What Is an AI Skill?
TL;DR: “Skill” means three different things: Microsoft Copilot capabilities, portable SKILL.md instruction packages for agents, and this library’s read-only Microsoft 365 audit skills. Ours inspect your tenant and produce evidence. They change nothing and are not certification.
What is an AI skill, in plain terms?
An AI skill is a named, reusable set of instructions that an AI assistant loads when a task matches its description. It tells the assistant how to do one job consistently. The word is used loosely across vendors, so the first step is knowing which of three meanings a person intends.
| Meaning | Who publishes it | What it is | Where you meet it |
|---|---|---|---|
| Microsoft Copilot skills and People Skills | Microsoft | Product capabilities, or a data service, built into Microsoft 365 | SharePoint admin centre, Copilot in SharePoint, the Microsoft 365 profile card |
| SKILL.md Agent Skills | Anthropic, GitHub Copilot tooling, Copilot Studio | A folder with a SKILL.md file of instructions | Claude, Visual Studio, Copilot Studio agents |
| This library’s audit skills | EDUC4TE community | Read-only Microsoft 365 review procedures | The pages on this site |
What do Microsoft mean by Copilot skills and People Skills?
Microsoft uses “skills” for several unrelated Microsoft 365 features, and none of them is a downloadable audit. Copilot skills in the SharePoint admin centre are Copilot capabilities for administrators, and People Skills is a service that builds skill profiles for users. Both are documented on Microsoft Learn.
- Copilot skills in the SharePoint admin centre: natural-language guidance and multi-criteria site search for SharePoint and OneDrive administration. Microsoft states that Copilot does not make configuration changes on your behalf, and the feature is included with a Microsoft Copilot licence.
- Skills in Copilot in SharePoint: reusable multistep workflows. A personal skill lives in the user’s OneDrive. A site skill lives in the site’s Agent Assets library at
/Agent Assets/Skills/<skill-name>/SKILL.md. Microsoft notes a skill can only do what the user already has permission to do. - People Skills: an AI-driven service that generates skill profiles for users against a taxonomy, so Microsoft Copilot and Viva can answer people-related questions.
What is a SKILL.md Agent Skill?
A SKILL.md Agent Skill is a directory containing a SKILL.md file, with YAML frontmatter (a name and a description) followed by Markdown instructions. An agent reads the description, then loads the instructions only when a request matches. Anthropic, Visual Studio with GitHub Copilot, and Copilot Studio all use the format.
Anthropic describes three loading levels: metadata at startup, instructions when triggered, and bundled resources or scripts only as needed. The name is limited to 64 characters and the description to 1,024. Anthropic’s documentation warns that skills can carry executable code and should only come from trusted sources.
| Product | Where skills live | Source |
|---|---|---|
| Claude Code | ~/.claude/skills/ (personal) or .claude/skills/ (project) | Anthropic Agent Skills documentation |
| Visual Studio with GitHub Copilot | .github/skills/, .claude/skills/, .agents/skills/ (workspace); ~/.copilot/skills/, ~/.claude/skills/, ~/.agents/skills/ (personal) | Microsoft Learn |
| Copilot Studio agents | Uploaded as a SKILL.md file or a .zip package, or generated with AI | Microsoft Learn |
Microsoft Learn says Copilot Studio skills apply to agents powered by the GitHub Copilot harness, with usage-based billing, and that skills follow an open specification. Visual Studio’s page says built-in skills are disabled by default and that Copilot activates a skill when it judges it relevant.
What are this library’s skills for Microsoft 365?
This library’s skills are read-only review procedures for a Microsoft 365 tenant, written for Microsoft Security and AI specialists. Each page states its scope, the least-privilege roles it needs, the evidence it returns and the sources behind its claims. Their purpose is to make Copilot and agent risk visible before it becomes an incident.
They sit in three buckets:
- Cowork: Agentic AI, Microsoft 365 Copilot and Copilot Studio governance, plus everyday workflow skills.
- SharePoint: oversharing, permissions and site lifecycle, which decide what Microsoft 365 Copilot can surface.
- Purview: Microsoft Purview data protection, plus the wider security and compliance estate.
Each page opens with a TL;DR, lists prompts that trigger it, and ends with sources. The structure is designed so a person or an AI assistant can pick the right skill quickly.
Why are these skills read-only by default?
They are read-only because the safest first question about an AI estate is “what is actually configured?”, not “what should we change?”. A skill that only reads cannot break production, cannot widen access, and can be run with read-only access. Where a skill changes anything, its page must say exactly what.
- Evidence, not certification: output supports a conversation with an assessor. It does not replace a formal assessment or audit, and no skill here certifies compliance.
- Least privilege: each page names the roles and read-only permissions it needs.
- Human decision: remediation is proposed as a ranked list with owners. People decide and act.
How do you run one of these skills?
To run a skill, give its page to an AI assistant that can read your tenant, using an account holding only the read-only roles listed on the page, then review the evidence it returns. The steps below are the same for every skill in the library.
- Pick the skill from the list below and open its page.
- Check the licences and least-privilege roles listed on the page against the account you will use.
- Confirm the page’s scope statement says read-only, or names what it changes.
- Use one of the page’s “When should you run this skill?” prompts with your assistant.
- Review the output table and check each finding against its evidence.
