Labsco
Labsco/Repos/microsoft/hve-core
REPO PACKAGE

microsoft hve-core

OFFICIAL
microsoft · publisher1,245 repository starsMIT · Freegithub.com/microsoft/hve-core
48skills
35ready to use

Two clusters dominate the set: seven are OWASP security knowledge bases — agentic, CI/CD, Docker, infrastructure, LLM, MCP, and web-application top-10 lists — licensed CC BY-SA 4.0 from the OWASP Foundation rather than under the repository's own MIT license, and a further cluster covers Design Thinking coaching (dt-coaching-foundation, dt-curriculum, dt-methods, dt-rpi-integration) alongside the "RPI" research-plan-implement-review cycle the README calls HVE Core's own core methodology (rpi-plan, rpi-implement, rpi-review, rpi-research, rpi-quick). A smaller group wires up third-party tools directly — jira, mural, gitlab, and gh-code-scanning each drive that service's own API or CLI, and vscode-playwright is the one skill here that talks to an MCP server rather than a REST API or local CLI.

This is built for a team already using GitHub Copilot Chat or the GitHub Copilot CLI inside HVE Core's own install (a VS Code extension or a copilot plugin add), not for a generic skills-aware agent — the README frames skills as only one of four building blocks alongside agents, prompts, and instructions, and the documented way to start is picking an agent like rpi-agent or task-researcher from a picker, not invoking a skill directly.

READ THE FULL ANALYSIS

Three skills route to one that isn't in our data. prompt-analyze, prompt-refactor, and prompt-builder each describe themselves as a compatibility alias that forwards to a skill called hve-builder — the review, refactor, or creation mode of it — but hve-builder does not appear anywhere among the 49 skills we have on file for this repository, live or dead. Either it lives somewhere our capture doesn't reach, or the alias points at something no longer present under that name; we could not confirm which from the material here.

What it costs to run one. 36 of the 49 need nothing beyond HVE Core itself, mostly the OWASP, Design Thinking, RPI, and standards-reference skills, which are read-only knowledge rather than tools that call out anywhere. Seven need a local tool already on the machine (PowerPoint generation, GIF or video conversion, the installer itself), five need a stored account credential (Jira, Mural, GitLab, GitHub code-scanning, and a text-to-speech voiceover skill), and vscode-playwright is the only one that depends on an MCP server.

35Work with nothing else to set up.
1,245Stars on the GitHub repository, at last check.