/parser": "^7.1.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1207 "@​​babel/types": "^7.0.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1217 "@​​babel/types": "^7.28.2"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1227 "@​​types/deep-eql": "*",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1228 "assertion-error": "^2.0.1"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1252 "undici-types": "~6.21.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1269 "@​​types/prop-types": "*",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1270 "csstype": "^3.2.2"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1280 "@​​types/react": "^18.0.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1290 "@​​babel/core": "^7.28.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1291 "@​​babel/plugin-transform-react-jsx-self": "^7.27.1",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1292 "@​​babel/plugin-transform-react-jsx-source": "^7.27.1",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1294 "@​​types/babel__core": "^7.20.5",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1295 "react-refresh": "^0.17.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1298 "node": "^14.18.0 || &gt;=16.0.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1301 "vite": "^4.2.0 || ^5.0.0 || ^6.0.0 || ^7.0.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1311 "@​​types/chai": "^5.2.2",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1314 "chai": "^5.2.0",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1315 "tinyrainbow": "^2.0.0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1329 "estree-walker": "^3.0.3",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1330 "magic-string": "^0.30.17"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1336 "msw": "^2.4.9",
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1337 "vite": "^5.0.0 || ^6.0.0 || ^7.0.0-0"
🟠 unpinned-version-indicator skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json 1355 "tinyrainbow": "^2.0.0"

121 additional finding(s) omitted from table.

Skipped non-text or missing files
  • skills/spa-sharepoint-power-automate/assets/spa-starter/public/icon-192.png
  • skills/spa-sharepoint-power-automate/assets/spa-starter/public/icon-512.png

This is an automated soft-gate report. Findings indicate review targets and do not block merge by themselves.

@github-actions github-actions Bot added new-submission PR adds at least one new contribution skills PR touches skills labels Sep 24, 2026
@github-actions

Copy link
Copy Markdown
Contributor

🔍 Vally Lint Results

✅ All checks passed

Scope Checked
Skills 1
Agents 0
Total 1
Severity Count
❌ Errors 0
⚠️ Warnings 0
ℹ️ Advisories 0

Summary

Level Finding
ℹ️ ✅ spa-sharepoint-power-automate (2/2 checks passed)
ℹ️ ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
ℹ️ ✓ spec-compliance: All spec checks passed.
ℹ️ ✓ [valid-refs] All file references across 1 skill(s) are valid.
ℹ️ ✓ valid-refs: All file references resolve to existing files within the skill directory.
ℹ️ 1 skill(s) linted, 1 passed
Full linter output
### Linting skills/spa-sharepoint-power-automate
✅ spa-sharepoint-power-automate (2/2 checks passed)
    ✓ [spec-compliance] All 1 skill(s) are spec-compliant.
        ✓ spec-compliance: All spec checks passed.
    ✓ [valid-refs] All file references across 1 skill(s) are valid.
        ✓ valid-refs: All file references resolve to existing files within the skill directory.

1 skill(s) linted, 1 passed

@exertion-solutions
exertion-solutions marked this pull request as draft September 24, 2026 16:07
The spa-sharepoint-power-automate skill is written mostly in Spanish and
codespell's English dictionary flags ordinary Spanish words (254 hits,
none elsewhere in the repository). Skip the skill directory the same way
the localized website docs are skipped.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The advertised browser pipeline has blocking CORS and security defects, and multiple operational claims are inaccurate.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 10 High severity · 4 Medium severity · 8 Low severity

Open (22)

And 2 more that still need to be addressed.

What changed in this PR

Adds a differentiated Power Automate–SharePoint troubleshooting skill, including operational guidance and a React/Vite reference SPA.

Changes:

  • Adds a skill router with Spanish references and selected English translations.
  • Adds a tested SPA/PWA starter, deployment workflow, and diagnostic scripts.
  • Regenerates the skills catalog.

However, the starter’s direct browser integration has blocking CORS, validation, retry, privacy, and accessibility issues, alongside several inaccurate documentation claims.

