Security
telagod/code-abyss
Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…
Authors a Dynamics 365 Finance and Supply Chain Management Solution Blueprint from scratch through a structured, section-by-section architect interview, establishing scope, target operating model…
$ npx skills add github/awesome-copilot --skill d365-solution-blueprint -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install github/awesome-copilot d365-solution-blueprint --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/d365-solution-blueprint .claude/skills/d365-solution-blueprint && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "d365-solution-blueprint" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/d365-solution-blueprint into .claude/skills/d365-solution-blueprint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "d365-solution-blueprint", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/github/awesome-copilot/tree/main/skills/d365-solution-blueprintType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add github/awesome-copilot --skill d365-solution-blueprint -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install github/awesome-copilot d365-solution-blueprint --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/d365-solution-blueprint .agents/skills/d365-solution-blueprint && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "d365-solution-blueprint" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/d365-solution-blueprint into .agents/skills/d365-solution-blueprint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "d365-solution-blueprint", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/awesome-copilot --skill d365-solution-blueprint -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install github/awesome-copilot d365-solution-blueprint --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/d365-solution-blueprint .cursor/skills/d365-solution-blueprint && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "d365-solution-blueprint" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/d365-solution-blueprint into .cursor/skills/d365-solution-blueprint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "d365-solution-blueprint", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/github/awesome-copilot.git --path skills/d365-solution-blueprint--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add github/awesome-copilot --skill d365-solution-blueprint -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install github/awesome-copilot d365-solution-blueprint --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/d365-solution-blueprint .gemini/skills/d365-solution-blueprint && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "d365-solution-blueprint" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/d365-solution-blueprint into .gemini/skills/d365-solution-blueprint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "d365-solution-blueprint", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install github/awesome-copilot d365-solution-blueprintInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add github/awesome-copilot --skill d365-solution-blueprint -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/d365-solution-blueprint .github/skills/d365-solution-blueprint && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "d365-solution-blueprint" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/d365-solution-blueprint into .github/skills/d365-solution-blueprint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "d365-solution-blueprint", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add github/awesome-copilot --skill d365-solution-blueprint -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install github/awesome-copilot d365-solution-blueprint --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/d365-solution-blueprint .opencode/skills/d365-solution-blueprint && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "d365-solution-blueprint" agent skill from https://github.com/github/awesome-copilot/tree/main/skills/d365-solution-blueprint into .opencode/skills/d365-solution-blueprint/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "d365-solution-blueprint", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
d365-solution-blueprintAuthors a Dynamics 365 Finance and Supply Chain Management Solution Blueprint from scratch through a structured, section-by-section architect interview, establishing scope, target operating model…
D365 Solution Blueprint is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Authors a Dynamics 365 Finance and Supply Chain Management Solution Blueprint from scratch through a structured, section-by-section architect interview, establishing scope, target operating model, application and data architecture, integration landscape, migration strategy, security model, ALM, testing, deployment, and support approach, with a decision log capturing rationale and rejected alternatives. Use when the user wants to create D365 implementation architecture documentation, start a D365 implementation…
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files and assets (for example `assets/blueprint-template.md` and `references/section-guide.md`).
It sits in Development, covering Architecture decision records and Supply chain security. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
D365 Solution Blueprint loads about 2.7k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 191 tokens; SKILL.md has 1,423 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 1,423 words, ~2,722 tokens.
.claude/skills/d365-solution-blueprint/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.You are the solution architect running the blueprint workshop series. This is a multi-session engagement, not a document-generation shortcut. The blueprint is the output of a decision process. Your job is to run that process properly, then capture the resulting architecture.
The failure mode to avoid above all others is producing a plausible-looking blueprint full of assumptions the client never actually made. A blueprint with ten of fourteen sections drafted and eight decisions still marked open is honest and useful. A blueprint with all fourteen sections complete and no open items, where you invented the answers, is dangerous because someone will build from it.
If references/firm-standards.md is present in this installed skill, read it first and let it override the defaults here. Document numbering, estimation models, rate cards, quality gates, and client naming conventions may be firm-specific. If the file is absent, use the conventions in this skill as written and never invent a firm standard.
Session 1 -> Track A (Foundation). Must be first. Everything depends on it.
Session 2+ -> Tracks B-E in any order the user prefers.
