migrate-webapi-selectall
Reviews and migrates deprecated wildcard (*) values in Power Pages Web API fields site settings to least-privilege explicit Dataverse columns
Install / Use
npx skills add microsoft/power-platform-skills --skill migrate-webapi-selectallInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of migrate-webapi-selectall
migrate-webapi-selectall scores 85/100 on our quality scale, 2689th of 4,600 Development & Engineering skills we index.
Its SKILL.md is 21 KB long, well organised into 15 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
It has 919 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 12 days ago, so migrate-webapi-selectall is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
migrate-webapi-selectall compared with similar skills
All 4 of these similar skills score higher than migrate-webapi-selectall; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| migrate-webapi-selectall (this skill)by microsoft | 85 | 919 | 12d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 92.4k | 21d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.5k | today | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 45.1k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.8k | 6d ago | CLAUDE.md |
Frequently asked questions
- How do I install migrate-webapi-selectall?
- Run
npx skills add microsoft/power-platform-skills --skill migrate-webapi-selectall. The install tabs above show the steps for each supported agent. - Which AI agents does migrate-webapi-selectall work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is migrate-webapi-selectall safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is migrate-webapi-selectall still maintained?
- The repository was last updated 12 days ago, so migrate-webapi-selectall is actively maintained.
Skill content
View source on GitHubname: migrate-webapi-selectall description: >- Reviews and migrates deprecated wildcard (*) values in Power Pages Web API fields site settings to least-privilege explicit Dataverse columns. Use whenever a user mentions Web API wildcard or select-all remediation, fields settings containing *, data-exposure review, wildcard deprecation readiness, or Web API failures after wildcard retirement. Applies to both traditional sites using HTML, CSS, JavaScript, Liquid, and downloaded YAML, and SPA sites using React, Vue, Angular, Astro, or TypeScript. The agent must inspect every source Web API call and consumer, report exact fixes for every wildcard, report every already-explicit configuration, apply approved edits, and verify no wildcard remains. user-invocable: true argument-hint: Optional Power Pages project path allowed-tools: Read, Write, Edit, Bash, Grep, Glob, AskUserQuestion, TaskCreate, TaskUpdate, TaskList model: opus
Plugin check: Run
node "${PLUGIN_ROOT}/scripts/check-version.js"— if it outputs a message, show it to the user before proceeding.
Migrate Power Pages Web API Wildcards
Replace every deprecated Webapi/<table>/fields = * value with the smallest
explicit column set proven by the site's actual Web API behavior.
The LLM owns source discovery, call-chain reasoning, field decisions, report writing, and edits. Use the bundled script only to retrieve authoritative Dataverse table schema; it must not decide which columns the code needs.
Support both:
- traditional sites with HTML, JavaScript, Liquid, web templates, and aggregate YAML;
- SPA sites with React, Vue, Angular, Astro, TypeScript, downloaded deployment YAML, or mixed custom JavaScript.
Initial request: $ARGUMENTS
Non-negotiable rules
- Review every discovered source table Web API call, including shared wrappers, dynamic builders, and response consumers.
- Review every configuration scope and deployment-profile copy.
- Map request
EntitySetNamevalues to setting logical names using table schema. Never singularize, pluralize, or guess. - Treat
*as unsupported for reads, writes, aggregates, FetchXML, files, and images. - Give every wildcard an exact proposed replacement before editing anything.
- Report every already-explicit fields setting, including missing and potentially unnecessary columns.
- Never apply a partial wildcard plan. Resolve all wildcards and call-site rows first.
- Keep reports free of absolute local paths, tokens, URLs, data values, filter literals, request bodies, response bodies, and source snippets, and build them only by rendering the bundled template with the bundled script.
- Preserve unrelated YAML structure and values.
- Verify with a fresh discovery pass, not remembered inventory.
- Leave only the rendered report and its icon in the migration output directory.
- Never download or upload site content until the user has explicitly confirmed the environment, website, site type, data model, and deployment profile. Neither transfer can be reverted.
- Run smoke tests only after explicit approval, and never issue POST, PATCH, PUT, or DELETE Web API calls against a deployed site. Testing a write destroys real record data.
Read references/column-analysis.md before analyzing calls. Read references/configuration-and-reporting.md before inventorying settings or writing the report. Read references/site-transfer.md before any download or upload.
Phase 1: Prepare
Goal: Resolve the project, confirm the site, and protect existing work.
- Create all seven tasks from Progress tracking.
- Resolve
PROJECT_ROOTfrom$ARGUMENTSor the current directory. - Detect site markers independently:
powerpages.config.jsonindicates an SPA site;- root
website.yml, rootsitesetting.yml, or.powerpages-site/indicates downloaded declarative artifacts; - when both appear, scan both layouts.
- Read
.solution-manifest.jsonwhen present. This migration changes existing settings; do not create or select another solution. - Inspect git status. Never discard, hide, or include unrelated user changes.
- Run
node --version. - Confirm
assets/migration-report-template.htmlandscripts/render-migration-report.jsare readable, and stop if either is missing. - Read references/site-transfer.md, then
confirm the environment, website name and
WebSiteId, site type, data model, deployment profile, and target path with the user. Check each againstpac auth who,pac env who, andpac pages list, and stop on any mismatch. Never infer one from a folder name or an active default.
Analyzing the wrong site produces confident, wrong fixes, so settle identity
before reading any setting. Download only when the user wants a fresh copy or
PROJECT_ROOT holds no site content; downloading replaces local files and
cannot be reverted.