File Description
docs/​README.skills.md Registers the skill and assets.
skills/​spa-sharepoint-power-automate/​SKILL.md Defines skill routing and scope.
assets/​spa-starter/​.env.example Documents starter configuration.
assets/​spa-starter/​.github/​workflows/​deploy-pages.yml Deploys the SPA to Pages.
assets/​spa-starter/​.gitignore Excludes generated and local files.
assets/​spa-starter/​README.md Documents starter setup and usage.
assets/​spa-starter/​index.html Provides the SPA entry page.
assets/​spa-starter/​package-lock.json Locks starter dependencies.
assets/​spa-starter/​package.json Defines scripts and dependencies.
assets/​spa-starter/​public/​icon-192.png Provides a PWA icon.
assets/​spa-starter/​public/​icon-512.png Provides a large PWA icon.
assets/​spa-starter/​public/​manifest.json Defines the PWA manifest.
assets/​spa-starter/​public/​sw.js Implements offline asset caching.
assets/​spa-starter/​scripts/​cli.test.mjs Tests CLI utilities.
assets/​spa-starter/​scripts/​make-icons.mjs Generates starter icons.
assets/​spa-starter/​scripts/​sp-upload-test-file.mjs Tests SharePoint file uploads.
assets/​spa-starter/​scripts/​spfetch.mjs Implements SharePoint requests.
assets/​spa-starter/​scripts/​spfetch.test.mjs Tests SharePoint requests.
assets/​spa-starter/​scripts/​test-flow.mjs Exercises a flow endpoint.
assets/​spa-starter/​src/​App.test.tsx Tests the main form.
assets/​spa-starter/​src/​App.tsx Implements the submission form.
assets/​spa-starter/​src/​components/​SignaturePad.tsx Implements signature capture.
assets/​spa-starter/​src/​lib/​draftStorage.test.ts Tests draft persistence.
assets/​spa-starter/​src/​lib/​draftStorage.ts Persists form drafts.
assets/​spa-starter/​src/​lib/​formatters.test.ts Tests formatting helpers.
assets/​spa-starter/​src/​lib/​formatters.ts Formats identifiers and values.
assets/​spa-starter/​src/​lib/​imageUtils.test.ts Tests image processing.
assets/​spa-starter/​src/​lib/​imageUtils.ts Compresses submitted images.
assets/​spa-starter/​src/​lib/​registerSW.ts Registers service-worker updates.
assets/​spa-starter/​src/​lib/​signature.test.ts Tests signature conversion.
assets/​spa-starter/​src/​lib/​signature.ts Converts signature data.
assets/​spa-starter/​src/​lib/​uploadClient.test.ts Tests submission behavior.
assets/​spa-starter/​src/​lib/​uploadClient.ts Submits payloads to flows.
assets/​spa-starter/​src/​main.tsx Boots the React application.
assets/​spa-starter/​src/​styles.css Styles the starter interface.
assets/​spa-starter/​src/​vite-env.d.ts Declares Vite environment types.
assets/​spa-starter/​tsconfig.json Configures TypeScript compilation.
assets/​spa-starter/​vite.config.ts Configures Vite and tests.
references/​01-seguridad.md Covers public-endpoint security.
references/​02-spa-cliente.md Describes SPA implementation.
references/​03-contrato-y-flow.md Defines the flow contract.
references/​04-sharepoint.md Covers SharePoint integration.
references/​05-deploy-y-credenciales.md Documents deployment and credentials.
references/​06-operacion-y-errores.md Catalogs operational failures.
references/​07-pwa-operativa.md Covers PWA operation.
references/​08-flows-como-codigo.md Discusses flows as code.
references/​09-licencias-limites-trigger.md Documents trigger limits and licensing.
references/​10-resiliencia-y-errores-flow.md Covers resilient flow design.
references/​11-lecturas-sharepoint-a-escala.md Covers pagination and throttling.
references/​12-alm-soluciones-y-auditoria.md Describes ALM and auditing.
references/​13-decisiones-de-herramientas.md Compares supporting tools.
references/​14-soluciones-por-codigo-pac-dataverse.md Covers PAC and Dataverse automation.
references/​15-diseno-listas-sharepoint.md Guides SharePoint list design.
references/​16-flujos-disparados-por-archivos.md Covers file-triggered flows.
references/​17-gobernanza-del-tenant-dlp.md Documents tenant governance.
references/​18-correo-outlook.md Covers Outlook email behavior.
references/​19-reportes-power-bi-listas.md Covers Power BI reporting.
references/​20-permisos-graph-sites-selected.md Explains scoped Graph access.
references/​21-datos-personales.md Covers personal-data handling.
references/​22-kit-de-arranque.md Introduces the starter kit.
references/​en/​09-licencias-limites-trigger.md Translates licensing guidance.
references/​en/​10-resiliencia-y-errores-flow.md Translates resilience guidance.
references/​en/​11-lecturas-sharepoint-a-escala.md Translates scaling guidance.
references/​en/​14-soluciones-por-codigo-pac-dataverse.md Translates automation guidance.
references/​en/​17-gobernanza-del-tenant-dlp.md Translates governance guidance.
references/​en/​18-correo-outlook.md Translates Outlook guidance.
references/​en/​20-permisos-graph-sites-selected.md Translates Graph permission guidance.
Files not reviewed (1)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json: Generated file

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread skills/spa-sharepoint-power-automate/assets/spa-starter/src/lib/uploadClient.ts Outdated
Comment on lines +283 to +286
// application/json es OBLIGATORIO: con text/plain el flow ve un String y
// triggerBody()?['folio'] falla (skill §9). El flow maneja el preflight CORS.
const headers: Record<string, string> = { "Content-Type": "application/json" };
if (appKey) headers["x-app-key"] = appKey;
Comment thread skills/spa-sharepoint-power-automate/assets/spa-starter/src/lib/uploadClient.ts Outdated
Comment thread skills/spa-sharepoint-power-automate/references/03-contrato-y-flow.md Outdated
Comment thread skills/spa-sharepoint-power-automate/references/18-correo-outlook.md Outdated
Comment thread skills/spa-sharepoint-power-automate/references/19-reportes-power-bi-listas.md Outdated
Comment thread skills/spa-sharepoint-power-automate/references/22-kit-de-arranque.md Outdated
Comment thread skills/spa-sharepoint-power-automate/references/en/18-correo-outlook.md Outdated
@exertion-solutions
exertion-solutions marked this pull request as ready for review September 24, 2026 16:15
Copilot AI review requested due to automatic review settings September 24, 2026 16:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Security, correctness, accessibility, and platform-documentation issues remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 11 High severity · 4 Medium severity · 9 Low severity

Open (24)

And 4 more that still need to be addressed.

