canvas-app
Creates or edits a Power Apps Canvas App through the Canvas Authoring MCP coauthoring session. Handles new app generation, direct targeted edits, complex multi-screen changes, responsive layout, per-screen self-QA, and compile-error convergence.
Install / Use
npx skills add microsoft/power-platform-skills --skill canvas-appInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
DesignSupported Platforms
Our assessment of canvas-app
canvas-app scores 87/100 on our quality scale, 126th of 266 Design skills we index (top 48%).
Its SKILL.md is 29 KB long, split into 5 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
It has 919 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 9 days ago, so canvas-app is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
Safety scan
No issues foundOur scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands.
Automated pattern scan on 2026-10-04. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.
canvas-app compared with similar skills
All 4 of these similar skills score higher than canvas-app; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| canvas-app (this skill)by microsoft | 87 | 919 | 9d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 89.8k | 18d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.4k | today | CLAUDE.md |
| CowAgentby zhayujie | 100 | 47.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.5k | today | MCP Server |
Frequently asked questions
- How do I install canvas-app?
- Run
npx skills add microsoft/power-platform-skills --skill canvas-app. The install tabs above show the steps for each supported agent. - Which AI agents does canvas-app work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is canvas-app safe to use?
- Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is canvas-app still maintained?
- The repository was last updated 9 days ago, so canvas-app is actively maintained.
Skill content
View source on GitHubname: canvas-app version: 3.1.0 description: Creates or edits a Power Apps Canvas App through the Canvas Authoring MCP coauthoring session. Handles new app generation, direct targeted edits, complex multi-screen changes, responsive layout, per-screen self-QA, and compile-error convergence. Trigger on requests to create, build, generate, modify, update, change, fix, or edit a Canvas App or .pa.yaml files. author: Microsoft Corporation user-invocable: true allowed-tools: Read, Write, Edit, apply_patch, Bash, AskUserQuestion, Task, TaskCreate, TaskUpdate, TaskList, EnterPlanMode, ExitPlanMode, mcp__canvas-authoring__sync_canvas, mcp__canvas-authoring__compile_canvas, mcp__canvas-authoring__list_controls, mcp__canvas-authoring__describe_control, mcp__canvas-authoring__list_apis, mcp__canvas-authoring__describe_api, mcp__canvas-authoring__list_data_sources, mcp__canvas-authoring__get_data_source_schema
Create or Edit a Canvas App
Create or edit a Power Apps canvas app for:
$ARGUMENTS
Establish the Workspace
Canvas Authoring tools operate on a local directory containing the app YAML.
- Treat
${PLUGIN_ROOT}as immutable runtime provenance. Never derive it from the current directory, app workspace, repository root, or a sibling worktree. - Read
${PLUGIN_ROOT}/references/QAChecks.mdand requireQACHK-SHARED-SOURCE-DERIVATION. If the check fails, stop with the observed path; do not mix prompt generations. - Reuse the current directory when it already contains
App.pa.yamland every existing file in that directory is a.pa.yamlfile. - Otherwise, reuse the single immediate child directory containing
App.pa.yaml, when exactly one exists and every existing file in it is a.pa.yamlfile. - Otherwise, derive a short kebab-case folder name from the app name or requirements,
create a new empty directory with
Bash, and resolve its absolute path. If that name already exists and contains non-YAML files, choose a fresh suffixed name rather than synchronizing into it. - Call
sync_canvaswith that absolute working directory before reading or editing app files. The directory must be dedicated to this app and contain no non-.pa.yamlfiles when synchronization starts; never pass the repository root or${PLUGIN_ROOT}. Do not callsync_canvasagainst the working directory again after planning or acceptance documents have been created there. Do not proceed if the initial sync fails.
Always use absolute paths for app files.
Route the Request
Inspect the synced .pa.yaml files before choosing a workflow. A blank app normally contains
App.pa.yaml, Screen1.pa.yaml, and _EditorState.pa.yaml.
Treat the app as empty when it has no screens with meaningful leaf controls. Containers without leaf controls do not make the app non-empty.
- Empty app: read
${PLUGIN_ROOT}/references/CreateWorkflow.mdand follow it. - Existing app: read
${PLUGIN_ROOT}/references/EditWorkflow.mdand follow it.
Do not load both workflow documents.
Planned Build Handoff
CREATE and complex EDIT workflows return here after the planner finishes.
- Read the orchestrator-authored
[working directory]/canvas-app-requirements.mdand[working directory]/canvas-app-plan.mdreturned by the planner. The requirements artifact must already exist before planner delegation, use contract version 1, preserve the original request, identify the target device, and assign stable requirement, action, scenario, and specialized-contract mappings. Do not let the planner create, rewrite, or replace this upstream artifact. - Verify
## Original Request Capability Inventorywas captured from the original request before planner reduction. Every stable key must appear in## Requirement Coverageand map to existing Action Contract key(s), named observer(s), and Functional Test Matrix scenario key(s). Reject dropped clauses and unknown mappings; do not add universal CRUD absent from the request. - Verify its
## Requirement Coveragetable maps every concrete requested noun and interaction to a visible affordance. Any approximation must be explicit and must not use UI copy that claims the unavailable interaction is exact. - When the app contains record cards, rows, lists, or details, verify its
## Required Record Fieldstable has one stable key for the canonical identity and every field the requirements say users must see. Reject a time-only, identity-only, or action-only surface when additional title, person, time, description, status, or other values are requested. - Verify its
## Action Contractstable:- Every requested or approved action has its own row and reachable entry point.
- Create, edit, delete, search, filter, approve, reject, period, and export behaviors are not collapsed into vague combined rows.
- When review distinguishes approved and rejected outcomes, Approve and Reject/Decline have separate contracts owned by the same eligible record surface.
