{
  "markdown": "<p align=\"center\">\n  <img src=\"assets/banner-v2.svg\" alt=\"Microsoft Security Skills\" width=\"100%\">\n</p>\n\n<h1 align=\"center\">Microsoft Security Skills Plugin</h1>\n\n<p align=\"center\">\n  <a href=\"LICENSE\"><img src=\"https://img.shields.io/badge/license-MIT-50E6FF?style=flat-square&labelColor=0A2540\" alt=\"License: MIT\"></a>\n  <img src=\"https://img.shields.io/badge/skills-88-50E6FF?style=flat-square&labelColor=0A2540\" alt=\"88 skills\">\n  <img src=\"https://img.shields.io/badge/validated-2%20models-50E6FF?style=flat-square&labelColor=0A2540\" alt=\"Validated across 2 models\">\n  <img src=\"https://img.shields.io/badge/grounded%20in-Microsoft%20Learn-50E6FF?style=flat-square&labelColor=0A2540\" alt=\"Grounded in Microsoft Learn\">\n  <img src=\"https://img.shields.io/badge/hosts-Copilot%20%7C%20Claude%20%7C%20Cursor%20%7C%20Codex%20%7C%20Gemini-50E6FF?style=flat-square&labelColor=0A2540\" alt=\"Compatible hosts\">\n</p>\n\n<p align=\"center\">\n  <a href=\"#install-in-60-seconds\"><b>Install the plugin</b></a> .\n  <a href=\"#which-skill-for-my-use-case\"><b>Which skill do I use?</b></a> .\n  <a href=\"#prompts-to-try\"><b>Prompts to try</b></a>\n</p>\n\n---\n\nSecurity work is not just a configuration problem. It is a decision problem: which control\napplies here, what needs to be validated before a policy goes live, which investigation path to\nfollow, and what guardrails matter in this environment. The Microsoft Security Skills Plugin\npackages security expertise into curated skills so compatible coding agents can give accurate,\nopinionated Microsoft Security guidance instead of generic security advice.\n\n> **This is a skills package, not a standalone agent.** There is no `microsoft-security-skills`\n> CLI. You install it into an existing AI host (GitHub Copilot, Claude Code, Cursor, Codex CLI,\n> or Gemini CLI) and invoke skills through that host's chat. If you do not already have a\n> working AI host, see [Prerequisites](#prerequisites) below before installing.\n\n- 88 curated Microsoft Security skills\n- Coverage: Security, Identity and Management, Compliance and Privacy, Cloud platform security\n- Compatible with GitHub Copilot, Claude Code, Cursor, Codex CLI, Gemini CLI, and other agentic hosts\n- Public knowledge only, grounded in Microsoft Learn\n- Behaviourally validated: a reproducible harness measures the lift each skill adds over an\n  unaided model, verified across two independent frontier models ([details](#validating-the-skills))\n\n## What this plugin delivers\n\n### Security skills: the brain\n\nThis plugin ships **88 curated Microsoft Security skills** that teach an agent how security\nwork gets done across the Microsoft portfolio. Each skill provides workflows, decision trees,\nand guardrails grounded in public [Microsoft Learn](https://learn.microsoft.com/security/)\ndocumentation - no proprietary content.\n\nSkills are grouped by portfolio area:\n\n- **Threat protection and SecOps** with `defender-xdr`, `defender-for-endpoint`,\n  `defender-for-identity`, `defender-for-cloud-hardening`, `defender-for-servers`,\n  `defender-for-storage`, `defender-for-containers`, `defender-for-iot`, `defender-easm`,\n  `defender-tvm`, `sentinel`, `sentinel-detection-engineering`, `unified-secops-platform`,\n  and `threat-modelling`\n- **Identity, access, and governance** with `entra-id`, `entra-id-governance`,\n  `entra-id-protection`, `entra-permissions-management`, `entra-global-secure-access`,\n  `entra-verified-id`, `entra-workload-identity`, `entra-external-id`, `passkeys-fido2`,\n  `conditional-access-mfa`, `azure-pim`, and `windows-hello`\n- **Compliance and data protection** with `purview-dlp-policy`, `purview-advanced-dlp`,\n  `purview-ediscovery`, `purview-audit`, `purview-data-classification`,\n  `purview-data-lifecycle`, `purview-communication-compliance`, `insider-risk-baseline`,\n  `purview-insider-risk-management`, `purview-records-management`, `purview-customer-key`,\n  `compliance-manager`, and `microsoft-priva`\n- **AI and agent security** with `microsoft-agent-365`, `purview-agent-365-security`,\n  `purview-copilot-oversharing`, `m365-oversharing`, `purview-dspm-ai`,\n  `copilot-for-m365-readiness`, `purview-ai-hub`, `defender-for-cloud-ai`,\n  `azure-ai-content-safety`, and `agent-identity-governance`\n- **Endpoint and device management** with `intune-device-mgmt`, `intune-app-protection`,\n  `bitlocker-design`, `paw-design`, `windows-11-security-baseline`, `macos-intune-baseline`,\n  and `defender-for-business`\n- **Cloud and platform security** with `azure-policy`, `azure-key-vault`,\n  `azure-network-security-design`, `azure-firewall`, `azure-app-service-security`,\n  `cloud-app-security-posture`, `api-security-design`, `azure-bastion-jit`,\n  `azure-ddos-protection`, `azure-waf`, `azure-confidential-computing`,\n  `azure-monitor-security`, and `iac-security`\n- **Security operations acceleration** with `security-copilot`, `security-copilot-agents`,\n  `compromise-recovery`, and `azure-site-recovery`\n\n## Why this plugin is different\n\nThis is not a prompt pack. It is a packaged Microsoft Security capability layer:\n\n- **Skills** teach the agent when to use each security workflow and what to avoid.\n- **Guardrails** are built into every skill to prevent common implementation mistakes.\n- **Public knowledge only** - every skill cites Microsoft Learn; no proprietary methodology\n  or customer data is included.\n- **Multi-host support** lets you use the same security capability across GitHub Copilot in\n  VS Code, Copilot CLI, Claude Code, Cursor, Codex CLI, Gemini CLI, and other compatible hosts.\n\n## Pairs with the agent toolkit\n\nSkills give the agent **knowledge**. To act on real tenant data (run KQL on Microsoft\nSentinel, read incidents from Microsoft Defender XDR, query Microsoft Graph for Entra\nsign-ins, search Microsoft Purview Audit), pair this plugin with\n[`microsoft-security-agent-toolkit`](https://github.com/vinayaklatthe/microsoft-security-agent-toolkit) -\nMCP servers, KQL snippets, Logic Apps templates, and end-to-end demos. See\n[`INTEGRATIONS.md`](INTEGRATIONS.md).\n\n## What you get\n\n| Component | What it adds | Scope |\n|---|---|---|\n| **88 Microsoft Security skills** | Expertise, decision trees, workflows, and guardrails across the Microsoft Security portfolio | Security, Identity and Management, Compliance and Privacy, Cloud platform security |\n\n## Install in 60 seconds\n\n### Prerequisites\n\n#### 1. A supported AI host (pick one and verify it works first)\n\nThis plugin extends an existing AI host. Confirm your host is installed **and** authenticated\nbefore you run any install command - a host folder on disk is not the same as a working host.\n\n| Host | Verify it works |\n|---|---|\n| **GitHub Copilot** (VS Code) | Open VS Code, open Copilot Chat, ask any question, confirm a response. |\n| **Claude Code** | `claude --version` **and** confirm you have an active Claude subscription. Licensing is the common trap. |\n| **Codex CLI** | `codex --version` |\n| **Gemini CLI** | `gemini --version` |\n| **Cursor** | Launch Cursor and confirm chat returns a response. |\n\n#### 2. Tooling\n\n- **Git** installed and accessible from the command line\n- **Node.js 18+** on your PATH if you plan to use `npx skills add`\n\n```bash\ngit --version\nnpx --version\n```\n\n### APM (one install, multiple harnesses)\n\nThe Microsoft Security Skills Plugin supports [APM](https://github.com/microsoft/apm). One\ncommand installs it across GitHub Copilot, Claude Code, Cursor, OpenCode, Codex, and Gemini:\n\n```bash\napm install vinayaklatthe/microsoft-security-skills\n```\n\n> **APM target detection caveat.** APM reports a target as `active` when it detects host\n> folders such as `.github/`, `.claude/`, or `.codex/` in your workspace. That does **not**\n> mean the host CLI is installed or licensed. Verify your host with the table above before\n> trusting `active` status.\n\n### Universal install (all hosts)\n\nClone the repository and point your agent at the `skills/` directory:\n\n```bash\ngit clone https://github.com/vinayaklatthe/microsoft-security-skills.git\n```\n\nOr use the skills CLI to install globally for a specific host:\n\n```bash\n# GitHub Copilot (VS Code, Copilot CLI)\nnpx skills add https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills -a github-copilot -g -y\n\n# Claude Code\nnpx skills add https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills -a claude -g -y\n\n# Cursor\nnpx skills add https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills -a cursor -g -y\n\n# Codex CLI\nnpx skills add https://github.com/vinayaklatthe/microsoft-security-skills/tree/main/skills -a codex -g -y\n```\n\n### Gemini CLI\n\n**Install the extension**:\n\n```bash\ngemini extensions install https://github.com/vinayaklatthe/microsoft-security-skills\n```\n\n## Quick start (GitHub Copilot)\n\nIf GitHub Copilot in VS Code is your host, this is the shortest path from zero to working\nskills.