Files not reviewed (1)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json: Generated file
Previously missed (3)

In code that hasn't changed since last review

Medium severity Namespace caches by service-worker scope

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​public/​sw.js:14

Cache Storage is shared by every app on an origin, regardless of service-worker scope. GitHub Pages commonly hosts multiple repositories under one origin, so this generic prefix lets one starter app delete another app’s caches during activation. Namespace the prefix with self.registration.scope.

Medium severity Require a 200 response in the smoke test

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​test-flow.mjs:121

The smoke test exits successfully for 202 Accepted, but this skill defines an empty 202 as the symptom of a branch missing its required Response action. As written, the advertised end-to-end check cannot detect that configuration error. Require the expected 200 response here.

Low severity Mark external documentation skill as an optional dependency

skills/​spa-sharepoint-power-automate/​references/​12-alm-soluciones-y-auditoria.md:51

This says the external power-automate-documentation skill is installed, but installing this contribution does not install anything from microsoft/cat-agent-skills. Consumers may therefore be told to invoke a capability they do not have. Present it as an optional external dependency and include explicit installation/check instructions or a built-in fallback.

Comment thread skills/spa-sharepoint-power-automate/references/01-seguridad.md
Comment thread .codespellrc Outdated
…back

- Verified against Microsoft Learn: DirectQuery is not available for the SharePoint Online list connector; shared-mailbox Sent Items go to the sender by default; CORS of the HTTP trigger is marked NOT VERIFIED; Get items pagination wording clarified.
- Added mandatory flow-side validation, untrusted-input notes for email, and gateway-based abuse control.
- Removed the Microsoft first-party client-ID recipe and the Windows Credential Manager token-extraction technique from this distribution.
- description is now a single single-quoted scalar.
- Removed a reference to material that is not distributed and a pointer to a missing file.
- Narrowed the codespell skip to the Spanish documentation and the starter kit; the English translations are checked again.
- Adds the tested flows-as-code recipe (section 26.7).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 24, 2026 19:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The starter can falsely confirm implicit 202 responses, lose photos during service-worker updates, and overwrite existing test files.

Review effort: Balanced
Findings: 4 High severity · 4 Medium severity · 1 Low severity

Open (9)
Resolved since last review (15)
Files not reviewed (1)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json: Generated file
Previously missed (5)

In code that hasn't changed since last review

Medium severity Fail service worker installation on precache errors

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​public/​sw.js:23

allSettled lets a partially populated cache install successfully. The worker then activates and deletes the previous complete cache, so one transient precache failure can break offline startup after an update. Fail the install when any required shell resource cannot be cached so the previous worker/cache remains available.

Medium severity Prevent upload script from overwriting existing files

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​sp-upload-test-file.mjs:56

The script is advertised as creating a new file to exercise creation triggers, but overwrite=true silently replaces an existing file when --name is reused. That can destroy test-library content and will not exercise the intended “created” behavior. Use overwrite=false and fail clearly on a name collision; update the matching CLI test and documentation snippet as well.

Medium severity Disable file selection during photo compression

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​src/​App.tsx:249

The file input remains enabled while an earlier selection is still being compressed. A second selection can start concurrently; when the first operation finishes it clears compressing, enabling submission while the second selection is still pending, so those newly selected photos may be omitted from the submitted payload. Disable the input during compression.

Medium severity Use safe non-overwriting uploads for new-file tests

skills/​spa-sharepoint-power-automate/​references/​16-flujos-disparados-por-archivos.md:100

Although this section says the upload must create a new file, overwrite=true can replace an existing file and therefore exercise modification behavior—or destroy existing test content—instead. Use overwrite=false, matching the safety correction in the bundled upload script.

Low severity Correct misleading photo persistence guidance

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:661

This promises that photos remain in localStorage, but the bundled implementation explicitly persists only text and signature (App.tsx's FormState; draftStorage.ts also documents that photos are excluded). After a reload, users must reselect every photo, so this recovery guidance is misleading.

- Automatic retries: only 429; 500/503 only with serverIdempotent (flow must deduplicate by folio).
- Success requires 200 with the folio; an empty 202 or a 200 without it is reported as unconfirmed and the draft is kept.
- Drafts expire after 7 days and there is a delete-my-data button.
- Photos are always re-encoded through a canvas so EXIF (including GPS) is dropped.
- The service worker no longer reloads on update; it shows a banner.
- The signature has a typed-name alternative for keyboard and screen-reader users.
- 117 starter tests pass; npm run skill:validate passes.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 24, 2026 19:21
@exertion-solutions

Copy link
Copy Markdown
Author

Thanks for the detailed reviews. I pushed two updates (fe9b41e and a23c86f, skill version 1.4.4) that address the findings.

Content (checked against Microsoft Learn)

  • DirectQuery is not available for the SharePoint Online list connector (Import only); corrected.
  • Messages sent from a shared mailbox are saved in the sender's Sent Items unless Exchange copy settings are enabled; corrected.
  • The CORS behaviour of the HTTP trigger is now marked NOT VERIFIED (Learn does not document it). The guidance says to test in a browser against the real trigger and to use a proxy if the preflight fails.
  • Get items: Learn says items are "paginated by default", but only 100 are returned unless the Pagination setting is turned on; the wording now says so.
  • Added mandatory flow-side validation of the request body, a note that email fields and attachments from a public caller are untrusted, and gateway-based rate limiting / bot verification from the start.
  • Removed the Microsoft first-party client-ID recipe and the Windows Credential Manager token-extraction technique from this distribution; they are replaced by approved app registrations, Sites.Selected and gh.
  • description is a single single-quoted scalar; removed a reference to material that is not distributed and a pointer to a missing file.
  • .codespellrc: the skip is narrowed to the Spanish documentation and the starter kit (Spanish comments and UI strings); the English translations are spell-checked again.

