scan-site

作者: microsoft

对已部署的Power Pages站点运行安全扫描,获取最新扫描报告,并生成通俗易懂的摘要。扫描实时站点的公开…

npx skills add https://github.com/microsoft/power-platform-skills --skill scan-site

Plugin check: Run node "${PLUGIN_ROOT}/scripts/check-version.js" — if it outputs a message, show it to the user before proceeding.

Scan Site

Run a security scan on a deployed Power Pages site, fetch the latest scan report, and surface findings in a plain-language summary. The scan runs server-side; duration depends on site size — small sites finish in minutes, large sites can take hours.

This skill scans the live deployed site, not local source code.

Initial request: $ARGUMENTS

Gotchas

  • Website record id vs portal id. .powerpages-site/website.yml stores the website record id, not the portal id. Every script takes --portalId. Resolve once via website.js --websiteId during prerequisites.
  • Never resolve by name. Site names can duplicate inside an environment; only the website record id is safe.
  • null from the resolver means the site is not deployed, or the authenticated profile points at a different environment.
  • Scans are long-running. Duration depends on site size — small sites finish in minutes, large sites can take hours. Poll in the background and increase --timeoutMinutes for large sites.
  • Only one scan per site at a time. A start while a scan is running returns Z003 — start-deep-scan.js reports it as { "status": "already-running" } (exit 0).
  • Rate limits may apply. The service may throttle repeated scans on the same site. When throttled, wait and retry later.
  • No completed scan yet. A fresh site or a site mid-scan has no completed report — get-latest-report.js returns { "status": "empty" }.

Workflow

  1. Prerequisites — Locate project, confirm sign-in, identify site
  2. Check scan state — Detect whether a scan is currently running
  3. Choose an action — Context-aware recommendation (run new scan / show latest)
  4. Run the scan — Start and poll for completion
  5. Fetch and summarize — Get the report, present findings
  6. Walk through follow-ups — Route issues to the right downstream skill (only if the report contains issues)

Task Tracking

Create tasks in four groups. Mark each in_progress when starting, completed when done.

GroupWhen to createTasks
1At startCheck prerequisites
2After prerequisites passCheck scan state · Choose an action (skip in review mode)
3After user confirms an action (or in review mode)Run the scan (skip only if the user chose to view latest results in interactive mode) · Fetch and summarize (always)
4After fetch and summarizeWalk through follow-ups (only if the report contains issues AND not in review mode)

1. Prerequisites

1.1 Locate the project, detect review mode

Use Glob to find **/powerpages.config.json. If $ARGUMENTS contains --review <out-dir>, remember the output directory — Step 3 (choose an action) is skipped, Step 4 (run scan) executes automatically (start a fresh scan or attach to a running one), Step 5 writes JSON only, and Step 6 (follow-ups) is skipped.

1.2 Resolve site identifiers

Read .powerpages-site/website.yml → extract id field → that is <WEBSITE_ID>.

If missing, the site has not been deployed. Tell the user and recommend /deploy-site. Stop. Do not resolve by name or URL.

Resolve to portalId:

node "${PLUGIN_ROOT}/scripts/website.js" --websiteId "<WEBSITE_ID>"

Capture Id (portalId), Type, Name, WebsiteUrl. If exit code 2 → sign-in required (pac auth create or az login). If null → site not found in this environment. Stop in either case.


2. Check scan state

node "${PLUGIN_ROOT}/skills/scan-site/scripts/poll-deep-scan.js" --portalId "<PORTAL_ID>" --once

--once does a single status check, exits 0, and prints:

  • { "status": "ongoing" } → a scan is currently running.
  • { "status": "idle" } → no scan running.

Then call get-latest-report.js to know whether a completed report exists:

node "${PLUGIN_ROOT}/skills/scan-site/scripts/get-latest-report.js" --portalId "<PORTAL_ID>"

{ "status": "ok" } means a report is available. { "status": "empty" } means no completed scan exists.


3. Choose an action

Skip in review mode — go straight to Step 4 (which always runs in review mode).

MUST use plain language only. Never use words like CSP, CORS, OWASP, hardening, or scan profile.

Default approach

🚦 Gate (plan · scan-site:3.action-choice): Recommend an action based on the site's scan state (running, idle, has report, no report), then ask the user to accept or choose differently. Starting a new scan triggers a multi-minute backend run; using an existing report is free.

