microsoft hve-core
OFFICIALLABSCO SUMMARY
Two clusters dominate the set: seven are OWASP security knowledge bases — agentic, CI/CD, Docker, infrastructure, LLM, MCP, and web-application top-10 lists — licensed CC BY-SA 4.0 from the OWASP Foundation rather than under the repository's own MIT license, and a further cluster covers Design Thinking coaching (dt-coaching-foundation, dt-curriculum, dt-methods, dt-rpi-integration) alongside the "RPI" research-plan-implement-review cycle the README calls HVE Core's own core methodology (rpi-plan, rpi-implement, rpi-review, rpi-research, rpi-quick). A smaller group wires up third-party tools directly — jira, mural, gitlab, and gh-code-scanning each drive that service's own API or CLI, and vscode-playwright is the one skill here that talks to an MCP server rather than a REST API or local CLI.
This is built for a team already using GitHub Copilot Chat or the GitHub Copilot CLI inside HVE Core's own install (a VS Code extension or a copilot plugin add), not for a generic skills-aware agent — the README frames skills as only one of four building blocks alongside agents, prompts, and instructions, and the documented way to start is picking an agent like rpi-agent or task-researcher from a picker, not invoking a skill directly.
READ THE FULL ANALYSIS
Three skills route to one that isn't in our data. prompt-analyze, prompt-refactor, and prompt-builder each describe themselves as a compatibility alias that forwards to a skill called hve-builder — the review, refactor, or creation mode of it — but hve-builder does not appear anywhere among the 49 skills we have on file for this repository, live or dead. Either it lives somewhere our capture doesn't reach, or the alias points at something no longer present under that name; we could not confirm which from the material here.
What it costs to run one. 36 of the 49 need nothing beyond HVE Core itself, mostly the OWASP, Design Thinking, RPI, and standards-reference skills, which are read-only knowledge rather than tools that call out anywhere. Seven need a local tool already on the machine (PowerPoint generation, GIF or video conversion, the installer itself), five need a stored account credential (Jira, Mural, GitLab, GitHub code-scanning, and a text-to-speech voiceover skill), and vscode-playwright is the only one that depends on an MCP server.
ALSO IN THIS PACKAGE
hve-core
Opinionated, rapidly evolving HVE Core agentic SDLC patterns and tools
agentic workflows
GitHub Agentic Workflows (gh-aw) - Create, debug, and upgrade AI-powered workflows with intelligent prompt routing
Backlog Grooming
Assesses open GitHub issues for backlog health and returns bounded advisory reports without mutating candidate issues
Dependency Reviewer
Reviews dependency changes for licensing, maintenance status, necessity, and SHA pinning compliance
Issue Triage Agent
Automated single-issue triage agent for classifying, labeling, quality-checking, and assessing GitHub issues for implementation readiness
README
Overview of all hve-core agent systems with workflow documentation and quick links
README
Reference documentation for HVE Core agents.
pptx.prompt
Create, update, or manage PowerPoint slide decks
WHAT'S INSIDE
48 showing · 48 totalNothing else to set up — install it and go.
accessibility
Finds where a website or app shuts out people with disabilities, and turns what it finds into planned work measured against the accessibility standards the project is held to.
adr-author
Walks a team through writing down one technical decision — what was chosen, what was rejected, and why — and files it as a numbered Architecture Decision Record in the repository.
architecture-diagrams
Draws how a cloud system is wired together, straight from the setup files that define it, instead of by hand.
backlog-templates
One shared shape for the tickets that come out of a security, privacy or accessibility review, so every team's findings land in Azure DevOps or GitHub looking the same.
caveman
A way to make an assistant answer in clipped, telegram-style English to save words, while code, error messages and commands are still printed in full.
code-review
Reviews a code change the way a careful team would — correctness, house style, accessibility, security, release readiness — and writes the findings up in one consistent format.
customer-card-render
Turns the notes written up in a Design Thinking session — the vision, the problem, the scenario, the personas — into a finished PowerPoint deck.
documentation
Keeps a project's documentation honest: what is missing, what no longer matches the code, what breaks the house rules — and writes the new pages when they are needed.
dt-coaching-foundation
The ground rules an AI coach follows while running a Design Thinking workshop: how much to hint before handing over an answer, when a group is ready to move on, and how rough the work is allowed to stay.
dt-curriculum
A nine-lesson course that teaches Design Thinking one method at a time, so a learner works up from framing a problem to rolling the answer out for real.
dt-methods
The per-method playbook an AI Design Thinking coach works from: what to ask a team at each of the nine stages, and which technique fits the moment.
dt-rpi-integration
The bridge from a finished Design Thinking workshop into the work that follows — what the session has to hand over before research, planning and building can start from it.
gh-code-scanning
Pulls a repository's security warnings out of GitHub and into the terminal, grouped so you can see which problem is the worst and how often it repeats.
gitlab
Work on GitLab from the terminal: review and comment on proposed code changes, start a build, and read back the log when it fails.
hve-core-installer
A guided setup for HVE-Core, Microsoft's pack of ready-made agents, prompts and skills for AI coding assistants — it puts the pack on your machine and confirms it landed.