Starter kit (117 tests, npm run skill:validate passes)

  • Automatic retries: only 429 retries on its own; 500/503 retry only with serverIdempotent: true, to be enabled only when the flow deduplicates by folio (the flow guide now documents the duplicate check).
  • Success requires 200 with the folio in the body; an empty 202 or a 200 without the folio is reported as unconfirmed and the draft is kept.
  • Drafts expire after 7 days and there is a "delete my data on this device" button.
  • Photos are always re-encoded through a canvas, so EXIF (including GPS) is dropped.
  • The service worker no longer reloads the page on update; it shows a banner so chosen photos are not lost.
  • The signature has a typed-name alternative for keyboard and screen-reader users.

Not yet verified: the typed-name signature and the update banner were checked by type-check and unit tests, not in a real browser or phone.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Retry safety, token handling, image privacy, offline caching, and several documentation inaccuracies remain unresolved.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 3 High severity · 3 Medium severity · 3 Low severity

Open (9)
Resolved since last review (6)
Files not reviewed (1)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json: Generated file
Previously missed (8)

In code that hasn't changed since last review

Medium severity Precache hashed assets for first-visit offline support

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​public/​sw.js:15

On the first visit, registration happens after the page's JS/CSS have already loaded, but the precache contains only HTML/manifest/icons. The newly installed worker therefore has no hashed /assets/ entries, so going offline after that first visit returns cached HTML whose JS/CSS are unavailable. Inject the Vite build assets into the precache (or use a generated service-worker manifest) so the advertised first-visit offline behavior works.

Medium severity Use ResourcePath APIs for special-character SharePoint names

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​sp-upload-test-file.mjs:56

This uses the legacy string-based GetFolderByServerRelativeUrl/Files/add APIs even though the surrounding guidance explicitly asks users to test names containing % and #. Microsoft documents the ResourcePath APIs for those names; the legacy form is ambiguous and can fail despite this helper's percent encoding. Use GetFolderByServerRelativePath(decodedurl=...) with Files/AddUsingPath(...) and update the URL tests/reference snippet.

Medium severity Honor Retry-After instead of retrying after a shorter cap

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​spfetch.mjs:70

Capping a server-provided Retry-After and retrying sooner does not respect the header and can extend SharePoint throttling or trigger blocking. If the requested delay exceeds the caller's maximum acceptable wait, stop and return/throw the throttling result rather than retrying after the shorter cap.

Medium severity Limit photo processing before decoding and compressing

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​src/​App.tsx:108

The 10-photo cap is applied only after every selected file has been decoded and compressed concurrently. Selecting many full-resolution photos can therefore allocate hundreds of megabytes on a phone for files that are ultimately discarded. Slice to the remaining slot count before processing and compress sequentially (or with tightly bounded concurrency).

Medium severity Combinar registros explícitamente por identificador en lugar de union()

skills/​spa-sharepoint-power-automate/​references/​10-resiliencia-y-errores-flow.md:83

union() no combina registros de dos arreglos por una clave. Solo elimina elementos que sean objetos completamente idénticos; dos registros con la misma clave y campos nulos/distintos permanecen separados, y el orden de argumentos no es una estrategia de merge soportada. Indicá una combinación explícita por el identificador del registro.

Medium severity Use ResourcePath APIs in the special-character upload snippet

skills/​spa-sharepoint-power-automate/​references/​16-flujos-disparados-por-archivos.md:100

This copied snippet has the same special-character problem as the bundled CLI: GetFolderByServerRelativeUrl/Files/add are legacy string-based APIs and are unreliable for the %/# filename cases that §28.3 asks users to test. Show the ResourcePath form (GetFolderByServerRelativePath(decodedurl=...) plus Files/AddUsingPath(...)) instead.

Medium severity Merge records explicitly by identifier instead of using union()

skills/​spa-sharepoint-power-automate/​references/​en/​10-resiliencia-y-errores-flow.md:83

This is not how union() merges arrays of records. Array elements are deduplicated only when the entire objects are equal; records sharing a lookup key but differing in null/non-null fields are both retained, and input order is not a supported key-based merge strategy. Recommend an explicit merge keyed by the record identifier instead of reversing the arguments.

Low severity Test the skill with representative GitHub Copilot scenarios

skills/​spa-sharepoint-power-automate/​SKILL.md:3

The PR checklist states that this new skill has not yet been exercised with GitHub Copilot. Static router/fact checks do not verify that Copilot selects the intended reference, follows the long cross-file instructions, or produces a usable result. Please run and document representative Copilot scenarios before presenting the skill as ready for installation.

