Skip to main content

Skills

This page lists the generated reference documentation for HVE Core skills.

AssetDescription
accessibilityConsolidated accessibility skill entrypoint for WCAG 2.2, ARIA Authoring Practices, cognitive accessibility, Section 508, EN 301 549, and the Accessibility Planner workflow.
code-reviewReview code changes from multiple perspectives with context bootstrap, depth-tier rigor, and structured findings output.
python-foundationalFoundational Python best practices, idioms, and code quality fundamentals
dt-coaching-foundationDesign Thinking coaching foundation knowledge: coach identity and philosophy, quality and fidelity constraints, method sequencing, coaching state schema, and the canonical deck workflow
dt-curriculumDesign Thinking learning curriculum covering nine progressive modules across the full Problem, Solution, and Implementation Space methods plus a shared manufacturing reference scenario for teaching and practice
dt-methodsDesign Thinking method coaching knowledge across all nine methods including per-method techniques, deep expertise, and industry context (energy, financial services, healthcare, manufacturing, nonprofit and social impact, pharmaceuticals and life sciences, professional services, public sector, retail and CPG)
dt-rpi-integrationDesign Thinking handoff knowledge for research-ready rpi-research inputs and DT-aware rpi-plan, rpi-implement, and rpi-review context
cavemanUltra-compressed response style that reduces output token count while preserving technical accuracy, with intensity levels and auto-clarity safety rules
copilot-otel-metricsSet up GitHub Copilot OpenTelemetry capture: configure the VS Code export settings, generate a local Grafana stack and dashboard, or generate the Azure collector, infrastructure, and dashboard for an organization.
customer-card-renderGenerate customer-card PowerPoint content YAML from Design Thinking canonical artifacts and build using the shared PowerPoint skill pipeline
demo-videoAssemble ordered frames or clips with narration into a narrated MP4 via FFmpeg
muralMural workspace, room, mural, and widget workflows via the Mural REST API exposed through a Python CLI. Use when you need to read or write Mural content or automate widget creation.
powerpointPowerPoint slide deck generation and management using python-pptx with YAML-driven content and styling
tts-voiceoverText-to-speech voice-over generation from YAML speaker notes using Azure Speech SDK with SSML pronunciation control
video-to-gifVideo-to-GIF conversion with FFmpeg two-pass optimization
vscode-playwrightVS Code screenshot capture using Playwright MCP with serve-web for slide decks and documentation
architecture-diagramsArchitecture diagram authoring for cloud infrastructure: parse Azure IaC, map relationships, and render either ASCII block diagrams or Mermaid flowcharts based on the caller's chosen output format
documentationCanonical documentation capability for audit, drift, validate, and author modes in hve-core.
hve-builder-testerTest HVE artifact behavior with black-box scenarios, contained simulation or approved native execution, independent grading, and evidence reports.
hve-builderAuthor, review, or validate Copilot prompt-engineering artifacts through independent review, behavior testing, and host checks.
prompt-analyzeCompatibility alias for read-only prompt artifact review. Routes static and behavior analysis to hve-builder review mode.
prompt-builderCompatibility alias for legacy prompt-building requests. Routes creation and improvement to the hve-builder skill.
prompt-refactorCompatibility alias for behavior-preserving prompt artifact cleanup. Routes refactoring to hve-builder refactor mode.
vally-testsAuthors Vally conformance tests for prompts, instructions, agents, and skills, including refusals for jailbreak, prompt-injection, harmful-elicitation, TOS, CoC, and PII-extraction stimuli
hve-core-installerDecision-driven HVE-Core installer with multiple clone-based and extension install methods, environment detection, and selective component installation
adr-authorAuthoring skill for Architecture Decision Records (ADRs) supporting capture, from-planner-handoff, and adopt-template entry modes with selectable Y-Statement or MADR v4.0.0 output templates, supersession lineage, and ASR trigger evaluation.
backlog-executeMutating backlog execution for Azure DevOps, GitHub, and Jira. Use to create one item or apply a reviewed handoff to a confirmed tracker.
backlog-managementShared backlog conventions for Azure DevOps, GitHub, and Jira. Use for platform resolution, autonomy tiers, sanitization guards, and story quality.
backlog-planRead-only backlog planning for Azure DevOps, GitHub, and Jira. Use to discover, triage, sprint-plan, or resume without mutating a tracker.
functional-plannerRead-only PRD-to-work-item hierarchy planning. Use to turn a PRD into a validated Azure DevOps, GitHub, or Jira handoff.
gitlabManage GitLab merge requests and pipelines with a Python CLI
jiraJira issue workflows for search, issue updates, transitions, comments, field discovery, and interactive credential setup via the Jira REST API. Use when you need to configure Jira access, search with JQL, inspect an issue, create or update work items, move an issue between statuses, post comments, or discover required fields for issue creation.