Trigger: Phase 3 entry (interactive mode only — review mode bypasses to step 4). Why we ask: Auto-starting a new scan wastes minutes if a recent report already answers the question; auto-using a stale report misses recent findings. Cancel leaves: Nothing — no scan triggered, no report consumed.

Analyze the site's current state and recommend the single most relevant action via AskUserQuestion:

  • Scan running, no completed report → recommend waiting for the running scan to finish.
  • Scan running, report exists → recommend showing the latest results while the new scan continues.
  • Idle, no completed report → recommend running a new scan.
  • Idle, recent report exists → ask whether to use the existing report or run a fresh scan.

If the site's state does not warrant a specific recommendation, do not force one — ask what the user wants to do.

Option rules

When presenting options via AskUserQuestion:

  • Keep label to 1–5 words. Include description on every option.
  • For options that trigger a new scan, surface the relevant caveats inside that option's description so the user has them at decision time. Do not ask a separate confirmation question after the user picks the option.
  • Include preview only when the option represents a concrete change (starting a new scan). Do not add preview to "show latest" or informational choices.
  • Only show options that are actionable given the current state. If a scan is already running, do not offer "Start a new scan".
  • Mark "(Recommended)" only when the site's state justifies it.

4. Run the scan

In review mode, always execute this step: if a scan is already running, attach to it and poll; otherwise start a fresh scan and poll. Do not ask — review mode runs end-to-end without user interaction.

In interactive mode, skip if the user chose to view the latest results.

Start the scan:

node "${PLUGIN_ROOT}/skills/scan-site/scripts/start-deep-scan.js" --portalId "<PORTAL_ID>"

If stdout is { "status": "already-running" }, skip ahead to polling — there is already a scan in progress.

Then poll for completion:

node "${PLUGIN_ROOT}/skills/scan-site/scripts/poll-deep-scan.js" --portalId "<PORTAL_ID>"

Run polling with run_in_background: true so the user can keep working. The script exits when the scan finishes or the timeout passes (default 20 minutes). If it times out, fetch whatever report is available and note the timeout in the summary.


5. Fetch and summarize

5.1 Fetch and transform the report

node "${PLUGIN_ROOT}/skills/scan-site/scripts/transform-report.js" --portalId "<PORTAL_ID>"

Parse the stdout JSON. The status field can be:

  • ok — a normal report with findings and details.
  • empty — no completed scan exists for this site (e.g., fresh site or scan still running). Record a single info finding explaining this and continue.
  • malformed — the API returned a response missing the Rules array. The transform emits a single warning finding describing this; surface it to the user and recommend re-running the scan.

See references/scan-reference.md for the Risk → severity mapping the script applies.

5.2 Review mode

In review mode, skip the HTML report and write the transform stdout to <REVIEW_DIR>/scan-site.json. Then stop. The transform emits { status, findings, details }; the orchestrating skill handles presentation.

5.3 Render HTML report

Skip in review mode.

Render uses the same shared template as the consolidated security review. Build a single-section review-data payload, then render:

node "${PLUGIN_ROOT}/scripts/build-review-data.js" \
  --reportName "Site Scan" \
  --inputDir "<TEMP_DIR>" \
  --siteName "<SITE_NAME>" \
  --goalLabel "Live Site Scan" \
  --scopeLabel "<SCOPE_LABEL>" \
  --summary "<SUMMARY_TEXT>" \
  --output "<TEMP_DIR>/data.json"

node "${PLUGIN_ROOT}/scripts/render-review.js" \
  --data "<TEMP_DIR>/data.json" \
  --output "<PROJECT_ROOT>/docs/site-scan-<YYYY-MM-DD-HHMMSS>.html"

<TEMP_DIR> should contain only scan-site.json (the transform output from Step 5.1) — build-review-data.js ignores intermediate files. The filename must include the local timestamp (e.g., site-scan-2026-05-14-053805.html). Delete <TEMP_DIR> after the render succeeds. Open the rendered HTML in the browser.

5.4 Present summary

Plain-language summary in the chat: total findings, count by severity, and what changed since the last scan if available. Do not lead with technical names.

5.5 Record skill usage

Reference: ${PLUGIN_ROOT}/references/skill-tracking-reference.md

Use --skillName "ScanSite".


6. Walk through follow-ups

Skip in review mode. Skip if the report has no issues.

Group findings by which downstream skill can help:

  • Header / cookie issues → /manage-headers
  • WAF / firewall issues (block bots, rate-limit pages, restrict IPs/countries) → /manage-firewall
  • Permission issues → /audit-permissions to review existing table permissions, and/or /create-webroles to set up role-based access
  • Login or external identity issues → /setup-auth
  • Code-level issues (exposed debug pages, information leakage, source visible publicly) → suggest a manual code fix; there is no routed skill for these findings

Suggest only the skills that match findings actually present in the report. If a finding does not map to any skill, surface it as a manual follow-up the user can act on. If no meaningful follow-up exists, end the skill — do not ask just to ask.


Constraints

  • Plain language — MUST NOT use technical jargon with the user. Use everyday language; explain the technical name only when asked.
  • Read-only — this skill only runs scans and reads results. It never enables WAF, deletes scans, or changes site configuration.
  • Background long-running calls — start the scan, then poll via run_in_background: true so the user can continue working.
  • Context-aware interactions — every recommendation MUST reflect the site's current state:
    • Never offer "Start a new scan" while one is already running.
    • Never offer "Show latest results" when no completed report exists.
    • Mark "(Recommended)" only when the state justifies it.
  • Preview is for change review only — include preview only on options that start a new scan. Do not add to navigation or informational choices.

References

  • references/commands.md — script flags, response shapes, error catalogue, operating notes. Read § "Common error catalogue" when a script returns a non-zero exit code.
  • references/scan-reference.md — field-level schema for the deep-scan report, alert risk values, rule statuses, and severity mapping. Read when normalizing findings.

来自 microsoft 的更多技能

oss-growth
microsoft
OSS增长黑客角色
agent-framework-azure-ai-py
microsoft
使用Microsoft Agent Framework Python SDK(agent-framework-azure-ai)构建Azure AI Foundry代理。在创建使用AzureAIAgentsProvider的持久化代理、使用托管工具(代码解释器、文件搜索、网络搜索)、集成MCP服务器、管理对话线程或实现流式响应时使用。涵盖函数工具、结构化输出和多工具代理。
development
airunway-aks-setup
microsoft
在AKS上设置AI Runway——从裸集群到运行模型。涵盖集群验证、控制器安装、GPU评估、提供商设置和首次部署。适用场景:“设置AI Runway”、“接入AKS集群”、“安装AI Runway”、“airunway设置”、“将模型部署到AKS”、“在AKS上进行GPU推理”、“在AKS上配置KAITO”、“在AKS上运行LLM”、“在AKS上使用vLLM”、“在AKS上设置模型服务”、“AI Runway控制器”。
devops
appinsights-instrumentation
microsoft
使用Azure Application Insights对Web应用进行插桩的指南。提供遥测模式、SDK设置和配置参考。适用场景:如何对应用进行插桩、App Insights SDK、遥测模式、什么是App Insights、Application Insights指南、插桩示例、APM最佳实践。
devops
applicationinsights-web-ts
microsoft
使用Application Insights JavaScript SDK(@microsoft/applicationinsights-web)为浏览器/Web应用添加检测。用于真实用户监控(RUM)——页面视图、点击、AJAX/fetch依赖项、异常、自定义事件,以及与后端OpenTelemetry追踪关联的浏览器端GenAI代理追踪。涵盖SDK加载器脚本和npm设置、框架扩展(React、React Native、Angular)、点击分析、遥测初始化器,以及从浏览器发出的代理/工具/模型跨度所遵循的OTel GenAI语义约定。
devops
azure-ai-anomalydetector-java
microsoft
使用适用于 Java 的 Azure AI 异常检测器 SDK 构建异常检测应用程序。在实现单变量/多变量异常检测、时间序列分析或 AI 驱动的监控时使用。
development
azure-ai-language-conversations-py
microsoft
使用azure-ai-language-conversations Python SDK实现对话语言理解(CLU)。当使用ConversationAnalysisClient分析对话意图和实体、构建NLP功能或将语言理解集成到应用程序中时使用。
development
azure-ai-ml-py
microsoft
Azure Machine Learning SDK v2 for Python。用于机器学习工作区、作业、模型、数据集、计算资源和管道。 触发词:“azure-ai-ml”、“MLClient”、“工作区”、“模型注册表”、“训练作业”、“数据集”。
development