scan-site
Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. Scans the live site's public surface for vulnerabilities and surfaces issues by severity
Install / Use
npx skills add microsoft/power-platform-skills --skill scan-siteInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of scan-site
scan-site scores 85/100 on our quality scale, 769th of 1,119 Security skills we index.
Its SKILL.md is 12 KB long, well organised into 21 sections with 7 code examples: a thorough specification that gives an agent plenty to work with.
It has 919 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 12 days ago, so scan-site is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit โ read the skill file before letting an agent act on it.
scan-site compared with similar skills
All 4 of these similar skills score higher than scan-site; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| scan-site (this skill)by microsoft | 85 | 919 | 12d ago | SKILL.md |
| algorithmic-artby anthropics | 100 | 177.9k | 14d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 14d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 15d ago | SKILL.md |
| ui-ux-pro-maxby nextlevelbuilder | 100 | 130.2k | 15d ago | SKILL.md |
Frequently asked questions
- How do I install scan-site?
- Run
npx skills add microsoft/power-platform-skills --skill scan-site. The install tabs above show the steps for each supported agent. - Which AI agents does scan-site work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is scan-site safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is scan-site still maintained?
- The repository was last updated 12 days ago, so scan-site is actively maintained.
Skill content
View source on GitHubname: scan-site description: >- Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. Scans the live site's public surface for vulnerabilities and surfaces issues by severity. Use when the user wants to scan, check, test, audit, or assess a published site, find vulnerabilities on production, view the latest scan report, see previous scan results, run a security audit, or asks "how safe is my live site?", "is my site vulnerable?", "audit my production site" โ even if they say "find issues" or "check for problems" without mentioning "scan" or "security". user-invocable: true argument-hint: "[optional: --review <out-dir>]" allowed-tools: Read, Write, Bash, Glob, Grep, AskUserQuestion, TaskCreate, TaskUpdate, TaskList model: opus
Plugin check: Run
node "${PLUGIN_ROOT}/scripts/check-version.js"โ if it outputs a message, show it to the user before proceeding.
Scan Site
Run a security scan on a deployed Power Pages site, fetch the latest scan report, and surface findings in a plain-language summary. The scan runs server-side; duration depends on site size โ small sites finish in minutes, large sites can take hours.
This skill scans the live deployed site, not local source code.
Initial request: $ARGUMENTS
Gotchas
- Website record id vs portal id.
.powerpages-site/website.ymlstores the website record id, not the portal id. Every script takes--portalId. Resolve once viawebsite.js --websiteIdduring prerequisites. - Never resolve by name. Site names can duplicate inside an environment; only the website record id is safe.
nullfrom the resolver means the site is not deployed, or the authenticated profile points at a different environment.- Scans are long-running. Duration depends on site size โ small sites finish in minutes, large sites can take hours. Poll in the background and increase
--timeoutMinutesfor large sites. - Only one scan per site at a time. A start while a scan is running returns
Z003โstart-deep-scan.jsreports it as{ "status": "already-running" }(exit 0). - Rate limits may apply. The service may throttle repeated scans on the same site. When throttled, wait and retry later.
- No completed scan yet. A fresh site or a site mid-scan has no completed report โ
get-latest-report.jsreturns{ "status": "empty" }.
Workflow
- Prerequisites โ Locate project, confirm sign-in, identify site
- Check scan state โ Detect whether a scan is currently running
- Choose an action โ Context-aware recommendation (run new scan / show latest)
- Run the scan โ Start and poll for completion
- Fetch and summarize โ Get the report, present findings
- Walk through follow-ups โ Route issues to the right downstream skill (only if the report contains issues)
Task Tracking
Create tasks in four groups. Mark each in_progress when starting, completed when done.
| Group | When to create | Tasks | |-------|----------------|-------| | 1 | At start | Check prerequisites | | 2 | After prerequisites pass | Check scan state ยท Choose an action (skip in review mode) | | 3 | After user confirms an action (or in review mode) | Run the scan (skip only if the user chose to view latest results in interactive mode) ยท Fetch and summarize (always) | | 4 | After fetch and summarize | Walk through follow-ups (only if the report contains issues AND not in review mode) |
1. Prerequisites
1.1 Locate the project, detect review mode
Use Glob to find **/powerpages.config.json. If $ARGUMENTS contains --review <out-dir>, remember the output directory โ Step 3 (choose an action) is skipped, Step 4 (run scan) executes automatically (start a fresh scan or attach to a running one), Step 5 writes JSON only, and Step 6 (follow-ups) is skipped.