performance-slo-plannerPerformance, load, and reliability (SLO/SRE) planning for production readiness. Use when defining service level objectives, load characterization, capacity, latency budgets, stress/soak/spike test plans, false-positive baselines, and reliability targets. USE FOR: SLO/SLA definition, load testing plan, performance budget, capacity planning, reliability/SRE backlog, latency targets, error-budget policy. DO NOT USE FOR: executing load tests (use Azure Load Testing tooling), security threat modeling, RAI assessment, privacy/compliance planning, or authoring/restating PRD requirements (cite the PRD's existing NFR/FR ids instead).
privacy-standardsPrivacy planning reference for data-flow reasoning, standards mapping, and DPIA thresholds
rai-plannerOn-demand RAI planner reference pack covering Phase 1 capture, Phase 2 risk classification, Phase 5 impact assessment, and Phase 6 review and backlog handoff.
requirements-authorRequirements authoring guide for BRD and PRD across Discover, Define, and Govern with canonical templates and handoff contracts
security-planningSecurity planning reference set for operational buckets, STRIDE analysis, standards mapping, NIST control families, and backlog scaffolding.
rai-standardsConsolidated Responsible AI standards reference: NIST AI RMF 1.0, AI STRIDE threat-modeling overlay, EU AI Act risk tiers, and an open-standards catalog with phase mapping
rpi-challengerChallenge a confirmed task, decision, plan, or artifact through adaptive skeptical questions. Use when you need to expose assumptions before acting.
rpi-implementExecute an approved RPI plan, maintain current planning state, and record implementation evidence. Use when implementation is ready to begin or resume.
rpi-plan-critiqueIndependently critique an RPI plan and phase details against supplied evidence without editing plan sources. Use when planning credibility needs a read-only assessment.
rpi-planCreate evidence-based RPI plans and phase details from supplied context, research, drafts, and decisions. Use when implementation planning is needed.
rpi-quickSequence Research, Plan, Implement, Review, and Follow-up for an RPI task. Use when one workflow should coordinate the full delivery lifecycle.
rpi-researchResearch-only RPI playbook that gathers task evidence, writes dated research artifacts under .copilot-tracking/research/, and hands off planning-ready findings. Use when the user needs evidence, alternatives, or task framing first.
rpi-reviewCompare RPI planning and implementation evidence, record review findings, and route follow-up work. Use when an implementation needs acceptance review.
rpi-walkthroughGuided, conversational walkthrough that explains code, UI, UX, features, or .copilot-tracking artifacts with navigable evidence links, deep subagent review, and a reconciled decisions-and-changes ledger. Use when the user wants to understand how something works or why it was changed.
gh-code-scanningRetrieves and groups GitHub code scanning alerts by rule and severity using the gh CLI
mcsbMicrosoft Cloud Security Benchmark (MCSB v2) control-domain taxonomy and NIST 800-53 / CIS Controls crosswalk for planning and reviewing Azure cloud resources.
owasp-agenticOWASP Agentic Security Top 10 knowledge base for identifying, assessing, and remediating AI agent system security risks.
owasp-cicdOWASP CI/CD Top 10 knowledge base for identifying, assessing, and remediating CI/CD pipeline security risks.
owasp-dockerOWASP Docker Top 6 knowledge base for identifying, assessing, and remediating Docker container security risks.
owasp-infrastructureOWASP Infrastructure Top 10 knowledge base for identifying, assessing, and remediating internal IT infrastructure security risks.
owasp-llmOWASP Top 10 for LLM Applications (2025) knowledge base for identifying, assessing, and remediating large language model security risks.
owasp-mcpOWASP MCP Top 10 knowledge base for identifying, assessing, and remediating Model Context Protocol security risks.
owasp-top-10OWASP Top 10 for Web Applications (2025) knowledge base for identifying, assessing, and remediating web application security risks.
secure-by-designSecure by Design principles knowledge base for assessing security-first design, development, and deployment across the software lifecycle.
security-reviewer-formatsFormat specifications and data contracts for the security reviewer orchestrator and its subagents.
supply-chain-securitySoftware supply chain security reference for OpenSSF Scorecard, SLSA, Sigstore, SBOM, and posture/backlog taxonomies.
vexOpenVEX v0.2.0 specification reference plus VEX management playbooks - Brought to you by microsoft/hve-core.
backlog-templatesShared work-item templates and conventions for ADO and GitHub backlog handoff across the RAI, Security, SSSC, Accessibility, and Privacy planners
pr-referenceGenerates PR reference XML with commit history and unified diffs between branches, with extension and path filtering. Use when creating pull request descriptions, preparing code reviews, analyzing branch changes, discovering work items from diffs, or generating structured diff summaries.
telemetry-foundationsDeclarative OpenTelemetry-aligned telemetry vocabulary and instrumentation conventions for traces, metrics, logs, and PII handling