Comment thread skills/spa-sharepoint-power-automate/assets/spa-starter/src/lib/imageUtils.ts Outdated
Comment on lines +107 to +111
* true = el flow DEDUPLICA por folio (busca el folio antes de crear el item). Solo entonces
* se reintentan solos los 500/503: si el primer POST creo el item y devolvio 5xx, reintentar
* sin esa garantia crea un duplicado (skill §22.4). Default false.
*/
serverIdempotent?: boolean;
Comment thread skills/spa-sharepoint-power-automate/assets/spa-starter/README.md Outdated
Comment thread skills/spa-sharepoint-power-automate/references/22-kit-de-arranque.md Outdated
Comment thread skills/spa-sharepoint-power-automate/references/22-kit-de-arranque.md Outdated
…ault

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 24, 2026 19:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved security, offline-cache, documentation-correctness, and validation issues could cause data loss or unsafe generated guidance.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 5 High severity · 2 Medium severity · 3 Low severity

Open (10)
Resolved since last review (1)
Files not reviewed (1)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json: Generated file
Previously missed (10)

In code that hasn't changed since last review

Medium severity Scope service-worker caches to the deployed application

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​public/​sw.js:14

This cache prefix is shared across every app on the same origin. Two GitHub Pages projects built from the starter can share a cache and delete each other's offline assets during activation. Derive the prefix from the service-worker scope so each deployed project owns only its caches.

Medium severity Fail installation when required precache resources are unavailable

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​public/​sw.js:23

Allowing every precache request to fail still activates this worker, after which activate deletes the previous cache. A transient failure can therefore replace a complete offline cache with an incomplete one. Required shell resources should fail installation so the previous worker/cache remains active.

Medium severity Use SharePoint ResourcePath APIs for special-character names

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​sp-upload-test-file.mjs:57

GetFolderByServerRelativeUrl is the legacy string API and has ambiguous handling for literal % and #; encoding them here does not make those names reliable. This conflicts with the stated special-character support. Use SharePoint's ResourcePath APIs (GetFolderByServerRelativePath/AddUsingPath) for these names and validate against a real tenant.

Medium severity Limit selected files before concurrent decoding

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​src/​App.tsx:108

The ten-photo limit is applied only after every selected file has been decoded concurrently. Selecting a large camera roll can therefore allocate and compress hundreds of full-resolution images before discarding all but ten, potentially freezing or crashing a mobile browser. Slice to the remaining slots before Promise.all.

Low severity Run and document representative GitHub Copilot scenarios

skills/​spa-sharepoint-power-automate/​SKILL.md:12

The contribution checklist says this skill has not been exercised with GitHub Copilot, but this line presents it as an end-to-end Copilot reference. The repository requires skills to be tested with Copilot; static evals and starter-kit unit tests do not validate routing or instruction-following. Please run and document representative Copilot scenarios before merging.

Low severity Document that failed submissions lose selected photos

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:661

This promises that photos survive in localStorage, but the bundled implementation explicitly persists only text and the signature (App.tsx:21, README.md:55). Closing or reloading after a failed submission therefore loses every selected photo, so the recovery guidance must state that limitation.

Low severity Avoid auto-reload that discards photos after service-worker updates

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:710

This auto-reload recipe conflicts with the bundled starter, which deliberately prompts before reloading because selected photos are not persisted. Following this section can reload immediately after a service-worker update and discard an in-progress user's photos; update the pattern and the later error-catalog entry to emit an update-ready event and let the user choose when to reload.

Low severity Correct misleading diagnosis of Apply to each save conflicts

skills/​spa-sharepoint-power-automate/​references/​03-contrato-y-flow.md:157

Apply to each is sequential by default, which this skill also states in references/10-resiliencia-y-errores-flow.md:43. A save conflict is caused when concurrency was enabled above 1, not by the default, so this diagnosis can make users change a safe loop unnecessarily.

Low severity Do not persist credentials in localStorage

skills/​spa-sharepoint-power-automate/​references/​07-pwa-operativa.md:193

Do not persist credentials in localStorage: any script running on the same origin can read them, and this section targets shared field devices. Persist only a non-sensitive item identifier or opaque server-issued handle; keep tokens/PINs out of browser storage.

Low severity Make power-automate-documentation an optional dependency

skills/​spa-sharepoint-power-automate/​references/​12-alm-soluciones-y-auditoria.md:51

This says power-automate-documentation is installed and auto-triggers, but that skill is not bundled in this repository. Consumers installing this skill will not necessarily have it, so the instruction can make Copilot depend on an unavailable external component. Describe it as optional and require checking availability/installing it before use.

Comment thread skills/spa-sharepoint-power-automate/assets/spa-starter/public/sw.js Outdated
SP_TOKEN only to SharePoint hosts; photos that cannot be re-encoded are skipped instead of uploading the original; precache of build assets; per-app draft keys; mandatory validation and duplicate check in the flow template; accurate retry and reload docs. 122 starter tests pass.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 24, 2026 20:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The direct browser integration fails CORS preflight, and the service-worker cache handling can disrupt offline operation.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 2 High severity · 3 Medium severity

Open (5)
Resolved since last review (8)
Files not reviewed (1)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json: Generated file
Previously missed (2)

In code that hasn't changed since last review

Low severity Automatic reload can discard photos during service worker updates

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:709

Automatically reloading on controllerchange contradicts the bundled starter's update banner and can discard selected photos, which are intentionally not persisted. Update this section to dispatch an update-ready event and let the user choose when to reload, matching assets/spa-starter/src/lib/registerSW.ts.

Low severity Manifest icon metadata falsely claims multiple bitmap sizes

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:749

A manifest icon's sizes value must describe the bitmap's actual dimensions; declaring one PNG as both 192×192 and 512×512 does not make it a valid 512×512 icon. This guidance would teach users to ship incorrect metadata. Require separate correctly sized files (as the bundled starter already does).

