Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →

microsoft/hve-core

12 skills800 installs15.6k starsGitHub

Install

npx skills add https://github.com/microsoft/hve-core

Skills in this repo

1PowerpointPowerPoint slide deck generation and management using python-pptx with YAML-driven content and styling. Generates, updates, and manages PowerPoint slide decks using `python-pptx` with YAML-driven content and styling definitions.312installs2Owasp Top 10Microsoft HVE Core OWASP Top 10 2025 knowledge base skill. Provides structured guidance for identifying, assessing, and remediating the ten most critical web application security risks per OWASP 2025 edition. Used during security review, threat modeling, and remediation planning for web applications. Covers injection, broken access control, cryptographic failures, insecure design, and other Top 10 categories with assessment and remediation patterns.170installs3Owasp AgenticThe owasp-agentic skill encodes the OWASP Top 10 for Agentic Applications 2026 as structured machine-readable references an agent can query to identify, assess, and remediate security risks in AI agent systems. The entrypoint links eleven normative reference documents from vulnerability index through agent goal hijack, tool misuse, identity abuse, supply chain vulnerabilities, unexpected code execution, memory poisoning, insecure inter-agent communication, cascading failures, human-agent trust exploitation, and rogue agents. Each reference document includes detection and remediation guidance restructured from OWASP Foundation CC BY-SA 4.0 content. The skill is not user-invocable directly but serves as a knowledge base for security review workflows. Layout separates SKILL.md entrypoint from references directory with per-vulnerability documents aligned to OWASP Agentic Security numbering. Use when assessing agent architecture security, mapping threats to OWASP categories, or drafting remediation plans for agentic application risk.42installs4Owasp LlmThe owasp-llm skill encodes the OWASP Top 10 for LLM Applications 2025 as machine-readable reference documents an agent can query when assessing LLM security risks. The SKILL.md entrypoint links eleven normative references covering prompt injection, sensitive information disclosure, supply chain, data and model poisoning, improper output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, misinformation, and unbounded consumption. Each vulnerability document in references aligns with OWASP LLM Applications numbering and includes detection and remediation guidance restructured for agent consumption. A vulnerability index cross-references identifiers and categories across the set. Content derives from OWASP Foundation material under CC BY-SA 4.0 with agent-oriented restructuring noted in attribution. The skill is not user-invocable directly but supports security reviews, threat modeling, and remediation planning for LLM-powered products. Triggers include assessing LLM risks, OWASP LLM Top 10 review, or remediating prompt injection and excessive agency issues. Use whenever builders need authoritative OWASP LLM vulnerability references during design rev.39installs5Hve Core InstallerThe hve-core-installer skill is a decision-driven installer for HVE-Core with environment detection, six clone-based methods, extension quick-install, validation, MCP configuration, and optional agent customization. It operates as Installer and Validator personas: the Installer detects the environment and executes steps, then the Validator verifies paths, settings, and agent accessibility before completion. Phase 1 obtains consent and detects the user environment. Phase 2 offers Quick Install via the VS Code Marketplace extension or clone-based installation for customization. Clone paths run a decision matrix recommending methods based on shell, IDE, and team needs across six clone strategies. Phase 5 validation confirms installation success, Phase 6 configures gitignore and presents MCP guidance, and Phase 7 optionally copies agents for local customization on clone installs only. Re-running validates existing installs or offers upgrade and is safe anytime. Compatibility requires VS Code or Insiders with git and network for clone methods. Use when installing HVE-Core agents, prompts, instructions, and skills into a development environment.35installs6Owasp CicdThe owasp-cicd skill encodes the OWASP Top 10 CI/CD Security Risks as structured, machine-readable references an agent can query during pipeline security reviews. The SKILL.md entrypoint points to eleven normative documents: a vulnerability index plus ten risk files covering insufficient flow control, inadequate IAM, dependency chain abuse, poisoned pipeline execution, insufficient PBAC, credential hygiene, insecure system configuration, ungoverned third-party services, improper artifact integrity validation, and insufficient logging. Each reference document includes detection and remediation guidance derived from OWASP Foundation content under CC BY-SA 4.0. The skill layout separates the entrypoint from references/ numbered 00 through 10 aligned with OWASP CI/CD numbering. Agents load specific vulnerability files when assessing pipeline configurations, workflow permissions, secret handling, or artifact signing gaps. It is a knowledge-base skill rather than an execution workflow. Use when reviewing CI/CD pipelines for OWASP CI/CD Top 10 compliance or investigating specific pipeline security weaknesses.35installs7Owasp McpThe owasp-mcp skill encodes the OWASP MCP Top 10 2025 as structured, machine-readable references for MCP security reviews. The entrypoint links to eleven documents: a vulnerability index and ten risks including token mismanagement, privilege escalation via scope creep, tool poisoning, supply chain attacks, command injection, prompt injection via contextual payloads, insufficient authentication, lack of audit telemetry, shadow MCP servers, and context injection over-sharing. Each reference file aligns with OWASP MCP numbering and includes detection and remediation guidance under CC BY-SA 4.0. Agents query specific numbered references when assessing MCP server configurations, tool permissions, token storage, or telemetry gaps. The skill is a knowledge base entrypoint rather than a deployment workflow, designed for security assessment of MCP integrations in agent systems. Use when evaluating MCP servers, tools, or agent connectors against OWASP MCP Top 10 risks.35installs8Owasp InfrastructureThe owasp-infrastructure skill encodes the OWASP Infrastructure Security Top 10 2024 as structured references an agent can query. The SKILL.md entrypoint links eleven reference documents from vulnerability index through outdated software, threat detection, insecure configurations, resource management, cryptography, network access, authentication, information leakage, access to management components, and asset management. Use to identify, assess, and remediate internal IT infrastructure security risks aligned with OWASP Infrastructure guidance. Content is CC-BY-SA-4.0 licensed from the OWASP Infrastructure Security Project.30installs9Video To GifThe video-to-gif skill converts video files to optimized GIF animations with FFmpeg two-pass palette optimization for better color fidelity and smaller sizes. Scripts convert.sh and convert.ps1 support fps, width, dithering, HDR tonemapping, trim start and duration, and loop count. Automatic HDR detection via ffprobe applies tonemapping algorithms hable, reinhard, mobius, or bt2390. File search checks cwd, workspace root, Movies or Videos, Downloads, and Desktop when paths are partial. Requires FFmpeg on PATH with install instructions for macOS, Linux, and Windows. Output includes absolute path link to the generated GIF.29installs10GitlabThe gitlab skill from hve-core provides GitLab-oriented security and development workflow references for agents assisting with GitLab repositories, pipelines, and secure configuration within the hve-core skill collection.25installs11Owasp DockerThe owasp-docker skill from hve-core encodes OWASP-oriented Docker and container security references for identifying misconfigurations, unsafe defaults, and remediation steps in containerized workloads.24installs12Security Reviewer FormatsThe security-reviewer-formats skill defines structured output templates for security review findings from the hve-core pack, ensuring consistent severity, evidence, and remediation sections across reviews.24installs

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.