- Opposing transitions such as Receive/Issue, Increase/Decrease, Credit/Debit, Allocate/Release, Check-in/Check-out, and Enable/Disable have separate contracts even when one shared form implements both.
- When opposing actions use a shared-operation flow — directional selector events
commit operation state and a distinct guarded event consumes that state to mutate —
each selector is selection-only and that distinct event is the single mutation entry
point, regardless of control name or label. Both contracts name that same mutation
event and operation state. A selector that calls
Patch,SubmitForm,Collect,Remove,RemoveIf,UpdateIf, or a connector mutation is invalid. Separate direct-action controls remain valid when no distinct shared mutation event exists and each action has its own selected-ID and amount eligibility gates. Their control identity commits direction, so they need no shared operation variable/reset. - Every mutation names an observable bound result, not only a confirmation message.
- Every mutation declares a write set and receipt proof set. For create/edit, reject the plan when any user-entered or user-selected write-set field is absent from the proof set.
- Every mutation has an additive lifecycle row naming its receipt, canonical source, requested destination, same stable ID, and exact synchronization/focus behavior when the destination differs or contains multiple records.
- Every mutation has a Changed/Preserved field ledger. Changed rows match handler writes and receipt proofs one-for-one; Preserved rows retain canonical pre-state and name post-state evidence.
- Conditional stable-ID continuation exists only when create feeds a later edit, delete, relationship, approval, or transition. It binds that action to the returned create ID and clears continuation state on downstream completion or cancellation.
- Every plan-declared state-driven UI surface names the surface control and its exact
state predicate. Recognize either the dedicated table or an exact
Surface.Visible=state predicateAction Contract observer. Do not add rows for always-visible surfaces, child-only visibility, navigation-based disclosure, or visibility not declared by the plan. - Supporting setup actions exist when required to exercise an explicitly requested lifecycle, relationship, comparison, or ranking.
- Role-scoped management of all primary records includes separate visible select/edit/save and remove/cancel paths, not only review or status controls.
- Create/edit contracts define required inputs, directly selectable finite choices, stable identity, edit prepopulation, cancel/reset behavior, and post-save evidence.
- Every row names a precondition, source and stable identity, exact transition and postcondition, observer reading that source, and visible evidence.
- Verify its
## Functional Test Matrix:- Every Action Contract has at least one deterministic Given/When/Then success row.
- Every required invalid, blocked, empty, clear/reset, or boundary path has a row.
- Every direction of an opposing pair has its own concrete scenario with explicit old value/state, selected operation, amount when applicable, and expected new value/state.
- Every
Thennames a source postcondition and an evidence surface that reads it. - Local/mock scenarios use concrete seeded IDs and values. Filter scenarios include at least two matching records and one non-matching record.
- EDIT scenarios cover existing behavior touched by changed sources, fields, controls, or observer formulas.
- When a continuation contract is present, scenarios cover the returned-ID-bound downstream completion and non-mutating cancellation paths, including continuation-state clear.
- When the plan contains an opposing directional pair, require
## Directional Mutation Evidencebefore dispatch. It must state a nullable selected-ID state with blank reset and row assignment, the actual operation state with an entry/successBlank()reset event, representable blank/non-positive amount bindings, a disabled invalid submission gate, exact final formulas for both directions, a canonical-source observer, and receipt bindings for operation, old value, amount, expected value, and actual persisted value. For a shared-operation flow, the plan must also identify each selection-only binding, the common guarded mutation event, and their common operation state. - Verify every responsive or unknown-device screen has a
## Viewport Containment Contractsrow naming one sole top-level AutoLayout root with exactWidth: =Parent.WidthandHeight: =Parent.Height. All visible and conditional surfaces must be nested below it. - When requested behavior orders or compares time-of-day values, require
## Temporal Ordering Contracts. Sort typed Date/Time fields directly, or require validated input normalization to a zero-padded 24-hourHH:mmsort key with explicit invalid/blank behavior. Reject direct sorting of 12-hour, non-padded, or mixed display strings. - Verify its
## Dispatchtable:- Every row has
Action,Screen,Target File,YAML Key,Name Prefix, andScreen Brief. - CREATE rows use
Create; EDIT rows useModifyorCreate. - Target files and screen briefs are absolute paths under
[working directory]. - No two rows target the same file.
- No two rows share a
Name Prefix. - In CREATE mode the first row targets
[working directory]/Screen1.pa.yamlwith YAML keyScreen1. ## Editor State Changesexists and contains exact final order lists orNone.
- Every row has
- Confirm
[working directory]/canvas-app-shared.mdand every dispatch row'sScreen Briefexists. Verify each brief's assignment matches its dispatch row and includes every Action Contract owned by that screen under## Required Actionsand every scenario it exercises under## Functional Test Scenarios. It also includes every## Required Record Fieldsrow owned by that screen with an exact bound control, formula, hierarchy, visibility rule, and layout budget. - Before dispatch, read every brief and reject it when:
- a used control lacks its exact creation keywords, supported input-property names, or
the full
Enum name:and compile-ready enum literal required by discovery; - a Required Action is only an identifier or summary instead of its complete precondition, event, source/stable identity, postcondition, observer, and evidence;
- a Functional Test Scenario is only an identifier instead of complete Given/When/Then text, boundary conditions, and expected evidence; or
- it contains an unreso
- a used control lacks its exact creation keywords, supported input-property names, or
the full
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
89.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.4kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
CowAgent
47.2kOpen-source personal AI assistant & Agent Harness. Plans tasks, runs tools and skills, self-evolves with memory and knowledge. Multi-agent, multi-model, multi-channel. Lightweight, extensible, one-line install.
Scrapling
85.5k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