Comment thread skills/spa-sharepoint-power-automate/assets/spa-starter/public/sw.js Outdated
Comment thread skills/spa-sharepoint-power-automate/assets/spa-starter/public/sw.js Outdated
Comment thread skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/spfetch.mjs Outdated
Per-scope service worker cache prefix; atomic install so a partial precache cannot replace a working one; DoD SharePoint host in the token allowlist; the SPA guide no longer recommends automatic reloads and declares manifest icons correctly.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings September 24, 2026 21:03
…kill 1.4.7

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@exertion-solutions

Copy link
Copy Markdown
Author

Update (skill 1.4.7, commits 1c8a74d and 6e5a8a3).

CORS of the HTTP trigger. Several review comments say the trigger does not answer a browser preflight. I tested it instead of assuming: a browser-style OPTIONS (Origin: https://apu242007.github.io, Access-Control-Request-Method: POST, Access-Control-Request-Headers: content-type,x-app-key) against a *.environment.api.powerplatform.com trigger URL was answered 204 with:

Access-Control-Allow-Origin: *
Access-Control-Allow-Methods: GET,POST,PUT,DELETE,PATCH,HEAD
Access-Control-Allow-Headers: content-type,x-app-key
Access-Control-Max-Age: 7200

and the actual POST response also carried Access-Control-Allow-Origin: *. Caveats, which the skill now states: Microsoft does not document this; the test used the URL of a flow I had just deleted, so it shows the gateway's behaviour rather than a live run from a real page; only this URL format was tested (not older logic.azure.com URLs). The guidance is now "observed, not documented: test with your own trigger", and because the trigger accepts any origin, the docs stress rate limiting and bot verification in front of it for production.

Also fixed in this round: service-worker cache prefix per scope and atomic install, DoD SharePoint host in the SP_TOKEN allowlist, the SPA guide no longer recommends automatic reloads and declares manifest icons correctly.

Still open by design: manual "Retry" after an ambiguous outcome only avoids duplicates if the flow deduplicates by folio; the flow template now requires that (steps 3b and 3c), and the client keeps serverIdempotent off by default.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The canonical flow instructions conflict with the starter payload and omit mandatory validation and deduplication steps.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 3 High severity · 1 Medium severity · 2 Low severity

Open (6)
Resolved since last review (3)
Files not reviewed (1)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json: Generated file
Previously missed (8)

In code that hasn't changed since last review

Medium severity Invalidate pending signature image paints on clear and new strokes

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​src/​components/​SignaturePad.tsx:59

paintDataUrl() leaves an asynchronous Image.onload callback active. If the user clears the restored signature or starts a new stroke before that callback runs, the old image can be painted back afterward, leaving the canvas visibly signed while the parent value is null or overwriting the new stroke. Invalidate pending paints on clear and pointer-down (for example with a generation token checked inside onload).

Medium severity Handle missing checklist arrays before iteration

skills/​spa-sharepoint-power-automate/​references/​03-contrato-y-flow.md:456

The bundled starter payload has no checklist property, yet this canonical template iterates that property directly. Following the starter instructions therefore passes null to Apply to each, so the run fails after the early 200 response and the email is skipped. Default the missing property to an empty array (or add checklist: [] to the starter contract).

Medium severity Align attachment contract with starter payload contents

skills/​spa-sharepoint-power-automate/​references/​03-contrato-y-flow.md:477

This attachment contract does not match the bundled starter: buildPayload() puts the signature at attachments[0], followed by photos, and §34 explicitly says the starter does not generate a PDF. A user combining the advertised starter and canonical flow will therefore attach the signature image as the business PDF. Make PDF attachment conditional, or align the starter payload ordering and content.

Low severity Clarify that parallel processing requires enabled concurrency

skills/​spa-sharepoint-power-automate/​references/​03-contrato-y-flow.md:157

Apply to each runs sequentially by default; it only runs in parallel after Concurrency Control is enabled above 1. Calling parallelism the default gives users the wrong diagnosis for a Save Conflict. Describe this as the cause only when concurrency was enabled, while retaining the degree-1 requirement for same-item writes.

Low severity Resolve conflicting REST POST setup instructions

skills/​spa-sharepoint-power-automate/​references/​06-operacion-y-errores.md:89

This instruction contradicts §10 (references/04-sharepoint.md:6-10), which explicitly corrected the old “skip the script” rule and says to attempt the REST POST once before falling back to the UI. Keeping both makes the router produce different setup procedures depending on which reference Copilot opens.

Low severity Use the SharePoint list delta endpoint for generic lists

skills/​spa-sharepoint-power-automate/​references/​11-lecturas-sharepoint-a-escala.md:71

This endpoint tracks drive items, so it only covers document libraries. For the generic SharePoint lists discussed in this section, Graph's delta endpoint is /sites/{siteId}/lists/{listId}/items/delta; directing users to the drive endpoint will miss their list changes.

Low severity Mark power-automate-documentation as an optional dependency

skills/​spa-sharepoint-power-automate/​references/​12-alm-soluciones-y-auditoria.md:51

power-automate-documentation is not bundled with this contribution, so it will not be installed—or auto-triggered—for users who install this skill. Describing the author's private environment as current state makes Copilot rely on an unavailable dependency. Mark it as an optional external skill and require checking/installing it separately before invoking it.

Low severity Use the SharePoint list delta endpoint for generic lists

skills/​spa-sharepoint-power-automate/​references/​en/​11-lecturas-sharepoint-a-escala.md:71

This endpoint tracks drive items, so it only covers document libraries. For the generic SharePoint lists discussed in this section, Graph's delta endpoint is /sites/{siteId}/lists/{listId}/items/delta; directing users to the drive endpoint will miss their list changes.