jira
Run the everyday Jira chores from the terminal — find a ticket, read it, edit it, move it along, comment on it — without opening the browser.
mural
Drives a Mural online whiteboard from the command line — listing the boards you can see, and adding, editing or clearing the sticky notes, shapes and images on them.
owasp-agentic
The ten ways an AI agent system gets attacked, one page each: a hijacked goal, a tool turned against its owner, a memory quietly poisoned.
owasp-cicd
Ten known weak points in the machinery that builds and ships software — credentials left lying about, a build step running code nobody reviewed, a release artifact nobody verified.
owasp-docker
Six things that go wrong once software is packaged into containers: it runs with more power than it needs, it sits on a stale base image, or it can reach anything on the network.
owasp-infrastructure
Ten weaknesses that turn up in a company's own servers and networks, from software years out of date to default passwords still in place and machines nobody has a record of.
owasp-llm
What goes wrong when a product is built on a large language model — someone talking it into ignoring its instructions, the model spilling what it was told, a bill that runs away — set out one risk at a time.
owasp-mcp
Ten security holes in the connectors that hand an AI assistant real tools and data: leaked tokens, a tool description rewritten by an attacker, servers nobody signed off on.
owasp-top-10
The best-known checklist in web security, one page per risk — broken access control, injection, weak cryptography and the seven others that keep breaking real sites.
powerpoint
Builds, edits and checks a PowerPoint deck from plain text files that describe the slides, so the deck can be rebuilt on demand instead of nudged into shape by hand.
pr-reference
Collects everything that changed on a branch — every commit, and the actual line-by-line edits — into one file to hand to whoever writes the pull request or reviews it.
privacy-standards
Tells you which privacy rule a finding actually falls under — a GDPR article, a California requirement, a line of the NIST privacy framework — so a review can cite it.
prompt-analyze
Reads one of the instruction files that tell an AI assistant how to behave and returns a verdict on it — pass, revise or blocked — leaving the file itself untouched.
prompt-builder
Writes a new instruction file for an AI assistant, or improves one you already have, and does not hand it back until it has been reviewed and tested.
prompt-refactor
Tidies up an instruction file that has grown messy: shorter, clearer, and tested to prove the assistant still behaves exactly as it did before.
python-foundational
Reads freshly written Python and points out where it drifts from the way experienced Python programmers write it: names, missing type hints, and shortcuts that bite later.
rai-planner
Walks a team through a Responsible AI review one stage at a time, and ends with the concrete work the review says has to be done.
rai-standards
The outside rules a Responsible AI review has to answer to: the American government's AI risk framework, the risk tiers in the EU's AI Act, and a threat list written for AI systems.
requirements-author
Writes the document that says what a product has to do and why — the business case first, then the product spec — and keeps every requirement tied back to the goal it came from.
rpi-implement
Carries out the plan that was agreed, one task at a time, ticking items off and writing down what actually changed — and stops to ask rather than improvising when the plan does not fit.
rpi-plan
Everything gets decided on paper first: the steps in order, a picture of the system before and after, and one pass of criticism over the draft, with no code touched yet.
rpi-research
The homework stage: work out what is actually known about a task, and what argues against the obvious answer, then write it down where the team can push back before any code is written.
rpi-review
Holds the finished work up against the plan it came from, grades whatever does not match, and sends each gap on to whoever has to deal with it.
secure-by-design
Eleven things the UK and Australian governments say software should be built around from day one, each one a set of questions to hold a design up against.
security-planning
Works out how an application could be attacked, part by part, and writes it up as a security plan — then checks that plan against the findings you have now to show where things have drifted.
security-reviewer-formats
The house style for security and Responsible AI review write-ups: what a report looks like, what a single finding looks like, and what each severity level means.
supply-chain-security
Checks how far a project can trust its own build and the code it depends on — are releases signed, is there a list of what went into them — and turns each gap into a ranked to-do.
telemetry-foundations
One agreed vocabulary for the measurements an application reports about itself, so two teams do not invent two names for the same thing, plus a rule for stripping personal data out first.
tts-voiceover
Reads a slide deck's speaker notes aloud in a synthetic voice and puts the audio back into the deck, so the presentation narrates itself.
vally-tests
Writes the tests that check whether an AI assistant's instruction file really behaves the way it claims to — and turns down requests to write attack tests instead.
vex
Sets up the paperwork that tells your customers a published vulnerability does not actually affect your product, and checks each such claim is backed by evidence.
video-to-gif
Turns a video file into an animated GIF small enough to paste into a document or a chat message, and still clean to look at.
vscode-playwright
Takes tidy screenshots of the VS Code editor, or of a chat with its AI assistant, sized to fit the slide or documentation page they are going into.
HOW TO GET IT
npx skills add microsoft/hve-corenpx skills add microsoft/hve-core --skill <name> --full-depthPick the skill name from the Skills tab — each entry there installs independently.
/plugin marketplace add microsoft/hve-core/plugin install hve-core@hve-coreTyped inside the agent's own prompt, not in a terminal. The marketplace is called hve-core, which is the part after the @.