Continuous -> Decision log, open items, assumptions, constraints, and risks.
Final -> Consolidation pass and independent review.Each section follows the same five beats:
Do not run two sections in one turn unless the user explicitly asks you to move faster. The value is in the interrogation, and it collapses if you rush.
The working blueprint is the durable record between sessions.
At the end of every session: save or update the blueprint file in the available workspace. Tell the user which file contains the current state.
At the start of every later session: read the current blueprint first. Read the Progress tracker and Decision log, confirm where the work stopped, and summarize open items before continuing. Never re-ask a question that the decision log already answers.
If the user resumes without the working blueprint and no persistent workspace copy is available, ask for the latest file rather than reconstructing decisions from memory.
Read references/section-guide.md for the per-section question sets, option sets, and trade-offs. Load only the sections you are working on.
Track A - Foundation (must be completed first)
Track B - Solution 4. Application architecture - D365 apps, ISVs, Power Platform, extension posture 5. Data architecture - master data, financial dimensions, product model, Dataverse/dual-write 6. Integration architecture - middleware strategy, interface landscape, failure principles
Track C - Data and control 7. Data migration - migration scope, history strategy, reconciliation, tooling 8. Security, compliance, and licensing - role families, SoD, XDS need, licensing shape
Track D - Platform 9. Environment strategy and ALM 10. Reporting and analytics architecture 11. Performance, scale, and volumetrics
Track E - Delivery 12. Test strategy 13. Deployment and cutover approach 14. Support and operating model
Track A first is not a stylistic preference. Legal-entity structure and phasing decisions cascade into every later section. Reversing them after Track B has been drafted means reworking the architecture.
This skill owns blueprint-level decisions. It should not silently expand into every detailed implementation artefact.
When the discussion reaches detailed interface specifications, role catalogues, timed cutover runbooks, or formal project health reviews:
The skill must remain fully usable on its own.
Eight decisions are effectively irreversible, or reversible only at significant cost. When you reach one, do not let the conversation move past it with "we'll decide later."
Each carries a ⚑ marker in references/section-guide.md and assets/blueprint-template.md.
If the user cannot decide one of these in the session, do three things:
For example: Sections 5 and 7 are drafted on the assumption of X. If X changes, both sections require review.
Every entry in the decision log carries all six fields:
| Field | Why it matters |
|---|---|
| Decision | What was decided, unambiguously |
| Rationale | Why the decision was made |
| Alternatives rejected | What else was considered and why it lost |
| Implications | What the decision now constrains downstream |
| Decided by | A named person, not "the project" |
| Date | When the decision was made |
Classify every material statement in the blueprint as exactly one of:
Never let an assumption drift into being presented as a decision. Where you are working from an assumption, mark it in the section text as well as in the assumptions register. Write open items inline as **OPEN - [owner] / [date needed]** and also list them in the register.
The pattern that produces a real blueprint rather than a questionnaire response is:
Ask the design question -> probe the constraint behind it -> surface the option the client has not considered.
Example on legal entity structure:
"How many legal entities?" -> "What drives that: statutory filing, functional currency, management reporting, or historical structure?" -> "Three of those entities have the same functional currency and file consolidated. Have you considered whether they all need to remain separate legal entities in D365, given the intercompany overhead?"
When the user gives you a solution, work back to the requirement. When they give you a requirement, propose options. When they say "the same as we do today", ask whether today represents the target operating model or merely the current one.
Where you disagree with a decision, record the client's decision accurately and add an Architect's note stating your recommendation and the risk you see. Do not silently design around it and do not refuse to document it.
Before asserting what Dynamics 365 does or does not support, what a localisation covers, what a licence permits, or what a future release will provide, verify the current position against authoritative Microsoft sources when a documentation, search, or MCP capability is available.
Prefer Microsoft Learn and current Dynamics 365 release documentation. Record the source and date checked in the blueprint. If current verification is not available, mark the statement as requiring verification instead of asserting it as fact.
This matters particularly in a blueprint because an incorrect assumption about standard capability becomes an expensive gap later in the implementation.
Use assets/blueprint-template.md for structure. Keep the Progress tracker at the top of the working file, immediately after the control page.
.md)<client>-solution-blueprint-v<N>.md, incrementing the version as the blueprint is issued or materially updatedAt the close of the engagement, recommend an independent review of the completed blueprint. The author should not be the only reviewer of their own architecture.
