Favicon of scan-site

scan-site Skill

AI Agent SkillJavaScriptOpen source

Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. Scans the live site's public surface for vulnerabilities and surfaces issues by severity. Use when the user wants to scan, check, test, audit, or assess a published site, find vulnerabilities on p Published by microsoft in power-platform-skills.

Decision snapshot

Is this a fit?

Best for

Testing, Security review, Includes SKILL.md, Reusable instructions

Works with

Compatibility not yet detected.

Access

Can write or update data, Write actions, Filesystem access, Shell access

Setup

Copy skill directory

Project health

2 months ago · MIT license

Considerations

Confirm write permissions and scope before use. Access note: Local files. Access note: Shell access.

What is scan-site Skill?

Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. Scans the live site's public surface for vulnerabilities and surfaces issues by severity. Use when the user wants to scan, check, test, audit, or assess a published site, find vulnerabilities on p Published by microsoft in power-platform-skills. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.

Trust signal
95/100
Maintenance signal
90/100
Adoption signal
66/100

Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.

Key capabilities

  • Includes SKILL.md support
  • Reusable instructions support
  • Testing
  • Security review
  • Testing use cases
  • Security review use cases

Declared skill metadata

  • Source file: plugins/power-pages/skills/scan-site/SKILL.md

Allowed tools declared by source

ReadWriteBashGlobGrepAskUserQuestionTaskCreateTaskUpdateTaskList

These fields retain source and confidence evidence from the indexed SKILL.md.

Compatibility and setup

Copy skill directory
  • Install or run with Copy skill directory
  • Local files
  • Shell access

Requirements and access

Local filesShell access

Security and permissions

Review permissions before connecting any MCP server to an agent. Pay special attention to whether it can read local files, write data, call external services, or perform destructive actions.

Write actionsFilesystem accessShell accessCan write or update data

When to use scan-site Skill

  • Use it for testing.
  • Use it for security review.

Built with

JavaScriptCopy skill directory

Editorial notes

Source

  • Creator: microsoft
  • Repository: microsoft/power-platform-skills
  • Skill file: plugins/power-pages/skills/scan-site/SKILL.md

What it does

Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary. Scans the live site's public surface for vulnerabilities and surfaces issues by severity. Use when the user wants to scan, check, test, audit, or assess a published site, find vulnerabilities on p

Skill instructions

Plugin check: Run node "${PLUGINROOT}/scripts/check-version.js" — if it outputs a message, show it to the user before proceeding. Scan Site Run a security scan on a deployed Power Pages site, fetch the latest scan report, and surface findings in a plain-language summary. The scan runs server-side; duration depends on site size — small sites finish in minutes, large sites can take hours. This skill scans the live deployed site, not local source code. Initial request: $ARGUMENTS Gotchas - Website record id vs portal id. .powerpages-site/website.yml stores the website record id, not the portal id. Every script takes --portalId. Resolve once via website.js --websiteId during prerequisites. - Never resolve by name. Site names can duplicate inside an environment; only the website record id is safe. - null from the resolver means the site is not deployed, or the authenticated profile points at a different environment. - Scans are long-running. Duration depends on site size — small sites finis

Verified compatibility and discovery

Frequently asked questions

What is scan-site?

scan-site is a open-source AI agent skill with Copy skill directory. Runs a security scan on a deployed Power Pages site, fetches the latest scan report, and produces a plain-language summary.

Who is scan-site best for?

scan-site is best for reusing agent instructions, scripts, and references, testing workflows, security review workflows.

How do I install scan-site?

Install or run scan-site using Copy skill directory. Check scan-site for the latest setup command.

Is scan-site actively maintained?

scan-site may need a closer maintenance check before production use.

Share:

Stars
459
Forks
88
Last commit
2 months ago
Last verified
Aug 29, 2026
Metadata fetched
Aug 29, 2026
Repository age
8 months
License
MIT

Project health auto-fetched from the source repository.

Maintain this resource?

Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.

Alternatives to scan-site