security-planning Skill
Security planning reference set for operational buckets, STRIDE analysis, standards mapping, NIST control families, backlog scaffolding, and deterministic TM7 (.tm7) plus markdown dual-output generation. Published by microsoft in hve-core.
Decision snapshot
Is this a fit?
Security review, Documentation, Data analysis, Includes SKILL.md
Compatibility not yet detected.
Permission behavior not yet detected.
Copy skill directory
2 months ago · MIT license
No specific cautions were detected. Review the source and requested permissions before installing.
What is security-planning Skill?
Security planning reference set for operational buckets, STRIDE analysis, standards mapping, NIST control families, backlog scaffolding, and deterministic TM7 (.tm7) plus markdown dual-output generation. Published by microsoft in hve-core. This profile combines repository metadata with install, compatibility, and usage signals so developers can quickly decide whether it fits their agent workflow before opening the source repository.
Automated repository signals based on public metadata such as recency, license, installation evidence, and adoption. These are not a security audit or endorsement. See how SkillIndex evaluates profiles.
Key capabilities
- Includes SKILL.md support
- Reusable instructions support
- Security review
- Documentation
- Data analysis
- Security review use cases
- Documentation use cases
Declared skill metadata
- Declared license: MIT
- Compatibility: Generation requires Python 3.11+ and uv. The native TM7 feedback loop additionally requires Windows with an interactive desktop session and the pinned Microsoft Threat Modeling Tool 7.3.51110.1.
- Source file: .github/skills/project-planning/security-planning/SKILL.md
These fields retain source and confidence evidence from the indexed SKILL.md.
Compatibility and setup
- Install or run with Copy skill directory
When to use security-planning Skill
- Use it for security review.
- Use it for documentation.
- Use it for data analysis.
Built with
Editorial notes
Source
- Creator: microsoft
- Repository: microsoft/hve-core
- Skill file: .github/skills/project-planning/security-planning/SKILL.md
What it does
Security planning reference set for operational buckets, STRIDE analysis, standards mapping, NIST control families, backlog scaffolding, and deterministic TM7 (.tm7) plus markdown dual-output generation.
Skill instructions
Security Planning This skill packages the durable security-planning reference material used by the Security Planner: operational bucket guidance, STRIDE analysis patterns, standards cross-references, NIST control-family references, and security-specific backlog formats. When to use Use this skill when you need to: Classify application components into the operational security buckets used during planning. Evaluate threats with STRIDE-based analysis, including AI-specific extensions when raiEnabled is true. Map bucket findings to standards references and control families without re-embedding long standard tables. Derive security-specific backlog priorities and RAI work item categories for Phase 5 handoff. Generate a dual-output TM7 model plus markdown report from a YAML/JSON threat-model spec for human-reviewed audit workflows. TM7 generation workflow When the user asks for a TM7 threat model, the runtime can generate a .tm7 file and a matching markdown report from the same spec. The gen
Verified compatibility and discovery
Frequently asked questions
What is security-planning?
security-planning is a open-source AI agent skill with Copy skill directory. Security planning reference set for operational buckets, STRIDE analysis, standards mapping, NIST control families, backlog scaffolding, and deterministic TM7 (.tm7) plus markdown dual-output generation.
Who is security-planning best for?
security-planning is best for reusing agent instructions, scripts, and references, security review workflows, documentation workflows, data analysis workflows.
How do I install security-planning?
Install or run security-planning using Copy skill directory. Check security-planning for the latest setup command.
Is security-planning actively maintained?
security-planning may need a closer maintenance check before production use.
Project health auto-fetched from the source repository.
Maintain this resource?
Review this source-backed profile, send a correction with evidence, or link to it from your documentation. Claims verify your relationship to the project; profile facts still require source evidence and editorial review.