- Record the result, assign owners, and re-run after remediation.
What do you need before you start?
- A Microsoft 365 tenant, and the licences named on the skill page.
- A named account limited to the read-only roles the page specifies.
- An AI assistant able to query the relevant admin portals or Microsoft Graph with those read permissions.
- A place to store evidence with an owner and a date.
- Agreement with your security lead that a review is happening.
Which skills should you run first, and in what order?
Run readiness and oversharing first, because they decide what Microsoft 365 Copilot can surface. Then cover labels, identity, agents, audit, Australian frameworks and the wider security estate. Every skill in the library appears once below.
- Readiness baseline (why: know your starting point): Copilot readiness assessment, Zero Trust maturity baseline, Secure Score improvement plan.
- SharePoint and Teams exposure (why: Copilot surfaces what people can already reach): oversharing audit, Everyone Except External Users sweep, external sharing deep audit, sharing links activity, site permissions baseline, broken permission inheritance, Restricted SharePoint Search readiness, Data Access Governance report review, SharePoint Advanced Management, site lifecycle review, Teams and Groups sprawl, Teams external access, Teams meeting policy.
- Labels and data loss prevention (why: controls follow the data into prompts): label coverage, sensitive information type coverage, tenant DLP coverage, Copilot DLP impact simulation, DSPM for AI remediation, Teams meeting label inheritance.
- Identity and access (why: agents and people act through Microsoft Entra): Conditional Access coverage gap, MFA and strong authentication, PIM privileged roles, access reviews health, entitlement management, lifecycle workflows, stale and guest accounts, starter and leaver access, risky users and sign-ins, workload identity risk, app registration secrets, OAuth consent risk, inactive licence recovery.
- Agents and Copilot governance (why: agents are the new identities and data paths): Copilot Studio agent inventory, Copilot Studio DLP gap check, computer-using agent risk, Entra Agent ID audit, Entra agent sponsorship, Conditional Access for agents, Agent 365 registry and shadow AI, Agent 365 tools governance, Copilot Control System validator, Copilot Notebooks governance, Copilot Wave 3 agent governance, Work IQ API access, SharePoint agent publishing, SharePoint AI skills governance, Security Copilot governance, multi-model Purview controls.
- Audit, monitoring and AI activity (why: you need evidence of what happened): audit log retention, admin audit trail, agent audit trail forensics, Copilot interaction compliance, Purview AI activity explorer, shadow AI app discovery, retention and records, communication compliance, insider risk, eDiscovery readiness, Privacy Act ADM logger.
- Australian frameworks (why: map evidence to what regulators ask for): Essential Eight self-assessment, Essential Eight ML3 uplift, Essential Eight evidence packager, ISM control pack, IRAP control evidence, IRAP evidence trail, PSPF control mapping, APRA CPS 234 readiness, Compliance Manager control mapper, SOCI incident responder.
- Wider security estate (why: AI risk rides on ordinary security hygiene): Defender advanced hunting, Defender ASR configuration, Defender incident hygiene, Intune compliance baseline, Security Exposure Management, Sentinel analytics rules, Sentinel data connectors, MITRE ATT&CK coverage, threat hunting readiness, Defender for Cloud Apps policy coverage, session control, OAuth app governance, cloud app risk catalogue, anti-phishing coverage, Safe Links and Attachments, transport rule risk, mailbox delegation and forwarding.
The cowork bucket also holds everyday workflow skills, which are drafting aids rather than audits: onboarding checklist, policy document template, secure meeting minutes and stakeholder update email. Check each page’s scope statement to see exactly what it produces.
Where are the best starter skills in each bucket?
Start with one skill per bucket, then widen. Each starter answers a question a buyer usually asks first and needs only read-only access.
| Bucket | Starter skill | Question it answers |
|---|---|---|
| Cowork | Copilot readiness assessment | Is this tenant ready to activate Microsoft 365 Copilot? |
| SharePoint | SharePoint oversharing audit | What can Microsoft 365 Copilot surface that it should not? |
| Purview | Essential Eight maturity self-assessment | How mature is our baseline security posture? |
Where do the related guides fit?
Use these pillar guides for the wider decision, then return here to run the skills.
- Copilot readiness guide: preparing SharePoint and the tenant for Microsoft 365 Copilot.
- Copilot governance guide: Microsoft Purview controls for Copilot and agents.
- Australian Copilot compliance: mapping Copilot evidence to Australian frameworks.
- Agent governance guide: governing agentic AI.
Notes
- This page is a guide, not a skill. It changes nothing in your tenant.
- Skills in this library produce evidence and prioritised findings. They do not certify compliance and are not a substitute for a formal assessment.
- Confirm current behaviour on the linked Microsoft and Anthropic pages, as product names and features change.
- Microsoft’s Visual Studio page refers to the agentskills.io specification for the SKILL.md format.
Sources
- Agent Skills overview, Anthropic
- Use Agent Skills with GitHub Copilot, Microsoft Learn (Visual Studio)
- Skills overview for agents, Microsoft Learn (Copilot Studio)
- Extend Copilot in SharePoint with skills, Microsoft Learn
- Copilot skills in the SharePoint admin center, Microsoft Learn
- Overview of People Skills, Microsoft Learn
Licensed under CC BY 4.0 by EDUC4TE .
Last reviewed 2026-09-30