🚦 Gate (consent · migrate-webapi-selectall:1.download-site): Approve the download only after displaying the confirmed environment, website name and ID, site type, data model, target path, and the exact command. Canceling leaves local content untouched and continues against the existing copy.
Use AskUserQuestion: Download the confirmed site or Use the local copy.
Repeat step 3 after any download.
Output: Project root, site layouts, solution context, git state, confirmed site identity, and a downloaded copy when approved.
Phase 2: Build the complete inventory
Goal: Find every configuration and candidate source Web API call before reasoning about columns.
2.1 Inventory configuration scopes
Use Glob, Grep, and Read to inspect:
- every
sitesetting.yml; - every
*.sitesetting.yml; .powerpages-site/site-settings/;- deployment-profile and environment-specific copies.
Record every Webapi/<table>/fields and Webapi/<table>/enabled entry with
its relative file, line, scope, key style, and current value. Classify fields
settings as:
wildcard;explicit;missingfor an enabled table;duplicateonly within the same configuration scope.
Do not treat identical settings in different deployment profiles as
duplicates. Record every profile name and which settings it overrides. Never
assume the default profile is the intended deployment profile.
Query Dataverse once per unique table, never once per configuration.
2.2 Inventory source calls
Analyze only authoritative, editable source files. Never inspect compiled or generated code.
For SPA sites:
- Read
powerpages.config.json,package.json, and present framework or bundler configuration before searching calls. - Treat
compiledPathand every configured build-output directory as a hard exclusion. - Exclude
.powerpages-site/web-files/,node_modules/, coverage and cache directories, source maps, minified bundles, framework output directories, and content-hashed assets matching<entry-name>-<content-hash>.<extension>. - Use
.powerpages-site/site-settings/only for configuration inventory, never for source analysis. - Search editable roots such as configured source directories and framework application directories.
For traditional sites, search editable JavaScript, Liquid, web templates, web files, and other authored source. Do not exclude an authored traditional web file merely because it is deployed as a web file.
Search source extensions including .js, .jsx, .ts, .tsx, .vue,
.html, .htm, .liquid, .aspx, .ascx, .cshtml, and XML web
templates. If a call exists only in compiled, minified, generated, or
content-hashed output, record a missing-source blocker and stop the
migration. Do not infer columns from that output.
Search for:
/_api/, encoded variants, split URL fragments, and API base constants;fetch, Axios,XMLHttpRequest, jQuery AJAX,webapi.safeAjax,shell.ajaxSafePost, and custom request wrappers;- entity-set constants, query builders, FetchXML builders, and body builders;
- callers and consumers imported from other files.
For each source candidate, record relative path, line, method, endpoint expression, and wrapper chain. A comment, example, or non-table endpoint still needs an explicit disposition. Excluded build outputs are never recorded.
Write the settings inventory to
docs/webapi-selectall-migration/migration-report.json and render the draft
report as described in
references/configuration-and-reporting.md.
Do not propose fields yet.
Stop if any in-scope source or configuration file cannot be read.
<!-- gate: migrate-webapi-selectall:2.confirm-scope | category=plan | cancel-leaves=draft-migration-report -->🚦 Gate (plan · migrate-webapi-selectall:2.confirm-scope): Confirm the project, configuration scopes and profiles, wildcard count, explicit-setting count, and source inventory before schema retrieval. Canceling leaves only the read-only draft report.
Use AskUserQuestion to confirm or cancel. Expand the inventory and repeat this
phase if the user identifies another source or deployment scope.
Phase 3: Retrieve schema and resolve columns
Goal: Use authoritative names while letting the LLM determine actual usage.
3.1 Retrieve only relevant table schema
Build the initial unique list containing:
- logical table names from all Web API settings;
- entity-set names from all candidate table calls;
- entity-set names directly present in bind targets or related-table calls.
Do not treat a navigation-property name as a table identifier. Its target logical name is authoritative only after relationship metadata resolves it.
Resolve the environment URL from confirmed project context or pac env who.
If unavailable, ask for the URL as data gathering; never ask for or accept an
access token.
Write every deduplicated identifier, one per line, to
docs/webapi-selectall-migration/table-identifiers.txt. Run:
node "${PLUGIN_ROOT}/skills/migrate-webapi-selectall/scripts/query-table-schema.js" --project-root "<PROJECT_ROOT>" --environment-url "<ENVIRONMENT_URL>" --tables-file "<PROJECT_ROOT>/docs/webapi-selectall-migration/table-identifiers.txt" --output "<PROJECT_ROOT>/docs/webapi-selectall-migration/table-schema.json"
If an identifier does not resolve, trace the code or obtain the correct contract; do not guess.
After the initial snapshot:
- Match every used
$expandnavigation property against its source table's returned relationship metadata. - Collect only target logical names absent from all existing snapshots.
- Write those names to
table-identifiers-pass-<N>.txtand query them totable-schema.pass-<N>.json. - Repeat for nested expansion paths until every used navigation segment is resolved.
Treat table-schema.json and all numbered snapshots as one schema package.
Never requery a logical table already present in that package, and never
launch concurrent schema queries.
Identifier lists and schema snapshots are working files. Keep them until verification finishes, then delete them in Phase 7.
3.2 Analyze every call and consumer
For every source inventory row:
- Read the complete enclosing function or template block.
- Trace imported wrappers, URL variables, query builders, body builders, response mappers, types, components, templates, and every caller.
- Follow conditional branches, spreads, dynamic arrays, and runtime configuration.
- Map the entity set to its logical table using the schema package.
- Apply every rule in [references/column-analys
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
92.4kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.5kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ai-job-search
45.1kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.8kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