\n\n1. **Verify Copilot works.** Open VS Code, open Copilot Chat, ask `What is Microsoft Entra ID?`\n   and confirm you get a response.\n2. **Install APM.** Follow [APM install instructions](https://github.com/microsoft/apm).\n3. **Install the skills.**\n   ```bash\n   apm install vinayaklatthe/microsoft-security-skills --target copilot\n   ```\n   Expected output: `88 skill(s) integrated -> .agents/skills/`\n4. **Confirm the skill files are present** (see [Verify the installation](#verify-the-installation) below).\n5. **Use the skills.** Open Copilot Chat and try one of the [Prompts to try](#prompts-to-try).\n\n## Verify the installation\n\nAfter install, run one file check and three behavioural checks.\n\n### 0. Confirm skill files installed\n\n```bash\n# macOS / Linux\nls .agents/skills | wc -l\n```\n\n```powershell\n# Windows PowerShell\n(Get-ChildItem .agents\\skills -Directory).Count\n```\n\nExpected: around 88 folders, including `defender-xdr`, `entra-id`, `sentinel`,\n`purview-dlp-policy`, and `m365-oversharing`. If the count is zero or `.agents/skills` is\nmissing, the install did not complete - re-run the install command and check the host you\ntargeted.\n\n### 1. Verify security skills\n\nAsk:\n\n> What Microsoft Defender controls should I prioritise for a new Microsoft 365 tenant?\n\nYou should get structured, product-specific guidance with Microsoft Learn references - not\ngeneric security advice.\n\n### 2. Verify identity skills\n\nAsk:\n\n> How do I design a Conditional Access policy baseline for a mid-size organisation?\n\nYou should get a policy framework with named Conditional Access templates and guardrails.\n\n### 3. Verify compliance skills\n\nAsk:\n\n> What Purview DLP policies should I configure to protect sensitive data in Microsoft 365?\n\nYou should get scoped DLP guidance with workload-specific recommendations.\n\n## Prompts to try\n\nOnce the plugin is installed, try prompts like these:\n\n- `What are the first Defender XDR controls I should enable for a new tenant?`\n- `Design a Conditional Access baseline for our Entra ID tenant.`\n- `Help me build a Purview DLP policy to protect financial data.`\n- `What Sentinel analytic rules should I enable for identity threat detection?`\n- `How do I configure Entra ID Protection for risky sign-in response?`\n- `Review my Intune device compliance policy for security gaps.`\n- `What Defender for Cloud hardening recommendations apply to my Azure workloads?`\n- `Help me design a PAW (Privileged Access Workstation) deployment.`\n- `What Purview Insider Risk policies should I start with?`\n- `How do I use Security Copilot to accelerate an incident investigation?`\n\n## Which skill for my use case?\n\nUse this table to pick the right skill before asking your question.\n\n| If you want to... | Use this skill |\n|---|---|\n| Investigate a multi-product incident (endpoint + identity + email) | `defender-xdr` |\n| Build or operate a SIEM, ingest logs, write KQL detections | `sentinel` |\n| Merge Sentinel and Defender XDR into one portal for your SOC | `unified-secops-platform` |\n| Use AI to help investigate or summarise incidents | `security-copilot` |\n| Automate repetitive triage with autonomous AI agents | `security-copilot-agents` |\n| Respond to an active breach or ransomware attack | `compromise-recovery` |\n| Set up identity and access management (users, SSO, hybrid) | `entra-id` |\n| Enforce MFA and access controls (Conditional Access) | `conditional-access-mfa` |\n| Detect risky users or leaked credentials | `entra-id-protection` |\n| Remove standing admin rights and implement JIT access | `azure-pim` |\n| Govern identity lifecycle and access packages | `entra-id-governance` |\n| Manage multicloud permissions across AWS, GCP, Azure | `entra-permissions-management` |\n| Protect endpoints with EDR, attack surface reduction | `defender-for-endpoint` |\n| Detect identity-based attacks on Active Directory | `defender-for-identity` |\n| Protect email from phishing and business email compromise | `defender-for-office-365` |\n| Harden cloud infrastructure posture (Secure Score, attack paths) | `defender-for-cloud-hardening` |\n| Harden SaaS app configurations (M365, Salesforce, etc.) | `cloud-app-security-posture` |\n| Manage Intune device compliance and configuration | `intune-device-mgmt` |\n| Prevent data loss across Exchange, SharePoint, Teams, Endpoint | `purview-dlp-policy` |\n| Find and classify sensitive data across your estate | `purview-data-classification` |\n| Investigate legal or HR matters with eDiscovery | `purview-ediscovery` |\n| Monitor what sensitive data flows through AI prompts | `purview-dspm-ai` |\n| Fix oversharing before rolling out Microsoft 365 Copilot | `purview-copilot-oversharing` |\n| Remediate Microsoft 365 oversharing across SharePoint/OneDrive/Teams (data foundation) | `m365-oversharing` |\n| Manage AI agents at scale (observe, govern, secure) with a single control plane | `microsoft-agent-365` |\n| Detect insider data theft or policy violations | `insider-risk-baseline` |\n| Understand which Purview feature to use (orientation) | `purview-general` |\n| Design a Zero Trust security architecture | `security-architecture` |\n| Threat model a system with STRIDE | `threat-modelling` |\n| Secure Azure network design (hub-spoke, NSG, private endpoints) | `azure-network-security-design` |\n| Store and rotate secrets, keys, certificates | `azure-key-vault` |\n| Enforce governance guardrails across Azure subscriptions | `azure-policy` |\n| Protect APIs (OWASP API Top 10, APIM security) | `api-security-design` |\n| Estimate cost of Azure security controls | `azure-pricing` |\n\n> **Overlapping scenarios:** If your scenario spans multiple areas (e.g., a SOC involving both\n> SIEM and XDR), start with the most specific skill and follow its cross-references.\n\n## Portfolio coverage\n\n| Product family | Coverage in this repo | Example skills |\n|---|---|---|\n| Security | Defender, Sentinel, SecOps workflows, threat modelling | `defender-xdr`, `sentinel`, `unified-secops-platform`, `threat-modelling` |\n| Identity and Management | Entra, Conditional Access, governance, endpoint management | `entra-id`, `entra-id-governance`, `conditional-access-mfa`, `intune-device-mgmt` |\n| Compliance and Privacy | Purview and Priva controls for data protection and compliance | `purview-dlp-policy`, `purview-ediscovery`, `purview-audit`, `microsoft-priva` |\n| Cloud and platform security | Azure security architecture and control implementation | `azure-policy`, `azure-key-vault`, `azure-network-security-design`, `azure-firewall` |\n| AI and agent security | Governing and securing AI agents and data foundations for AI | `microsoft-agent-365`, `purview-agent-365-security`, `m365-oversharing`, `purview-copilot-oversharing` |\n| Security operations acceleration | Security Copilot and response-oriented workflows | `security-copilot`, `security-copilot-agents`, `compromise-recovery` |\n\n## How agents use these skills\n\n1. Agents scan skill front matter (`name`, `description`, and `WHEN:` triggers) to identify likely matches.\n2. Agents load the most relevant `SKILL.md` files for detailed guidance.\n3. Agents follow the skill body to produce focused, actionable outputs tied to Microsoft Learn references.\n\n## Repository layout\n\nThe key pieces are:\n\n- `skills/` - the Microsoft Security skill definitions, one subfolder per skill\n- `plugin.json` - plugin metadata for agent harnesses\n- `validation/` - zero-dependency validation harness (structure, links, evals)\n- `README.md` - high-level overview and install guide\n\n```\nskills/\n  sentinel/SKILL.md\n  defender-xdr/SKILL.md\n  purview-dlp-policy/SKILL.md\n  ...\n```\n\n## Skill format\n\nEach `SKILL.md` follows a consistent structure:\n\n```markdown\n---\nname: <skill-slug>\ndescription: \"<what it does>. WHEN: <trigger>, <trigger>, <trigger>.\"\nlicense: MIT\nmetadata:\n  author: Microsoft\n  version: \"0.1.0\"\n---\n\n<concise, public-knowledge guidance, with Microsoft Learn links>\n```\n\n## Validating the skills\n\nA zero-dependency validation harness (just Node 18+, no `npm install`) verifies the\nskills are well-formed, accurate, and actually drive the intended outcome.\n\n```bash\nnpm run check:structure   # frontmatter, WHEN: triggers, required sections\nnpm run eval              # desired-outcome coverage (see validation/cases/)\nnpm run check:links       # every Microsoft Learn URL resolves (catches link rot)\nnpm run validate          # all three\n```\n\nThree layers of checks:\n\n| Check | Answers | Script |\n|---|---|---|\n| Structural | Are skills well-formed and discoverable? | `validation/check-structure.mjs` |\n| Behavioural (coverage) | Does the skill contain the knowledge each desired outcome needs? | `validation/run-evals.mjs` |\n| Link rot | Do all documentation links still resolve? | `validation/check-links.mjs` |\n\nThe behavioural eval reads assertion files in `validation/cases/<skill>.json`. Each case\nlists a prompt and the must-mention points a good answer should contain, grounded in the\nskill's Microsoft Learn references. The default `coverage` mode checks those points are\npresent in the skill (runs anywhere, free). To score real model answers, generate one\n`<skill>__<index>.txt` per case with the skill loaded, then run:\n\n```bash\nnpm run eval:answers          # score answers in validation/answers/with-skill\nnpm run eval:answers:report   # same, as a Hit/Miss + Score table\n```\n\nThe 10 highest-risk skills ship with hand-authored assertions and a set of `with-skill`\nanswers. To prove a skill *changes behaviour*, capture a `baseline` (answers from a clean\nsession with no skill loaded) and compare the scores - see\n`validation/answers/README.md`.\n\n```bash\nnpm run eval:compare          # baseline vs with-skill, lift summary\nnpm run eval:compare:report   # per-case comparison table\n```\n\nMeasured on the 10 high-risk skills (20 prompts, 61 assertions), validated across two\nindependent frontier models used as graders:\n\n| Model | Baseline (no skill) | With skill | Lift |\n|---|---|---|---|\n| Claude Opus 4.8 | 51/61 (84%) | 61/61 (100%) | +10 |\n| GPT-5.5 | 55/61 (90%) | 61/61 (100%) | +6 |\n\nThe skill never regressed either model, and the gains concentrate on the high-consequence\noperational details a generic answer tends to skip. See `validation/answers/README.md`.\n\n\nAll three checks run automatically on every pull request and weekly (link-rot sweep) via\nGitHub Actions - see `.github/workflows/validate.yml`.\n\n## Troubleshooting\n\n### The agent is not using security skills\n\n- Make sure the plugin installed successfully in your host.\n- Confirm the `skills/` directory is present and contains `SKILL.md` files.\n- Reload or restart your host so it re-indexes plugins and skill definitions.\n\n### Skills are loading but responses seem generic\n\n- The agent may not have matched a skill trigger. Try phrasing the prompt using product\n  names directly (for example, \"Defender XDR\", \"Purview DLP\", \"Entra Conditional Access\").\n- Check that the skill's `WHEN:` triggers in the `description` front matter cover your\n  scenario. If they do not, open an issue or a pull request.\n\n### A skill is missing for a product or scenario I need\n\n- Check the `skills/` directory first - coverage may already exist under a different name.\n- If genuinely missing, contributions are welcome. See the contributing guide below.\n\n## Learn more\n\n- [Microsoft Security documentation](https://learn.microsoft.com/security/)\n- [Microsoft Defender XDR documentation](https://learn.microsoft.com/defender-xdr/)\n- [Microsoft Sentinel documentation](https://learn.microsoft.com/azure/sentinel/)\n- [Microsoft Entra documentation](https://learn.microsoft.com/entra/)\n- [Microsoft Purview documentation](https://learn.microsoft.com/purview/)\n- [microsoft/azure-skills](https://github.com/microsoft/azure-skills) - the Azure equivalent of this plugin\n\n## Contributing\n\nContributions are welcome. Keep every skill:\n\n- **Public-knowledge only** - cite Microsoft Learn; no proprietary methodology or customer data.\n- **Focused** - one product or task per skill.\n- **Concise** - guidance an agent can act on, not a full product manual.\n- **Guarded** - include at least one guardrail section covering common mistakes.\n\nThis project welcomes contributions and suggestions. Most contributions require you to agree\nto a Contributor License Agreement (CLA). For details, visit https://cla.opensource.microsoft.com.\n\n## Trademarks\n\nThis project may contain trademarks or logos for projects, products, or services. Authorised\nuse of Microsoft trademarks or logos is subject to and must follow\n[Microsoft's Trademark & Brand Guidelines](https://www.microsoft.com/legal/intellectualproperty/trademarks/usage/general).\n\n## License\n\n[MIT](LICENSE)\n",
  "bytes": 21481,
  "sha": "cb1b1497ec0f19dfc55ffcff5a48e25336b2532bfce0c928b0ea96d86e7f7e08",
  "repo_slug": "vinayaklatthe/microsoft-security-skills",
  "fonte": "repo",
  "truncated": false,
  "api": "https://api.agentalog.com/api/listings/skl_vinayaklatthe_microsoft_security_skills__a7e8aff2/readme"
}