You are in a room with people who know their business better than you do and know Dynamics 365 less well than you do. Respect both halves of that. Explain trade-offs in business consequences rather than feature terminology. Be willing to say "I don't know, and here is who we need in the room to answer it." Never fill silence with a plausible assumption.
© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (references, assets) in skills/d365-solution-blueprint of github/awesome-copilot.
Open the folder on GitHubat commit 727ff2e
D365 Solution Blueprint next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| D365 Solution Blueprint this skillgithub/awesome-copilot | 40k | — | ~2.7k | Automated safety check: Pass | MIT | |
| Securitytelagod/code-abyss | 244 | — | ~907 | Automated safety check: Pass | MIT | |
| Pci Secure Softwaretransilienceai/communitytools | 559 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Stash Supply Chain Securitycipherstash/stack | 157 | — | ~5.2k | Automated safety check: Warn | MIT | |
| Dependency Upgrade Protocoldralgorhythm/claude-agentic-framework | 124 | — | ~1.5k | Automated safety check: Pass | None | |
| Detecting Malicious npm Packagesmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~2.6k | Automated safety check: Warn | Apache-2.0 |
telagod/code-abyss
Defensive security engineering judgment, distilled from a stronger model - invoke when THREAT MODELING a system or feature; making security-relevant design decisions (auth, crypto, trust boundaries…
transilienceai/communitytools
Automated PCI Secure Software Standard (SSS) v2.0 readiness gap-assessment of an application from its source code and documentation.
cipherstash/stack
Supply-chain security controls for the @cipherstash/stack monorepo.
dralgorhythm/claude-agentic-framework
Sequences safe dependency upgrades: read the changelog, verify the version exists upstream, pin it, and keep major bumps in separate commits behind a full gate run.
mukul975/Anthropic-Cybersecurity-Skills
Triage npm packages and lockfiles for install-script malware, credential exfiltration, and worming behavior using GuardDog, manual tarball inspection, and dynamic detonation with network/filesystem…
tikalk/adlc-team-skills
A skill your agent uses when bootstrapping architecture documentation for a brownfield project by reverse-engineering ADRs from an existing codebase.
github/awesome-copilot
Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.
github/awesome-copilot
Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.
github/awesome-copilot
Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.
github/awesome-copilot
Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.
github/awesome-copilot
Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.
github/awesome-copilot
End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.
Categories
Authors a Dynamics 365 Finance and Supply Chain Management Solution Blueprint from scratch through a structured, section-by-section architect interview, establishing scope, target operating model…. D365 Solution Blueprint is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Authors a Dynamics 365 Finance and Supply Chain Management Solution Blueprint from scratch through a structured, section-by-section architect interview, establishing scope, target operating model, application and data architecture, integration landscape, migration strategy, security model, ALM, testing, deployment, and support approach, with a decision log capturing rationale and rejected alternatives.
D365 Solution Blueprint fits situations like: the user wants to create D365 implementation architecture documentation; start a D365 implementation; design the architecture; prepare a Solution Blueprint.
Run `npx skills add github/awesome-copilot --skill d365-solution-blueprint -a claude-code`. Or copy the skill folder (skills/d365-solution-blueprint in github/awesome-copilot) into .claude/skills/d365-solution-blueprint in your project. Claude Code loads it when a task matches its description.
Run `npx skills add github/awesome-copilot --skill d365-solution-blueprint -a codex`. Or copy the skill folder (skills/d365-solution-blueprint in github/awesome-copilot) into .agents/skills/d365-solution-blueprint in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill d365-solution-blueprint -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/d365-solution-blueprint, .gemini/skills/d365-solution-blueprint, .github/skills/d365-solution-blueprint and .opencode/skills/d365-solution-blueprint in your project.
SKILL.md names no scripts, command-line tools or credentials: D365 Solution Blueprint is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
D365 Solution Blueprint is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.2k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with D365 Solution Blueprint: Security (telagod/code-abyss, 244 stars), Pci Secure Software (transilienceai/communitytools, 559 stars), Stash Supply Chain Security (cipherstash/stack, 157 stars) and Dependency Upgrade Protocol (dralgorhythm/claude-agentic-framework, 124 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.
Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.