Comment thread skills/spa-sharepoint-power-automate/references/02-spa-cliente.md Outdated
Comment thread skills/spa-sharepoint-power-automate/references/06-operacion-y-errores.md Outdated
Copilot AI review requested due to automatic review settings September 24, 2026 21:10
exertion-solutions and others added 2 commits September 24, 2026 18:12
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…reload guidance, signature pad stale paints (skill 1.4.9)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Retry safety, smoke-test validation, signature handling, CLI output limits, and documentation accuracy have unresolved issues.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
Resolved since last review (4)
Files not reviewed (1)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json: Generated file
Previously missed (8)

In code that hasn't changed since last review

Medium severity Avoid retrying non-idempotent POST requests after 503

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​spfetch.mjs:72

spFetch retries every 503 regardless of the HTTP method. For a POST, the server can commit the write and still return/lose a 503 response, so replaying it can create duplicate list items—the same ambiguity that uploadClient guards with serverIdempotent. Restrict automatic 503 retries to idempotent methods or require an explicit idempotency/deduplication option for writes, and update the tests and usage docs accordingly.

Medium severity Reject invalid --max-chars values to enforce output limits

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​spfetch.mjs:154

--max-chars is not validated. With NaN the truncation comparison is always false, and with a negative number slice(0, -1) emits almost the entire body, defeating this CLI's output cap and potentially exposing a large or sensitive SharePoint response. Reject invalid values before making the request.

Medium severity Validate --max-chars before making the request

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​test-flow.mjs:84

--max-chars is not validated. A typo such as --max-chars nope makes the comparison against NaN false and prints the complete response body; a negative value prints nearly all of it. Since flow responses can contain operational or personal data, reject non-integer or negative values just as this code already rejects an invalid timeout.

Medium severity Require exact 200 response and matching folio in smoke test

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​test-flow.mjs:121

This smoke test treats every 2xx response as success, so Power Automate's silent 202 for a branch without a Response action passes even though the starter client deliberately classifies it as unconfirmed. Require the documented contract (200 plus the same folio) before returning exit code 0; otherwise this script misses the exact flow wiring failure it is intended to catch.

Medium severity Prevent stale image loads from repainting deleted signatures

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​src/​components/​SignaturePad.tsx:59

Image loading is asynchronous, but this callback does not verify that the signature is still current. If a restored/typed signature is still decoding when the user clicks “Borrar firma,” its later onload repaints the supposedly deleted signature; it can likewise overwrite a newly drawn stroke. Track/cancel stale paint requests (for example with a generation ref incremented by clear/new input) before drawing.

Low severity Clarify that failed submissions do not persist selected photos

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:661

This says the failed submission's photos remain in localStorage, but the starter explicitly persists only text and signature (App.tsx:20, draftStorage.ts:14); photos survive only while the current page remains open. This can make users believe it is safe to close/reload after a failure and then lose all selected photos. Document that limitation here.

Low severity Document required Sites.FullControl.All Graph permission

skills/​spa-sharepoint-power-automate/​references/​20-permisos-graph-sites-selected.md:23

An administrator role by itself is not sufficient authorization for this Graph call: the access token used for POST /sites/{siteId}/permissions must carry the required Sites.FullControl.All permission. As written, a global administrator can follow this step and still receive 403, while the actual token requirement is obscured. State the required Graph permission (and the applicable admin role/consent separately).

Low severity Document required Sites.FullControl.All Graph permission

skills/​spa-sharepoint-power-automate/​references/​en/​20-permisos-graph-sites-selected.md:23

An administrator role by itself is not sufficient authorization for this Graph call: the access token used for POST /sites/{siteId}/permissions must carry the required Sites.FullControl.All permission. As written, a global administrator can follow this step and still receive 403, while the actual token requirement is obscured. State the required Graph permission (and the applicable admin role/consent separately).

Copilot AI review requested due to automatic review settings September 24, 2026 21:18
SKILL.md and the sections where techniques were left out now link to the author's repository.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Security-sensitive guidance and starter defects can expose personal data, duplicate mutations, or misstate platform behavior.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 2 High severity · 1 Medium severity

Open (3)
Files not reviewed (1)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/package-lock.json: Generated file
Previously missed (13)

In code that hasn't changed since last review

Medium severity Automatic retries can duplicate non-idempotent mutations

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​scripts/​spfetch.mjs:72

This retries every 429/503 regardless of method, while the CLI accepts arbitrary methods and bodies. Automatically replaying POST/PATCH requests can duplicate a mutation when the server committed it before returning a transient error; restrict automatic retries to idempotent methods unless callers explicitly opt in with an idempotency guarantee.

Medium severity Overlapping file processing can re-enable submission prematurely

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​src/​App.tsx:278

The picker remains enabled while an earlier batch is being compressed, so two handleFiles calls can overlap. The first completion can clear compressing while the second is still running, re-enabling submission before every selected photo has been processed.

Medium severity startOver leaves the typed signer name visible

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​src/​App.tsx:311

SignaturePad owns the typed signer name in internal state, so startOver() clears the parent draft but leaves that personal data visible in the mounted child after “Borrar mis datos.” Remount it when a new folio is created so all signature state is cleared.

Medium severity Lowercase base reference causes a ReferenceError

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:28

This snippet defines BASE above but interpolates lowercase base, which is undefined. Copying it throws a ReferenceError instead of fetching the asset.