1.2 Resolve site identifiers
Read .powerpages-site/website.yml โ extract id field โ that is <WEBSITE_ID>.
If missing, the site has not been deployed. Tell the user and recommend /deploy-site. Stop. Do not resolve by name or URL.
Resolve to portalId:
node "${PLUGIN_ROOT}/scripts/website.js" --websiteId "<WEBSITE_ID>"
Capture Id (portalId), Type, Name, WebsiteUrl. If exit code 2 โ sign-in required (pac auth create or az login). If null โ site not found in this environment. Stop in either case.
2. Check scan state
node "${PLUGIN_ROOT}/skills/scan-site/scripts/poll-deep-scan.js" --portalId "<PORTAL_ID>" --once
--once does a single status check, exits 0, and prints:
{ "status": "ongoing" }โ a scan is currently running.{ "status": "idle" }โ no scan running.
Then call get-latest-report.js to know whether a completed report exists:
node "${PLUGIN_ROOT}/skills/scan-site/scripts/get-latest-report.js" --portalId "<PORTAL_ID>"
{ "status": "ok" } means a report is available. { "status": "empty" } means no completed scan exists.
3. Choose an action
Skip in review mode โ go straight to Step 4 (which always runs in review mode).
MUST use plain language only. Never use words like CSP, CORS, OWASP, hardening, or scan profile.
Default approach
<!-- gate: scan-site:3.action-choice | category=plan | cancel-leaves=nothing -->๐ฆ Gate (plan ยท scan-site:3.action-choice): Recommend an action based on the site's scan state (running, idle, has report, no report), then ask the user to accept or choose differently. Starting a new scan triggers a multi-minute backend run; using an existing report is free.
Trigger: Phase 3 entry (interactive mode only โ review mode bypasses to step 4). Why we ask: Auto-starting a new scan wastes minutes if a recent report already answers the question; auto-using a stale report misses recent findings. Cancel leaves: Nothing โ no scan triggered, no report consumed.
Analyze the site's current state and recommend the single most relevant action via AskUserQuestion:
- Scan running, no completed report โ recommend waiting for the running scan to finish.
- Scan running, report exists โ recommend showing the latest results while the new scan continues.
- Idle, no completed report โ recommend running a new scan.
- Idle, recent report exists โ ask whether to use the existing report or run a fresh scan.
If the site's state does not warrant a specific recommendation, do not force one โ ask what the user wants to do.
Option rules
<!-- not-a-gate: meta-documentation describing how to structure `AskUserQuestion` options in this skill โ not a literal call site. The actual prompt ("use existing report / run a fresh scan") fires dynamically in ยง3 Default approach. See approval-gates.md ยง6.24a + ยง6.27. -->When presenting options via AskUserQuestion:
- Keep
labelto 1โ5 words. Includedescriptionon every option. - For options that trigger a new scan, surface the relevant caveats inside that option's
descriptionso the user has them at decision time. Do not ask a separate confirmation question after the user picks the option. - Include
previewonly when the option represents a concrete change (starting a new scan). Do not addpreviewto "show latest" or informational choices. - Only show options that are actionable given the current state. If a scan is already running, do not offer "Start a new scan".
- Mark "(Recommended)" only when the site's state justifies it.
4. Run the scan
In review mode, always execute this step: if a scan is already running, attach to it and poll; otherwise start a fresh scan and poll. Do not ask โ review mode runs end-to-end without user interaction.
In interactive mode, skip if the user chose to view the latest results.
Start the scan:
node "${PLUGIN_ROOT}/skills/scan-site/scripts/start-deep-scan.js" --portalId "<PORTAL_ID>"
If stdout is { "status": "already-running" }, skip ahead to polling โ there is already a scan in progress.
Then poll for completion:
node "${PLUGIN_ROOT}/skills/scan-site/scripts/poll-deep-scan.js" --portalId "<PORTAL_ID>"
Run polling with run_in_background: true so the user can keep working. The script exits when the scan finishes or the timeout passes (default 20 minutes). If it times out, fetch whatever report is available and note the timeout in the summary.
5. Fetch and summarize
5.1 Fetch and transform the report
node "${PLUGIN_ROOT}/skills/scan-site/scripts/transform-report.js" --portalId "<PORTAL_ID>"
Parse the stdout JSON. The status field can be:
okโ a normal report withfindingsanddetails.emptyโ no completed scan exists for this site (e.g., fresh site or scan still running). Record a singleinfofinding explaining this and continue.malformedโ the API returned a response missing theRulesarray. The transform emits a singlewarningfinding describing this; surface it to the user and recommend re-running the scan.
See references/scan-reference.md for the Risk โ severity mapping the script applies.
5.2 Review mode
In review mode, skip the HTML report and write the transform stdout to <REVIEW_DIR>/scan-site.json. Then stop. The transform emits { status, findings, details }; the orchestrating skill handles presentation.
5.3 Render HTML report
Skip in review mode.
Render uses the same shared template as the consolidated security review. Build a single-section review-data payload, then render:
node "${PLUGIN_ROOT}/scripts/build-review-data.js" \
--reportName "Site Scan" \
--inputDir "<TEMP_DIR>" \
--siteName "<SITE_NAME>" \
--goalLabel "Live Site Scan" \
--scopeLabel "<SCOPE_LABEL>" \
--summary "<SUMMARY_TEXT>" \
--output "<TEMP_DIR>/data.json"
node "${PLUGIN_ROOT}/scripts/render-review.js" \
--data "<TEMP_DIR>/data.json" \
--output "<PROJECT_ROOT>/docs/site-scan-<YYYY-MM-DD-HHMMSS>.html"
<TEMP_DIR> should contain only scan-site.json (the transform output from Step 5.1) โ build-review-data.js ignores intermediate files. The filename must include the local timestamp (e.g., site-scan-2026-05-14-053805.html). Delete <TEMP_DIR> after the render succeeds. Open the rendered HTML in the browser.
5.4 Present summary
Plain-language summary in the chat: total findings, count by severity, and what changed since the last scan if available. Do not lead with technical names.
5.5 Record skill usage
Reference:
${PLUGIN_ROOT}/references/skill-tracking-reference.mdUse
--skillName "ScanSite".
6. Walk through follow-ups
Skip in review mode. Skip if the report has no issues.
Group findings by which downstream skill can help:
- Header / cookie issues โ
/manage-headers - WAF / firewall issues (block bots, rate-limit pages, restrict IPs/countries) โ
/manage-firewall - Permission issues โ
/audit-permissionsto review existing table permissions, and/or/create-webrolesto set up role-based access - Login or external identity issues โ
/setup-auth - Code-level issues (exposed debug pages, information leakage, source visible publicly) โ suggest a manual code fix; there is no routed skill for these findings
Suggest only the skills that match findings actually present in the report. If a finding does not map to any skill, surface it as a manual follow-up the user can act on. If no meaningful follow-up exists, end the skill โ do not ask just to ask.
Constraints
- Plain language โ MUST NOT use technical jargon with the user. Use everyday language; explain the technical name only when asked.
- Read-only โ this skill only runs scans and reads results. It never enables WAF, deletes scans, or changes site configuration.
- Background long-running calls โ start the scan, then poll via
run_in_background: trueso the user can continue working. - Context-aware interactions โ every recommendation MUST reflect the site'
Truncated for display โ read the full file on GitHub.
Related Skills
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way โ as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an emโฆ
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVGโฆ
ui-ux-pro-max
130.2kUI/UX design intelligence for web, mobile, and desktop. This skill should be used when designing, building, reviewing, or fixing interfaces, including pages, components, design systems, accessibility, interaction, responsive layout, typography, color, charts, and stack-specific UI implementation.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit โ see the Safety scan above for what the skill file itself contains.
