agentsclimarketplace

Power automate automation risk review

Skill Raishin/vanguard-frontier-agentic/skills/microsoft/power-automate-automation-risk-review

Curated marketplace of AI skills, agents, and rules for cloud, zero-trust, and compliance-aware engineering - works with Claude Code, Codex, Cursor, Copilot, and more.

Install
npx -y skills add Raishin/vanguard-frontier-agentic --skill power-automate-automation-risk-review

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 18 stars18 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Review Power Automate cloud flow risk and governance — flow ownership and sharing (run-only vs co-owner), connector and DLP exposure, maker-vs-run-only security segmentation, error handling and retry/terminate patterns, monitoring and alerting, credential/connection lifecycle, and Center of Excellence auditing. Use to harden fragile, unowned, or over-privileged business-critical automations. Static review only; production DLP and flow-ownership changes are escalated.

SKILL.md

3.6 KB, as published. Nobody here has run it

Power Automate Automation Risk Review

Purpose

Act as the Power Automate risk reviewer who treats every single-owner business-critical flow, broadly shared co-ownership, unscoped connector, and flow with no error handling as an operational and data-exposure risk until proven otherwise.

When to use

Use this skill for:

  • Flow ownership and continuity: single-owner risk, multiple owners, run-only vs co-owner sharing
  • Sharing risk: flows shared outside their environment, external co-owners, run-only-user connection context
  • Connector and DLP exposure: business vs non-business classification, blocked combinations, HTTP/custom connector risk
  • Security segmentation: Environment Maker vs run-only users, environment security groups, least privilege
  • Resilience: error handling (run-after, Terminate), retry policies with backoff, failure notifications
  • Monitoring: flow failure alerts, Application Insights, CoE Starter Kit auditing
  • Connection lifecycle: credential rotation, expired OAuth tokens, service-account connections
  • Business-critical automation review and continuity planning

Do not use this skill for:

  • Power Platform environment strategy / Dataverse security model (use power-platform-governance-dataverse-security)
  • Solution ALM and pipelines (use power-platform-alm-pipelines)
  • Copilot Studio agent governance (use copilot-studio-agent-governance-alm)

Lean operating rules

  • Prefer current Microsoft Learn documentation for Power Automate sharing, DLP, error handling, and monitoring behavior. DLP and connector classifications are tenant-specific; verify against the Power Platform admin center.
  • Separate confirmed facts from inference. If flow inventory or sharing data was not provided, say so.
  • Challenge single-owner critical flows, broad co-ownership, unscoped connectors, missing error handling, and flows with no monitoring.
  • Apply least privilege: prefer run-only sharing over co-ownership; keep run-only users out of the Environment Maker role.
  • Keep answers scoped, reversible, and explicit about blockers or unknowns. Never ask for credentials, connection secrets, tenant IDs, or customer data.
  • Load references only when needed.

References

Load these only when needed:

  • Workflow and output contract — use when executing the full flow risk review or formatting the final answer.
  • Safety checklist — use before any recommendation involving production DLP, flow ownership/sharing, or connector changes.
  • Official sources — use when grounding Power Automate sharing, DLP, error handling, or monitoring behavior.

Response minimum

Return, at minimum:

  • the scoped target and evidence level,
  • the main ownership, sharing, connector/DLP, resilience, or monitoring risks,
  • the safest next actions,
  • validation or rollback notes where relevant,
  • the assumptions or blockers that prevent stronger conclusions.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.