Medium severity Unsupported formats can preserve and upload metadata

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:363

Returning the original blob for unsupported formats defeats the section's privacy guarantee: the original can retain EXIF/GPS metadata and later be uploaded. Reject unsupported input instead of passing it through unchanged.

This issue also appears on line 379 of the same file.

Medium severity DNI data persists indefinitely in localStorage

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:651

This saves a profile that can contain a DNI indefinitely in localStorage; deletion is only manual. On shared or lost devices that retains identity data beyond the stated privacy/minimization model, so add an expiry and avoid storing DNI by default (or scope it to an authenticated user).

Low severity Photo removal buttons need unique accessible names

skills/​spa-sharepoint-power-automate/​assets/​spa-starter/​src/​App.tsx:298

Every photo-removal button has the same accessible name, “Quitar,” so screen-reader button navigation cannot identify which photo will be removed. Include the photo number or file name in an aria-label.

Low severity Synchronous response limit is incorrectly stated as 110 seconds

skills/​spa-sharepoint-power-automate/​references/​02-spa-cliente.md:358

The platform's documented synchronous response limit is 120 seconds, not approximately 110 seconds. Keeping the incorrect value here makes this otherwise copyable guidance disagree with the limit reference.

Low severity Use the documented 120-second synchronous response limit

skills/​spa-sharepoint-power-automate/​references/​03-contrato-y-flow.md:53

The documented synchronous HTTP response limit is 120 seconds, not approximately 110 seconds; this also conflicts with the 120-second value used elsewhere in this skill. Use the platform limit consistently.

Low severity Anonymous triggers can still write validated Person values

skills/​spa-sharepoint-power-automate/​references/​03-contrato-y-flow.md:115

An anonymous trigger does not prevent the authenticated SharePoint connector from populating a Person column. What is unavailable is trustworthy caller identity; a validated tenant email/claims value can still be written, so this rule would make users unnecessarily redesign their list.

Low severity Sequential Apply to each does not explain concurrent conflicts

skills/​spa-sharepoint-power-automate/​references/​03-contrato-y-flow.md:157

Apply to each is sequential by default; it only runs iterations in parallel when concurrency control is explicitly enabled. This diagnosis can send users looking for a default that does not exist and misses other concurrent flow runs or writers that can cause the same conflict.

Low severity Incorrect 110-second timeout causes inconsistent guidance

skills/​spa-sharepoint-power-automate/​references/​03-contrato-y-flow.md:424

The platform's documented synchronous response limit is 120 seconds, so calling this a 110-second gateway timeout makes the troubleshooting guidance internally inconsistent.

Low severity Troubleshooting row uses an incorrect 110-second limit

skills/​spa-sharepoint-power-automate/​references/​06-operacion-y-errores.md:131

This troubleshooting row should use the documented 120-second synchronous response limit. The current 110-second value conflicts with the skill's own limits reference and can mislead timing investigations.

Comment on lines +253 to +255
El endpoint es público y sin login (§1). Lo que cambia respecto de un formulario de alta es
que acá se registran **hechos con consecuencia económica**: tiempos facturables, entregas,
horas extra. Cuatro reglas, ninguna opcional:
Copilot AI review requested due to automatic review settings September 24, 2026 21:27

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

github-actions Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

🚦 Submission status: ⏳ Awaiting automation

Risk tier: merge-risk:high — Privileged execution, automation, or review-policy change
Required to merge: passing submission-gate checks plus 2 approvals from reviewers with write access, including a maintainer with admin or maintain permission.

Why this tier
  • skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/cli.test.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/make-icons.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/sp-upload-test-file.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/spfetch.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/spfetch.test.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
  • skills/spa-sharepoint-power-automate/assets/spa-starter/scripts/test-flow.mjs is a high-risk path (automation, scripts, MCP config, hooks, or review policy)
  • Spawns processes or evaluates code in skills/spa-sharepoint-power-automate/references/08-flows-como-codigo.md

Automated checks

Check Status Details
Line endings ✅ Passed Passed · logs
Spelling ✅ Passed Passed · logs
Generated README consistency ✅ Passed Passed · logs
Skill validation ⏳ Pending Waiting for the check to start
Skill lint (vally) ✅ Passed Passed · logs
Risk scan ✅ Passed Passed · logs
Contributor reputation ✅ Passed Passed · logs
Duplicate resource scan ✅ Passed Passed · logs
PR quality signal ⏭️ Skipped Skipped by its workflow · logs
Contributor risk signal 🔧 Infrastructure failure The contributor check succeeded but its result artifact was missing, unreadable, or for another commit · logs

Action needed

  • 🔧 Contributor risk signal hit an automation problem that is not caused by your contribution. Comment /rerun-checks to retry; maintainers are notified if it keeps failing.

Review

  • Approvals: 0/2
  • Assigned reviewer: aaronpowell
  • Review target date: not set
  • Still needed: 2 more approval(s); an approval from a maintainer with admin or maintain permission
  • The core-maintainers pool is not staffed yet; an approver with admin or maintain permission is required instead.

Commands

Command Who What it does
/rerun-checks PR author, maintainers Re-runs failed or incomplete checks and re-evaluates this gate
/request-review PR author, maintainers Asks the review rotation to assign a reviewer (adds needs-reviewer)

Updated for c4aa911 · This comment is maintained automatically — see submission gate docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

awaiting-automation merge-risk:high new-submission PR adds at least one new contribution skills PR touches skills

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants